Governance and Audit / align it

Cyber Assessment Framework alignment

If you fall under the NIS Regulations, or a regulator or prime contractor expects the NCSC Cyber Assessment Framework, we map where you stand against its outcomes and show you what closes each gap, in order. Run by a team certified for ISO 27001 by a UKAS-accredited certification body.

Governance and Audit / 01 · What CAF alignment is

What is the Cyber Assessment Framework?

The Cyber Assessment Framework is the NCSC's standard for assessing cyber resilience. It is outcome focused rather than a fixed checklist: demonstrate outcomes, not ticked controls. There is no CAF certificate to hold, so the goal is an evidenced position you can put in front of a competent authority or a buyer.

Governance and Audit / 02 · The framework

The four objectives

The CAF organises cyber resilience into four objectives, A to D, each made up of contributing outcomes, and we turn the framework's language into work you can plan.

AManage

Managing security risk

Governance structures, risk management, asset management and supply chain security. Do you understand and own the risk, rather than react to it?

BProtect

Protecting against cyber attack

Access control, data security, system hardening, network security and staff awareness. The controls that reduce the chance of a successful attack, and the proof they are in place.

CDetect

Detecting security events

Security monitoring, logging, alerting and threat detection. Would you know if something were wrong, and how quickly?

DMinimise

Minimising the impact of incidents

Incident response, recovery planning, business continuity and learning from what happens. How well do you contain, recover and improve when something does go wrong?

Governance and Audit / 03 · Context

Who the CAF applies to, and how it compares with ISO 27001

When the CAF is in scope

The Network and Information Systems (NIS) Regulations 2018 require operators of essential services to put appropriate security measures in place and to report significant incidents. The regulated sectors include energy, water, transport, healthcare, telecoms, government and defence. Where a competent authority uses the CAF to assess that resilience, alignment is the practical way to show you meet the expectation.

CAF and ISO 27001 are complementary, not competing

ISO 27001 certifies a management system against a defined set of controls. The CAF assesses whether you achieve a set of security outcomes. Work done for one is rarely wasted on the other, and organisations serving UK regulated sectors often do both.

  ISO 27001 Cyber Assessment Framework
Focus A management system and its controls Security outcomes
Approach Prescriptive, built around the Annex A controls Outcome based, across the contributing outcomes in objectives A to D
How it is checked Third party certification by an accredited body Self assessment, or assessment by a competent authority
Recognition International standard UK government standard
Best when You need to show systematic, certified security management You need to meet a UK regulated sector or NIS expectation

Weighing up which standard a contract calls for? Our guide on Cyber Essentials or ISO 27001 walks through how to read the clause, and the same care applies when a buyer asks for something "equivalent".

Governance and Audit / 04 · How we work

From a gap analysis to an evidence pack

01

Scope and self assess

We agree the systems in scope and assess your position against the four objectives, recording the starting point.

02

Gap analysis

We map where you fall short of each outcome and rank the gaps by risk, so the work that reduces exposure comes first.

03

Close the gaps

We put the controls in place and operate them, documenting what was done and when.

04

Evidence and maintain

We assemble the evidence into a pack mapped to the framework, and keep it current.

FAQ

Common questions

Is the CAF mandatory?

It is not universally mandatory, but it is increasingly required when you serve a regulated sector. The Network and Information Systems Regulations 2018 place duties on operators of essential services, and a competent authority may use the CAF to assess them. Beyond that, prime contractors and buyers in regulated supply chains often ask for it whether or not you are formally in scope.

What is the difference between CAF alignment and CAF certification?

There is no CAF certification in the way ISO 27001 offers a certificate. The CAF uses a self assessment or a competent authority assessment model. Alignment means you have assessed your position against the framework's outcomes and hold the evidence to support it, which is what a buyer or authority wants to see.

How long does CAF alignment take?

It depends on where you start. An organisation that already runs security to a good standard can often demonstrate alignment relatively quickly through a self assessment and gap analysis. Starting from a lower base, meaningful alignment more commonly takes a number of months, because the gaps have to be closed and the evidence has to be generated, not just written down.

How does the CAF relate to ISO 27001 and Cyber Essentials?

They are complementary. Cyber Essentials covers five technical basics, ISO 27001 certifies a whole management system, and the CAF assesses security outcomes for regulated and essential services. The work overlaps, so effort is rarely wasted. Many organisations serving UK regulated sectors hold ISO 27001, certify to Cyber Essentials, and align to the CAF, each answering a different question.

Can you align us to the CAF and also run the controls?

Yes. We assess your position, close the gaps, and then operate the controls behind objectives B, C, and D as part of our cyber security work. One team runs the technology and assembles the evidence, so the evidence describes what is in place.

Talk to us about CAF alignment

Tell us which authority or contract is asking, and we will tell you where you stand and what it takes to close the gaps.

Reading, Berkshire  /  Cyber Essentials certification body  /  reply within one working day