Complete documentation architecture for evidencing incident response under the NCSC Cyber Assessment Framework (CAF)
The CAF Incident Response Document Library is a structured documentation framework designed to help organisations evidence their cyber incident response capability against the UK National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF) Version 4.0. It contains 91 incident response documents organised into 13 logical categories, each mapped to the relevant CAF contributing outcomes, with every document weighted according to how strongly it supports an assessor's judgement.
Unlike many compliance frameworks, the UK CAF is not a checklist of mandatory documents. It is an outcome-based framework that assesses whether an organisation can demonstrate mature cyber resilience through evidence, governance, processes and operational capability. The document library has therefore been designed around the evidence that supports CAF outcomes rather than simply producing paperwork.
The guide focuses specifically on the CAF outcomes most relevant to cyber incident response, including:
Rather than starting from a blank page, organisations receive a complete documentation architecture covering governance, incident planning, monitoring, threat hunting, resilience, recovery, lessons learned, supplier management, training and evidence management.
The library also introduces a structured numbering convention, recommended folder hierarchy and a companion CAF Master Document Register, enabling organisations to manage documentation consistently throughout its lifecycle.
|
Component |
Detail |
|
91 incident response documents |
Every major document required to evidence CAF incident response capability. |
|
13 structured categories |
Governance, monitoring, recovery, resilience, testing, training, evidence management and more. |
|
CAF outcome mapping |
Every document mapped to one or more relevant CAF contributing outcomes. |
|
Core vs Supporting evidence |
Each document weighted according to its evidential value during an assessment. |
|
Document numbering convention |
Consistent CAF-IR document IDs across every artefact. |
|
Recommended folder structure |
Practical document management hierarchy for implementation. |
|
Lifecycle guidance |
Shows which documents are prepared before, during and after incidents. |
|
Companion Master Register |
18-column CSV register available separately for document management. |
One of the biggest misconceptions about the Cyber Assessment Framework is that passing an assessment simply means producing policies. It doesn't. The CAF evaluates whether an organisation can demonstrate that its cyber resilience outcomes are being achieved.
That means assessors look beyond individual documents. They examine whether governance is active, risks are understood, monitoring is effective, incidents are managed consistently and lessons are continuously incorporated into future improvements.
Without a structured documentation architecture, organisations frequently encounter familiar problems:
The CAF Incident Response Document Library addresses these challenges by providing a coherent documentation framework organised around how incident response actually operates.
Instead of asking: "Do we have an incident response plan?", it helps organisations answer much more important questions:
Those are the questions the CAF is ultimately designed to answer.
Many security standards specify the documents organisations should maintain.
The Cyber Assessment Framework takes a fundamentally different approach.
CAF measures outcomes, not paperwork.
Its contributing outcomes are assessed as:
Documentation is simply the evidence that helps an assessor determine which judgement is appropriate. The documents themselves are not the objective—they support the demonstration of governance, capability and operational maturity.
This means organisations require documentation that is:
The CAF Incident Response Document Library has been built around this philosophy.
Rather than generating unnecessary paperwork, every document has a defined purpose, an owner, an evidential weight and a mapping to one or more contributing outcomes.
That makes it significantly easier to prepare for CAF assessments while simultaneously improving day-to-day cyber resilience.
One of the distinguishing features of the CAF Incident Response Document Library is that every document is assigned an evidential weighting. Rather than treating all documents equally, each artefact is classified according to the strength of evidence it provides during a CAF assessment.
Core Evidence: Core Evidence documents directly support the assessment of one or more CAF contributing outcomes. These documents typically include governance artefacts, approved policies, incident response plans, monitoring procedures, recovery plans, exercise reports and management evidence that an assessor would normally expect to review.
They form the primary evidence base used to demonstrate that the relevant outcome has been achieved.
Supporting Evidence: Supporting Evidence documents strengthen the wider evidence chain. These documents include operational guides, templates, reference material, checklists, working records and supporting registers that help demonstrate consistent implementation.
While they may not individually determine an assessment outcome, together they provide confidence that incident response activities are mature, repeatable and well governed.
To simplify document management, every artefact within the library follows a structured numbering convention.
Each document receives a unique identifier using the format:
CAF-IR-[TYPE]-[NNN]
Where:
Examples include:
Maintaining consistent identifiers simplifies version control, document references, audit trails and cross-linking between related artefacts.
Build a Complete Documentation Architecture: Instead of creating documents individually as gaps emerge, start with a complete incident response documentation framework containing 91 predefined artefacts organised into a logical structure.
Align Documentation with the Cyber Assessment Framework: Every document has been mapped to the relevant CAF contributing outcomes, making it significantly easier to understand how each artefact contributes to demonstrating cyber resilience during an assessment.
Focus on Evidence Rather Than Paperwork: CAF assessments evaluate evidence, not simply whether documents exist. The library has therefore been designed around the operational evidence that assessors expect to review rather than producing unnecessary documentation.
Improve Governance and Ownership: Each document can be assigned clear ownership, approval responsibilities and review cycles, helping organisations maintain documentation as an operational asset instead of a static compliance exercise.
Accelerate Assessment Preparation: Rather than spending weeks deciding what documentation should exist, security teams can begin with a structured architecture that reflects recognised incident response good practice.
Reduce Documentation Gaps: By presenting all 91 documents within one integrated framework, missing procedures, registers, playbooks and governance records become immediately visible.
Improve Cross-Team Consistency: Incident response rarely belongs to one department. The documentation framework supports consistent collaboration across departments.
Support Continuous Improvement: The framework extends well beyond planning and response. Dedicated categories covering testing, lessons learned, assurance and continual improvement help organisations demonstrate increasing maturity over time.
Integrate with Existing Document Management Systems: The recommended document identifiers and folder structure make it straightforward to implement the library within SharePoint, Microsoft Teams, document management platforms or GRC solutions.
Create a Sustainable Documentation Programme: Perhaps the greatest benefit is consistency. Rather than producing documents solely for an assessment, organisations establish documentation that continues supporting incident response throughout its operational lifecycle.
** GDPR & Privacy ** We wholeheartedly believe in your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data.
It is a structured guide containing 91 incident response documents organised into 13 categories and mapped to relevant outcomes within the NCSC Cyber Assessment Framework Version 4.0.
No. CAF is outcome-based rather than document-based. The library provides a practical documentation architecture that helps organisations demonstrate the evidence assessors typically expect to review.
The library contains 91 incident response documents covering governance, monitoring, investigations, recovery, resilience, communications, training, testing, continual improvement and supporting evidence.
Core Evidence documents provide primary evidence for one or more CAF contributing outcomes.
Supporting Evidence documents reinforce the wider evidence chain and demonstrate operational maturity.
Yes. The framework is intended to be customised to reflect each organisation's governance structure, technologies, incident response processes and regulatory obligations.
No. The guide provides the complete documentation architecture and explains the purpose of each document rather than supplying completed organisational templates.
The Master Register is a companion CSV control sheet that tracks ownership, approvals, review dates, implementation status, evidence locations and document versions across the complete documentation set.
Yes. The documentation framework has been designed around the Cyber Assessment Framework and can assist organisations preparing for GovAssure or other CAF-based assessments by improving documentation structure and evidence management.
Absolutely. Many organisations voluntarily adopt the Cyber Assessment Framework as a recognised cyber resilience model even when formal CAF assessments are not mandatory.
No. The guide provides a documentation architecture aligned to CAF outcomes.
Successful CAF assessments depend on operational capability, governance and demonstrable evidence—not documentation alone.
Documentation should be reviewed regularly and updated following incidents, exercises, audits, significant technology changes and governance reviews to ensure it continues reflecting operational practice.
ISO 27001 and NIS2 define different governance and regulatory expectations. The CAF Incident Response Document Library is specifically organised around the evidence required to demonstrate achievement of Cyber Assessment Framework outcomes, making it particularly useful for organisations using the NCSC assessment methodology.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.