Cyber Security Blog

How to Prepare for a CAF Assessment: A Step-by-Step Checklist

Written by Aditi Uberoi | 4 September 2026

 A CAF assessment prepares an organisation to demonstrate cyber resilience against the NCSC Cyber Assessment Framework by gathering evidence, mapping it to the framework's outcomes, and closing gaps before a formal review. Preparation involves confirming your scope and essential functions, assembling outcome-based evidence, running a gap analysis against the 14 principles, and organising documentation so an assessor can trace every claim to proof. 

The Cyber Assessment Framework (CAF) is not a tick-box checklist. It is an outcome-based framework. Assessors judge whether you can genuinely demonstrate mature cyber resilience through governance, processes, evidence and operational capability. That distinction is the single most important thing to understand before you prepare. You are not collecting mandatory documents. You are building a defensible evidence story.

This guide walks through exactly how to get ready, step by step.

What is a CAF Assessment?

A CAF assessment measures how well an organisation manages cyber risks to its essential functions against four objectives and 14 principles, each broken down into contributing outcomes. Each outcome is graded Achieved, Partially Achieved or Not Achieved, based on Indicators of Good Practice (IGPs). The result is a maturity picture across governance, protection, detection and response. 

Because judgement is evidence-led, preparation is really about making your resilience visible and traceable.

Who Needs to Prepare for a CAF Assessment?

The CAF is designed primarily for organisations that provide essential services or operate under UK regulatory oversight. For example, operators in NIS-regulated sectors such as energy, health, transport, water, telecoms and finance, and central government bodies under GovAssure. That said, any organisation that wants to align with the NCSC's best-practice resilience model can use the CAF to benchmark and improve, whether or not they are formally regulated.

If you fall into any of those groups, the checklist below applies to you.

How to Prepare for a CAF assessment: The Step-by-Step Checklist

Step 1: Confirm your scope and essential functions

Identify the essential functions the assessment covers and the systems, data and people that support them. Everything downstream — evidence, risk decisions, boundaries — hangs off this. Get it wrong and you either over-scope (wasted effort) or under-scope (a failed outcome).

Step 2: Understand the framework's structure

Map the four objectives (A: Managing security risk, B: Protecting against cyber attack, C: Detecting cyber security events, D: Minimising the impact of incidents) and the 14 principles beneath them. For each contributing outcome, read the IGPs so you know precisely what "Achieved" looks like in the assessor's eyes.

Step 3: Run a gap analysis against each outcome

For every contributing outcome, honestly grade yourself Achieved/Partially Achieved/Not Achieved and note why. This is where an independent, expert-led review pays for itself. An experienced assessor sees the gaps you've normalised. Cyber Management Alliance's NCSC-Assured CAF Assessment produces exactly this: a maturity benchmark across the CAF principles, risk ratings, and a prioritised remediation roadmap.

Step 4: Assemble outcome-based evidence

Gather the governance records, policies, processes, logs and operational proof that show each outcome is genuinely met. Remember the CAF is not satisfied by a policy sitting in a folder. Assessors want evidence the process is lived: approvals, review dates, test results, real incident records.

Step 5: Organise your documentation for traceability

An assessor should be able to pick any outcome and immediately find the evidence behind it. This is where most preparation stalls, particularly on Objective D (Minimising the impact of incidents), where incident-response evidence is typically scattered across shared drives.

Two resources make this dramatically easier:

  • The CAF Incident Response Document Library: A complete documentation architecture of 91 incident-response documents across 13 categories, each mapped to the relevant CAF v4.0 contributing outcomes and weighted by how strongly it supports an assessor's judgement.
  • The CAF Incident Response Master Document Register: An Excel-ready control sheet that tracks all 91 documents in one place: ownership, approval status, CAF mapping, review dates and evidence location. Its Core/Supporting evidence split tells you in advance which documents an assessment will focus on.

Together they turn "we think we have the evidence somewhere" into a single, controlled source of truth with direct CAF outcome traceability.

Step 6: Prioritise and close the highest-risk gaps

Not all gaps are equal. Fix the ones that undermine a Core outcome first, especially any "Not Achieved" grading on an essential function. Sequence remediation by risk, not by whichever fix is easiest.

Step 7: Test your incident response capability

Objective D can't be evidenced by documents alone. Assessors want proof your plans work. Run a tabletop exercise or cyber drill against a realistic scenario, capture the lessons learned, and feed them back into your plans and playbooks. This closes the loop the CAF explicitly looks for under Response and Recovery Planning and Lessons Learned.

Step 8: Conduct a readiness review before the formal assessment

Do a full dry run. Walk each outcome as if you were the assessor. Confirm every claim traces to evidence, and check nothing has drifted out of date. Only then book the formal assessment.

Common Mistakes that Derail CAF Preparation

  • Treating the CAF as a checklist. It is outcome-based; a stack of policies with no operational proof will still score Partially Achieved.
  • Under-scoping essential functions. Miss a supporting system and you miss its evidence.
  • Neglecting Objective D. Incident-response documentation is the most commonly disorganised area — and one of the most heavily assessed.
  • Evidence with no ownership or review dates. Assessors read stale, unowned documents as a governance failure.
  • Leaving remediation until after the assessment. A structured gap analysis first is far cheaper than re-assessment.

How Long Does CAF preparation take?

It depends on your starting maturity and scope, but the pattern is consistent: organisations with organised, owned, outcome-mapped evidence prepare far faster than those starting from scattered documentation. Front-loading Steps 1, 2 and 5 — scope, framework understanding, and documentation traceability — is what compresses the timeline.

Frequently Asked Questions About CAF Assessments

1. What is a CAF assessment?

A CAF assessment evaluates how well an organisation manages cyber risks to its essential functions against the NCSC Cyber Assessment Framework's four objectives and 14 principles, grading each contributing outcome as Achieved, Partially Achieved or Not Achieved.

2. Is the CAF a checklist of mandatory documents?

No. The CAF is an outcome-based framework. It assesses whether you can demonstrate mature cyber resilience through evidence, governance, processes and operational capability, not whether you hold a fixed list of documents.

3. How do I evidence incident response for a CAF assessment?

Incident response sits under CAF Objective D. Evidence it with owned, in-date, outcome-mapped documentation — plans, playbooks, registers, logs and tested exercises. A structured set such as the CAF Incident Response Document Library, tracked in a master document register, maps this evidence directly to the relevant CAF outcomes.

4. Should I do a self-assessment or an independent CAF assessment?

A self-assessment is a useful starting point, but an independent, expert-led assessment surfaces gaps you've normalised and gives you a defensible maturity benchmark and prioritised roadmap. Many regulated organisations use an independent assessment to validate readiness before a formal review.

5. Who needs a CAF assessment?

Primarily organisations providing essential services or operating under UK regulatory oversight, such as NIS-relevant sectors. Any organisation seeking to align with the NCSC's best-practice resilience model can also benefit.