Managing security risk
Governance structures, risk management, asset management and supply chain security. Do you understand and own the risk, rather than react to it?
If you fall under the NIS Regulations, or a regulator or prime contractor expects the NCSC Cyber Assessment Framework, we map where you stand against its outcomes and show you what closes each gap, in order. Run by a team certified for ISO 27001 by a UKAS-accredited certification body.
The Cyber Assessment Framework is the NCSC's standard for assessing cyber resilience. It is outcome focused rather than a fixed checklist: demonstrate outcomes, not ticked controls. There is no CAF certificate to hold, so the goal is an evidenced position you can put in front of a competent authority or a buyer.
The CAF organises cyber resilience into four objectives, A to D, each made up of contributing outcomes, and we turn the framework's language into work you can plan.
Governance structures, risk management, asset management and supply chain security. Do you understand and own the risk, rather than react to it?
Access control, data security, system hardening, network security and staff awareness. The controls that reduce the chance of a successful attack, and the proof they are in place.
Security monitoring, logging, alerting and threat detection. Would you know if something were wrong, and how quickly?
Incident response, recovery planning, business continuity and learning from what happens. How well do you contain, recover and improve when something does go wrong?
The Network and Information Systems (NIS) Regulations 2018 require operators of essential services to put appropriate security measures in place and to report significant incidents. The regulated sectors include energy, water, transport, healthcare, telecoms, government and defence. Where a competent authority uses the CAF to assess that resilience, alignment is the practical way to show you meet the expectation.
ISO 27001 certifies a management system against a defined set of controls. The CAF assesses whether you achieve a set of security outcomes. Work done for one is rarely wasted on the other, and organisations serving UK regulated sectors often do both.
| ISO 27001 | Cyber Assessment Framework | |
|---|---|---|
| Focus | A management system and its controls | Security outcomes |
| Approach | Prescriptive, built around the Annex A controls | Outcome based, across the contributing outcomes in objectives A to D |
| How it is checked | Third party certification by an accredited body | Self assessment, or assessment by a competent authority |
| Recognition | International standard | UK government standard |
| Best when | You need to show systematic, certified security management | You need to meet a UK regulated sector or NIS expectation |
Weighing up which standard a contract calls for? Our guide on Cyber Essentials or ISO 27001 walks through how to read the clause, and the same care applies when a buyer asks for something "equivalent".
We agree the systems in scope and assess your position against the four objectives, recording the starting point.
We map where you fall short of each outcome and rank the gaps by risk, so the work that reduces exposure comes first.
We put the controls in place and operate them, documenting what was done and when.
We assemble the evidence into a pack mapped to the framework, and keep it current.
Access control, monitoring and incident response map directly onto objectives B, C and D. We put those controls in place and operate them.
Go to Cyber Security Get readyIf the CAF is one of several obligations, compliance readiness pulls Cyber Essentials, ISO 27001 and GDPR into a single prioritised path rather than four projects.
See compliance readinessIf you supply the Ministry of Defence, the framework sits alongside Def Stan 05-138 and Cyber Essentials, which we cover on our defence and aerospace page. It is part of our governance and audit work, and pairs with audit and assurance.
It is not universally mandatory, but it is increasingly required when you serve a regulated sector. The Network and Information Systems Regulations 2018 place duties on operators of essential services, and a competent authority may use the CAF to assess them. Beyond that, prime contractors and buyers in regulated supply chains often ask for it whether or not you are formally in scope.
There is no CAF certification in the way ISO 27001 offers a certificate. The CAF uses a self assessment or a competent authority assessment model. Alignment means you have assessed your position against the framework's outcomes and hold the evidence to support it, which is what a buyer or authority wants to see.
It depends on where you start. An organisation that already runs security to a good standard can often demonstrate alignment relatively quickly through a self assessment and gap analysis. Starting from a lower base, meaningful alignment more commonly takes a number of months, because the gaps have to be closed and the evidence has to be generated, not just written down.
They are complementary. Cyber Essentials covers five technical basics, ISO 27001 certifies a whole management system, and the CAF assesses security outcomes for regulated and essential services. The work overlaps, so effort is rarely wasted. Many organisations serving UK regulated sectors hold ISO 27001, certify to Cyber Essentials, and align to the CAF, each answering a different question.
Yes. We assess your position, close the gaps, and then operate the controls behind objectives B, C, and D as part of our cyber security work. One team runs the technology and assembles the evidence, so the evidence describes what is in place.
Tell us which authority or contract is asking, and we will tell you where you stand and what it takes to close the gaps.
Hello, I am Ainsley, the AI assistant here at Dead Simple Computing. Ask me anything about managed IT, cyber security, software and AI, or governance and audit. I can also put you in touch with a person.
Replies are AI generated and can be wrong. Your messages are sent to a third-party AI service to produce them, and a member of our team can read this chat and may join it. Do not type anything confidential. See our privacy notice.