Governance and Audit / align it

Cyber Assessment Framework alignment

If you fall under the NIS Regulations, or a regulator or prime contractor expects the NCSC Cyber Assessment Framework, we map where you stand against its outcomes and show you what closes each gap, in order. Run by a team certified for ISO 27001 by a UKAS-accredited certification body.

What is the Cyber Assessment Framework?

The Cyber Assessment Framework is the NCSC's standard for assessing cyber resilience. It is outcome focused rather than a fixed checklist: demonstrate outcomes, not ticked controls. There is no CAF certificate to hold, so the goal is an evidenced position you can put in front of a competent authority or a buyer.

The four objectives

The CAF organises cyber resilience into four objectives, A to D, each made up of contributing outcomes, and we turn the framework's language into work you can plan.

AManage

Managing security risk

Governance structures, risk management, asset management and supply chain security. Do you understand and own the risk, rather than react to it?

BProtect

Protecting against cyber attack

Access control, data security, system hardening, network security and staff awareness. The controls that reduce the chance of a successful attack, and the proof they are in place.

CDetect

Detecting security events

Security monitoring, logging, alerting and threat detection. Would you know if something were wrong, and how quickly?

DMinimise

Minimising the impact of incidents

Incident response, recovery planning, business continuity and learning from what happens. How well do you contain, recover and improve when something does go wrong?

Who the CAF applies to, and how it compares with ISO 27001

When the CAF is in scope

The Network and Information Systems (NIS) Regulations 2018 place security and incident-reporting duties on operators of essential services within their scope. These services include energy, drinking water, transport, healthcare and digital infrastructure. Relevant digital service providers have separate duties. The organisation's activity, applicable thresholds and designation determine the position; working in a sector does not automatically put every business in scope.

A regulator or buyer in telecoms, government or defence may separately ask for CAF evidence. Confirm the actual requirement, including the CAF version and assessment profile, rather than treating every use of the framework as a NIS obligation.

CAF and ISO 27001 are complementary, not competing

ISO 27001 certification assesses an information security management system, including how an organisation evaluates risks, selects appropriate controls and improves its approach. Annex A provides a reference set of controls; their applicability must be considered and justified. The CAF assesses security outcomes for the essential functions in scope. Risk assessments, control records and other evidence can support both, while each framework keeps its own requirements.

  ISO 27001 Cyber Assessment Framework
Focus A management system and its controls Security outcomes
Approach Risk based, with justified control selection and applicability Outcome based, across the contributing outcomes in objectives A to D
How it is checked Third party certification by an accredited body Self assessment, or assessment by a competent authority
Recognition International standard UK government standard
Best when You need to show systematic, certified security management You need to meet a UK regulated sector or NIS expectation

Weighing up which standard a contract calls for? Our guide on Cyber Essentials or ISO 27001 walks through how to read the clause, and the same care applies when a buyer asks for something "equivalent".

From a gap analysis to an evidence pack

01

Scope and self assess

We agree the systems in scope and assess your position against the four objectives, recording the starting point.

02

Gap analysis

We map where you fall short of each outcome and rank the gaps by risk, so the work that reduces exposure comes first.

03

Close the gaps

We put the controls in place and operate them, documenting what was done and when.

04

Evidence and maintain

We assemble the evidence into a pack mapped to the framework, and keep it current.

Common questions

Is the CAF mandatory?

It is not universally mandatory. The Network and Information Systems Regulations 2018 place duties on operators of essential services within their scope, and a competent authority may use the CAF to assess them. A regulator, prime contractor or buyer can also require CAF evidence under a separate arrangement. Confirm your organisation's regulatory position and the version, profile and evidence your authority or contract requires.

What is the difference between CAF alignment and CAF certification?

There is no CAF certification in the way ISO 27001 offers a certificate. The CAF uses a self assessment or a competent authority assessment model. Alignment means you have assessed your position against the framework's outcomes and hold the evidence to support it, which is what a buyer or authority wants to see.

How long does CAF alignment take?

It depends on where you start. An organisation that already runs security to a good standard can often demonstrate alignment relatively quickly through a self assessment and gap analysis. Starting from a lower base, meaningful alignment more commonly takes a number of months, because the gaps have to be closed and the evidence has to be generated, not just written down.

How does the CAF relate to ISO 27001 and Cyber Essentials?

They are complementary. Cyber Essentials covers five technical basics, ISO 27001 certifies a whole management system, and the CAF assesses security outcomes for regulated and essential services. The work overlaps, so effort is rarely wasted. Many organisations serving UK regulated sectors hold ISO 27001, certify to Cyber Essentials, and align to the CAF, each answering a different question.

Can you align us to the CAF and also run the controls?

Yes. We assess your position, close the gaps, and then operate the controls behind objectives B, C, and D as part of our cyber security work. One team runs the technology and assembles the evidence, so the evidence describes what is in place.

Talk to us about CAF alignment

Tell us which authority or contract is asking, and we will tell you where you stand and what it takes to close the gaps.

Reading, Berkshire  /  Cyber Essentials certification body  /  reply within one working day