Date: 11 August 2026
How the Code and CAF Connect
The Cyber Governance Code of Practice isn't a separate, unrelated initiative. The government has explicitly mapped it onto the CAF. Its own risk-management actions cross-reference CAF language directly: Action A2 of the Code requires boards to "agree senior ownership of cyber security risks and gain assurance that they are integrated into the organisation's wider enterprise risk management," which is the same governance chain A1.a assesses. The Code is, in effect, the practical checklist for satisfying what CAF's governance principle expects of a board, with the word "training" spelled out where CAF leaves it as an implied prerequisite.
NCSC backs this with free, purpose-built delivery: Cyber Governance Training: Five interactive modules aligned to the Code's principles, covering risk management, strategy and the other pillars boards are expected to act on. It exists precisely because a written Code of actions isn't the same as boards actually being equipped to perform them.
Is CAF Legally Binding the Way NIS2 or DORA Are?
Not in the same way. CAF is the assessment methodology regulators use, not primary legislation with its own penalty regime. For UK operators of essential services and relevant digital service providers under the NIS Regulations 2018, a competent authority (Ofgem, the ICO, ORR and others depending on sector) uses CAF outcomes to judge compliance. Therefore, failing A1.a isn't a paperwork gap, it's a governance finding a regulator can act on.
But there's no article-numbered clause saying "board members shall undertake training" the way NIS2 Article 20(2) or DORA Article 5(4) do. The obligation arrives indirectly, through the outcome CAF requires and the Code that operationalises it — which in practice makes it just as unavoidable for any board actually trying to pass an A1 assessment.
What This Means in Practice for Boards
- A trained "champion" isn't sufficient. A1.a requires a named board-level individual with overall accountability — but the "regular discussions… informed by expert guidance" language implies the whole board needs enough grounding to engage, not just defer to one person.
- Stale knowledge fails the same way stale information does. A1.a explicitly marks "partial or out-of-date information" as a failure condition — a board trained once years ago is functionally in the same position as a board never trained.
- Assurance has to be evidenced, not assumed. Action C4 requires the board to gain assurance "using suitable metrics" — a training programme with no completion tracking or effectiveness measure won't satisfy it.
- Annual exercising is the proof, not the training itself. Action D2's annual exercise is what turns board cyber literacy from a claim into demonstrated capability under pressure.
This is exactly the shape Cybersecurity Training for Executives and the Board Cyber Crisis Programme are built around, the former building the literacy Action C3 and CAF's "informed by expert guidance" language require, the latter delivering the realistic tabletop exercise that satisfies Action D2 and demonstrates the board can actually translate direction into effective practice, which is precisely what A1.a is assessing.
Common Mistakes Boards Make Against CAF's Governance Principle
- Treating A1.a as an org-chart exercise. Naming a board-level accountable individual satisfies part of the indicator, but not the "regular discussions… informed by expert guidance" requirement that applies to the whole board.
- Confusing IT reporting with board governance. A1.a fails where security is "not discussed or reported on regularly at board level" — a report that goes to a risk committee but never reaches full board discussion doesn't meet the bar.
- No metrics behind the training assurance. Action C4 specifically calls for "suitable metrics" — a training programme the board can't quantify or evidence doesn't satisfy the Code's own wording.
- Skipping the annual exercise. Training without the Action D2 exercise leaves the board unable to demonstrate the direction it sets actually converts into effective organisational practice, which is the exact failure condition A1.a names.
- Assuming CAF's silence on "training" means it's optional. The outcome CAF requires — informed, current, expert-guided board discussion — is not achievable without it, regardless of the word choice.
Getting Started
- Assess your board against A1.a's exact wording — ownership, regular discussion, expert-guided input, and translation into organisational practice — not just whether a security report reaches the board agenda.
- Adopt the Cyber Governance Code of Practice's People actions (C3 and C4) as your working standard, since they're the government's own operationalisation of CAF's governance expectations.
- Track training with metrics, per Action C4, so assurance is evidenced rather than assumed at the next audit or regulatory review.
- Run the annual exercise Action D2 requires, using the Board Cyber Crisis Programme to test decision-making under realistic pressure rather than leaving it untested until a real incident does the testing instead.
- Build board literacy deliberately, using Cybersecurity Training for Executives to close the specific "expert guidance" gap A1.a assumes the board already has.
Key Terms
- Cyber Assessment Framework (CAF): The NCSC's assessment framework of 14 principles across 4 objectives, used by UK regulators to assess cybersecurity outcomes for essential services and digital service providers.
- Indicator of Good Practice (IGP): The specific "Achieved" / "Not Achieved" statements under each CAF principle used to assess whether an outcome has been met.
- Board Direction (A1.a): The CAF indicator assessing whether an organisation's security approach is owned, discussed and driven at board level with expert-informed input.
- Cyber Governance Code of Practice: The UK government's action-based code for boards, mapped to CAF's outcomes, covering risk management, strategy, people, incident planning and assurance.
- Operator of Essential Services (OES): An organisation designated under the UK NIS Regulations 2018 whose cybersecurity is assessed by a competent authority using the CAF.
- Competent Authority: The sector regulator (such as Ofgem, the ICO or ORR) responsible for assessing OES and relevant digital service providers against CAF outcomes under the NIS Regulations 2018.
Frequently Asked Questions About the UK CAF Assessment
1. Does the UK CAF explicitly require board training?
Not by that name. CAF's Principle A1, Board Direction, requires the board to hold regular, expert-guided discussions on security and translate that direction into effective practice — an outcome that isn't achievable without board-level training, even though CAF's own wording doesn't use the term.
2. What does CAF Principle A1 actually require of the board?
A1.a requires the organisation's security approach to be owned and managed at board level, discussed regularly using timely and accurate information informed by expert guidance, driven by a named board-level accountable individual, and translated into effective organisational practice.
3. Does the Cyber Governance Code of Practice make board training mandatory?
The Code is government guidance rather than statute, but it states its actions directly: Action C3 requires each board member to undertake training to improve their own cyber literacy, and Action C4 requires the board to gain assurance that the wider organisation has an effective training programme.
4. Is CAF legally binding like NIS2 or DORA?
Not in the same way. CAF is the assessment methodology UK competent authorities use under the NIS Regulations 2018 to judge cybersecurity outcomes for essential services and digital service providers — it doesn't carry its own statutory clause naming individual training duties the way NIS2 Article 20(2) or DORA Article 5(4) do, but failing its governance indicator is still a regulatory finding.
5. What's the difference between CAF and the Cyber Governance Code of Practice?
CAF is the outcome-based assessment framework regulators use to judge whether governance, risk management and technical controls meet expectations. The Code of Practice is the government's action-based guidance for boards specifically, mapped onto CAF's outcomes, that spells out what boards should actually do — including training.
6. How often should board members refresh their CAF-related training?
CAF doesn't set an interval, but A1.a's failure condition explicitly names "partial or out-of-date information" as unacceptable, and the Code of Practice's Action D2 calls for at least annual exercising of the incident plan — both point to an annual cadence as the practical minimum.
7. Does an organisation need to be an operator of essential services for CAF to matter?
CAF was built for operators of essential services and relevant digital service providers under the UK NIS Regulations 2018, assessed by their sector's competent authority, but many organisations outside that formal scope use CAF voluntarily as a governance benchmark for their own cybersecurity maturity.
8. How can a board demonstrate it meets CAF's Board Direction indicator?
By evidencing regular, minuted board-level security discussions based on current information, a named accountable board member driving those discussions, individual training records per member, and at least an annual incident exercise showing that board direction actually converts into effective organisational practice.

.webp)
.webp)