The UK Cyber Assessment Framework (CAF) is how the NCSC and UK regulators assess whether an organisation's cybersecurity meets the outcomes expected under the UK NIS Regulations 2018 and equivalent regimes. Fourteen principles across four objectives, each broken into indicators of good practice, CAF is thorough on technical and process detail. Where it gets interesting is governance: the CAF doesn't use the word "training" when it talks about the board. It talks about something arguably stricter: A board that can't function without it.
Principle A1, Governance, is unambiguous about where accountability sits: "The organisation has appropriate management policies, processes and procedures in place to govern its approach to the security of network and information systems."
The indicator that matters most here is A1.a, Board Direction. To be assessed as "Achieved," all of the following must be true:
Conversely, an organisation is marked "Not Achieved" if even one of these is true: security isn't discussed or reported on regularly at board level; board discussions rely on partial or out-of-date information without expert guidance; direction from the board doesn't effectively drive security practice; or senior management treats itself as exempt from policies everyone else follows.
Read that "Achieved" column carefully and the training question answers itself. A board cannot hold "regular discussions… informed by expert guidance" or translate direction into "effective organisational practices" if its members don't understand what they're discussing. CAF doesn't mandate a training certificate. It mandates the outcome that training exists to produce, which is functionally the same requirement approached from the other direction.
This is where the UK government stopped leaving board competence implicit. The Cyber Governance Code of Practice, published by DSIT and underpinned by NCSC resources, sets out concrete actions boards need to take and unlike CAF's outcome-based language, it names training directly.
Under Section C: People, the Code states:
Action C3 — "Undertake training to improve your own cyber literacy and take responsibility for the security of the data and digital assets that you use."
Action C4 — "Gain assurance, using suitable metrics, that the organisation has an effective cyber security training, education and awareness programme."
Action C3 puts the obligation on each individual board member personally — "your own cyber literacy" — echoing the individual-member framing NIS2's Article 20(2) and DORA's Article 5(4) both use. Action C4 then makes the board accountable for the wider organisation's training programme, not just its own.
The Code also closes the loop on testing that competence rather than just delivering it. Under Section D: Incident planning, response and recovery:
Action D2 — "Gain assurance that there is at least annual exercising of the plan involving relevant internal and external stakeholders and that lessons from the exercise are reflected in the incident plan (Action D1) and risk assessments (Action A5)."
An annual tabletop exercise isn't framed as optional best practice here. It's the mechanism the Code uses to verify that board-level cyber literacy is real rather than certificated.
The Cyber Governance Code of Practice isn't a separate, unrelated initiative. The government has explicitly mapped it onto the CAF. Its own risk-management actions cross-reference CAF language directly: Action A2 of the Code requires boards to "agree senior ownership of cyber security risks and gain assurance that they are integrated into the organisation's wider enterprise risk management," which is the same governance chain A1.a assesses. The Code is, in effect, the practical checklist for satisfying what CAF's governance principle expects of a board, with the word "training" spelled out where CAF leaves it as an implied prerequisite.
NCSC backs this with free, purpose-built delivery: Cyber Governance Training: Five interactive modules aligned to the Code's principles, covering risk management, strategy and the other pillars boards are expected to act on. It exists precisely because a written Code of actions isn't the same as boards actually being equipped to perform them.
Not in the same way. CAF is the assessment methodology regulators use, not primary legislation with its own penalty regime. For UK operators of essential services and relevant digital service providers under the NIS Regulations 2018, a competent authority (Ofgem, the ICO, ORR and others depending on sector) uses CAF outcomes to judge compliance. Therefore, failing A1.a isn't a paperwork gap, it's a governance finding a regulator can act on.
But there's no article-numbered clause saying "board members shall undertake training" the way NIS2 Article 20(2) or DORA Article 5(4) do. The obligation arrives indirectly, through the outcome CAF requires and the Code that operationalises it — which in practice makes it just as unavoidable for any board actually trying to pass an A1 assessment.
This is exactly the shape Cybersecurity Training for Executives and the Board Cyber Crisis Programme are built around, the former building the literacy Action C3 and CAF's "informed by expert guidance" language require, the latter delivering the realistic tabletop exercise that satisfies Action D2 and demonstrates the board can actually translate direction into effective practice, which is precisely what A1.a is assessing.
1. Does the UK CAF explicitly require board training?
Not by that name. CAF's Principle A1, Board Direction, requires the board to hold regular, expert-guided discussions on security and translate that direction into effective practice — an outcome that isn't achievable without board-level training, even though CAF's own wording doesn't use the term.
2. What does CAF Principle A1 actually require of the board?
A1.a requires the organisation's security approach to be owned and managed at board level, discussed regularly using timely and accurate information informed by expert guidance, driven by a named board-level accountable individual, and translated into effective organisational practice.
3. Does the Cyber Governance Code of Practice make board training mandatory?
The Code is government guidance rather than statute, but it states its actions directly: Action C3 requires each board member to undertake training to improve their own cyber literacy, and Action C4 requires the board to gain assurance that the wider organisation has an effective training programme.
4. Is CAF legally binding like NIS2 or DORA?
Not in the same way. CAF is the assessment methodology UK competent authorities use under the NIS Regulations 2018 to judge cybersecurity outcomes for essential services and digital service providers — it doesn't carry its own statutory clause naming individual training duties the way NIS2 Article 20(2) or DORA Article 5(4) do, but failing its governance indicator is still a regulatory finding.
5. What's the difference between CAF and the Cyber Governance Code of Practice?
CAF is the outcome-based assessment framework regulators use to judge whether governance, risk management and technical controls meet expectations. The Code of Practice is the government's action-based guidance for boards specifically, mapped onto CAF's outcomes, that spells out what boards should actually do — including training.
6. How often should board members refresh their CAF-related training?
CAF doesn't set an interval, but A1.a's failure condition explicitly names "partial or out-of-date information" as unacceptable, and the Code of Practice's Action D2 calls for at least annual exercising of the incident plan — both point to an annual cadence as the practical minimum.
7. Does an organisation need to be an operator of essential services for CAF to matter?
CAF was built for operators of essential services and relevant digital service providers under the UK NIS Regulations 2018, assessed by their sector's competent authority, but many organisations outside that formal scope use CAF voluntarily as a governance benchmark for their own cybersecurity maturity.
8. How can a board demonstrate it meets CAF's Board Direction indicator?
By evidencing regular, minuted board-level security discussions based on current information, a named accountable board member driving those discussions, individual training records per member, and at least an annual incident exercise showing that board direction actually converts into effective organisational practice.