CAF Incident Response Document Library

Complete documentation architecture for evidencing incident response under the NCSC Cyber Assessment Framework (CAF)

CAF IR Doc Library CAF IR Document Library

91 pre-defined documents. 13 structured categories. Mapped to CAF v4.0 contributing outcomes.

What is the CAF Incident Response Document Library?

The CAF Incident Response Document Library is a structured documentation framework designed to help organisations evidence their cyber incident response capability against the UK National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF) Version 4.0. It contains 91 incident response documents organised into 13 logical categories, each mapped to the relevant CAF contributing outcomes, with every document weighted according to how strongly it supports an assessor's judgement.

Unlike many compliance frameworks, the UK CAF is not a checklist of mandatory documents. It is an outcome-based framework that assesses whether an organisation can demonstrate mature cyber resilience through evidence, governance, processes and operational capability. The document library has therefore been designed around the evidence that supports CAF outcomes rather than simply producing paperwork.

The guide focuses specifically on the CAF outcomes most relevant to cyber incident response, including:

  • Objective A – Managing Security Risk
  • Objective B5 – Resilient Networks and Systems
  • Objective B6 – Staff Awareness and Training
  • Objective C – Detecting Cyber Security Events
  • Objective D – Minimising the Impact of Cyber Security Incidents

Rather than starting from a blank page, organisations receive a complete documentation architecture covering governance, incident planning, monitoring, threat hunting, resilience, recovery, lessons learned, supplier management, training and evidence management.

The library also introduces a structured numbering convention, recommended folder hierarchy and a companion CAF Master Document Register, enabling organisations to manage documentation consistently throughout its lifecycle.

What's Inside?

Component

Detail

91 incident response documents

Every major document required to evidence CAF incident response capability.

13 structured categories

Governance, monitoring, recovery, resilience, testing, training, evidence management and more.

CAF outcome mapping

Every document mapped to one or more relevant CAF contributing outcomes.

Core vs Supporting evidence

Each document weighted according to its evidential value during an assessment.

Document numbering convention

Consistent CAF-IR document IDs across every artefact.

Recommended folder structure

Practical document management hierarchy for implementation.

Lifecycle guidance

Shows which documents are prepared before, during and after incidents.

Companion Master Register

18-column CSV register available separately for document management.

 

Why Do Organisations Need a CAF Incident Response Document Library?

One of the biggest misconceptions about the Cyber Assessment Framework is that passing an assessment simply means producing policies. It doesn't. The CAF evaluates whether an organisation can demonstrate that its cyber resilience outcomes are being achieved.

That means assessors look beyond individual documents. They examine whether governance is active, risks are understood, monitoring is effective, incidents are managed consistently and lessons are continuously incorporated into future improvements.

Without a structured documentation architecture, organisations frequently encounter familiar problems:

  • Evidence spread across multiple teams;
  • Duplicated procedures;
  • Inconsistent ownership;
  • Outdated versions remaining in circulation;
  • Gaps between governance and operational processes;
  • Difficulty demonstrating how evidence supports individual CAF outcomes.

The CAF Incident Response Document Library addresses these challenges by providing a coherent documentation framework organised around how incident response actually operates.

Instead of asking: "Do we have an incident response plan?", it helps organisations answer much more important questions:

  • Can we evidence board oversight?
  • Can we demonstrate threat-informed decision making?
  • Can we show monitoring effectiveness?
  • Can we evidence testing?
  • Can we demonstrate continuous improvement?
  • Can assessors easily follow the audit trail?

Those are the questions the CAF is ultimately designed to answer.

Why CAF Documentation Is Different From Traditional Compliance Frameworks

Many security standards specify the documents organisations should maintain.

The Cyber Assessment Framework takes a fundamentally different approach.

CAF measures outcomes, not paperwork.

Its contributing outcomes are assessed as:

  • Achieved
  • Partially Achieved
  • Not Achieved

Documentation is simply the evidence that helps an assessor determine which judgement is appropriate. The documents themselves are not the objective—they support the demonstration of governance, capability and operational maturity.

This means organisations require documentation that is:

  • Connected to operational processes;
  • Linked to governance decisions;
  • Supported by records and evidence;
  • Maintained throughout the incident lifecycle;
  • Clearly mapped to the relevant CAF outcomes.

The CAF Incident Response Document Library has been built around this philosophy.

Rather than generating unnecessary paperwork, every document has a defined purpose, an owner, an evidential weight and a mapping to one or more contributing outcomes.

That makes it significantly easier to prepare for CAF assessments while simultaneously improving day-to-day cyber resilience.

Core Evidence vs Supporting Evidence

One of the distinguishing features of the CAF Incident Response Document Library is that every document is assigned an evidential weighting. Rather than treating all documents equally, each artefact is classified according to the strength of evidence it provides during a CAF assessment.

Core Evidence: Core Evidence documents directly support the assessment of one or more CAF contributing outcomes. These documents typically include governance artefacts, approved policies, incident response plans, monitoring procedures, recovery plans, exercise reports and management evidence that an assessor would normally expect to review.

They form the primary evidence base used to demonstrate that the relevant outcome has been achieved.

Supporting Evidence: Supporting Evidence documents strengthen the wider evidence chain. These documents include operational guides, templates, reference material, checklists, working records and supporting registers that help demonstrate consistent implementation.

While they may not individually determine an assessment outcome, together they provide confidence that incident response activities are mature, repeatable and well governed.

The CAF-IR Document Numbering Convention

To simplify document management, every artefact within the library follows a structured numbering convention.

Each document receives a unique identifier using the format:

CAF-IR-[TYPE]-[NNN]

Where:

  • CAF identifies the Cyber Assessment Framework
  • IR identifies the Incident Response documentation set
  • TYPE identifies the document category
  • NNN provides a permanent sequential identifier

Examples include:

  • CAF-IR-POL-001 – Policy
  • CAF-IR-PLN-001 – Plan
  • CAF-IR-PRO-001 – Procedure
  • CAF-IR-PLY-001 – Playbook
  • CAF-IR-REG-001 – Register
  • CAF-IR-CHK-001 – Checklist
  • CAF-IR-RPT-001 – Report
  • CAF-IR-LOG-001 – Log
  • CAF-IR-TPL-001 – Template
  • CAF-IR-GDE-001 – Guide

Maintaining consistent identifiers simplifies version control, document references, audit trails and cross-linking between related artefacts.

Key Benefits of the CAF Incident Response Document Library

  • Build a Complete Documentation Architecture: Instead of creating documents individually as gaps emerge, start with a complete incident response documentation framework containing 91 predefined artefacts organised into a logical structure.

  • Align Documentation with the Cyber Assessment Framework: Every document has been mapped to the relevant CAF contributing outcomes, making it significantly easier to understand how each artefact contributes to demonstrating cyber resilience during an assessment.

  • Focus on Evidence Rather Than Paperwork: CAF assessments evaluate evidence, not simply whether documents exist. The library has therefore been designed around the operational evidence that assessors expect to review rather than producing unnecessary documentation.

  • Improve Governance and Ownership: Each document can be assigned clear ownership, approval responsibilities and review cycles, helping organisations maintain documentation as an operational asset instead of a static compliance exercise.

  • Accelerate Assessment Preparation: Rather than spending weeks deciding what documentation should exist, security teams can begin with a structured architecture that reflects recognised incident response good practice.

  • Reduce Documentation Gaps: By presenting all 91 documents within one integrated framework, missing procedures, registers, playbooks and governance records become immediately visible.

  • Improve Cross-Team Consistency: Incident response rarely belongs to one department. The documentation framework supports consistent collaboration across departments.

  • Support Continuous Improvement: The framework extends well beyond planning and response. Dedicated categories covering testing, lessons learned, assurance and continual improvement help organisations demonstrate increasing maturity over time.

  • Integrate with Existing Document Management Systems: The recommended document identifiers and folder structure make it straightforward to implement the library within SharePoint, Microsoft Teams, document management platforms or GRC solutions.

  • Create a Sustainable Documentation Programme: Perhaps the greatest benefit is consistency. Rather than producing documents solely for an assessment, organisations establish documentation that continues supporting incident response throughout its operational lifecycle.

** GDPR & Privacy ** We wholeheartedly believe in your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data.

Please Fill the Form Below To Get Your Free Copy of the CAF Incident Response Document Library

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

Frequently Asked Questions about the CAF Incident Response Document Library

  • 1. What is the CAF Incident Response Document Library?

    It is a structured guide containing 91 incident response documents organised into 13 categories and mapped to relevant outcomes within the NCSC Cyber Assessment Framework Version 4.0.

  • 2. Does the Cyber Assessment Framework prescribe mandatory documents?

     No. CAF is outcome-based rather than document-based. The library provides a practical documentation architecture that helps organisations demonstrate the evidence assessors typically expect to review. 

  • 3. How many documents are included?

    The library contains 91 incident response documents covering governance, monitoring, investigations, recovery, resilience, communications, training, testing, continual improvement and supporting evidence.

  • 4. What are Core and Supporting Evidence?

    Core Evidence documents provide primary evidence for one or more CAF contributing outcomes. 

    Supporting Evidence documents reinforce the wider evidence chain and demonstrate operational maturity.

  • 5. Can the documents be adapted?

     Yes. The framework is intended to be customised to reflect each organisation's governance structure, technologies, incident response processes and regulatory obligations. 

  • 6. Does the library include document templates?

    No. The guide provides the complete documentation architecture and explains the purpose of each document rather than supplying completed organisational templates.

  • 7. What is the CAF Master Document Register?

    The Master Register is a companion CSV control sheet that tracks ownership, approvals, review dates, implementation status, evidence locations and document versions across the complete documentation set.

  • 8. Can this support GovAssure assessments?

    Yes. The documentation framework has been designed around the Cyber Assessment Framework and can assist organisations preparing for GovAssure or other CAF-based assessments by improving documentation structure and evidence management.

  • 9. Can private sector organisations use the guide?

    Absolutely. Many organisations voluntarily adopt the Cyber Assessment Framework as a recognised cyber resilience model even when formal CAF assessments are not mandatory.

  • 10. Is this a compliance checklist?

    No. The guide provides a documentation architecture aligned to CAF outcomes.

    Successful CAF assessments depend on operational capability, governance and demonstrable evidence—not documentation alone.

  • 11. How should organisations maintain the library?

    Documentation should be reviewed regularly and updated following incidents, exercises, audits, significant technology changes and governance reviews to ensure it continues reflecting operational practice.

  • 12. How does this differ from ISO 27001 or NIS2 documentation?

    ISO 27001 and NIS2 define different governance and regulatory expectations. The CAF Incident Response Document Library is specifically organised around the evidence required to demonstrate achievement of Cyber Assessment Framework outcomes, making it particularly useful for organisations using the NCSC assessment methodology. 

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • Contact you about our services including, but not limited to, training, trusted advisory and consultancy.
  • Keep you posted on free resources and documents.
  • Update you on upcoming webinars and surveys.
  • Update you when we host our ground-breaking Wisdom of Crowds events.
  • Ask you, every now and then, if you want to take part in crowdsourced initiatives.
  • Our partners (we carefully select our partners) may contact you to arrange or demo or share more information with you about their products or services when you watch one of our sponsored webinars. Remember, you can always tell us or our partners, "No, not interested".
Cyber Incident Response Plan Template