Date: 11 August 2026
The 4 Objectives and 14 Principles At a Glance
Everything in a CAF assessment traces back to four objectives. Get comfortable with this table. It's the map assessors use, and it's the map your documentation needs to mirror.
|
Objective |
Focus |
Principles |
|
A — Managing security risk |
Governance, risk management, asset management, supply chain |
A1 Governance, A2 Risk Management, A3 Asset Management, A4 Supply Chain |
|
B — Protecting against cyber attack |
Access control, data security, system resilience, staff awareness |
B1 Service Protection Policies, B2 Identity & Access Control, B3 Data Security, B4 System Security, B5 Resilient Networks, B6 Staff Awareness & Training |
|
C — Detecting cyber security events |
Monitoring and anomaly detection |
C1 Security Monitoring, C2 Proactive Security Event Discovery |
|
D — Minimising the impact of incidents |
Response, recovery, and continuous improvement |
D1 Response and Recovery Planning, D2 Lessons Learned |
Each principle breaks down into contributing outcomes. 39 of them across the full framework and each contributing outcome is judged against detailed Indicators of Good Practice (IGPs), which describe the specific evidence an assessor looks for to conclude that outcome is "achieved," "partially achieved," or "not achieved."
This is the structural reason a spreadsheet doesn't scale as a CAF evidence base: you're not tracking 4 things, you're tracking 39 outcomes, each with its own IGP checklist, each needing a live link to the document or control that proves it.
CAF Profiles: Basic vs. Enhanced And Why "Achieved" isn't Binary
The CAF doesn't set one universal bar. Instead, a CAF Profile defines the target level of cyber resilience your organisation needs against a given level of attacker capability and NCSC defines two reference profiles.
|
Profile |
Target attacker capability |
Typical use case |
|
Basic |
Commodity capabilities available to less sophisticated attackers |
Baseline expectation for most OES |
|
Enhanced |
Bespoke capabilities available to sophisticated, well-resourced threat actors |
Higher-criticality operators, or sectors facing elevated targeted threat |
In practice, a CAF profile is a mixture: some contributing outcomes need to be met at "achieved," others might be acceptable at "partially achieved," depending on which profile your regulator has set for your sector and risk tier. NCSC Meeting "achieved" across all 39 contributing outcomes at the Enhanced level requires a genuinely different order of maturity, capability, and investment than scraping by at Basic.
The practical takeaway: know which profile your regulator expects of you before you start building evidence, because it changes which IGPs you need to satisfy and how rigorously.
Incident Reporting Under the CAF: the 72-Hour Clock
Objective D exists because the CAF assumes incidents will happen — the real test is how fast you detect, report, and recover. Under the UK NIS Regulations, an OES must notify its designated competent authority of an incident causing (or likely to cause) significant disruption to its essential service no later than 72 hours after becoming aware of it. legislation.gov.uk RDSPs face broadly equivalent notification duties, with the ICO as their competent authority.
What assessors and regulators actually want to see as evidence of D1 (Response and Recovery Planning) and D2 (Lessons Learned):
- A documented, tested incident response plan with clearly assigned roles and escalation paths.
- A pre-drafted notification template mapped to your specific competent authority's reporting format and the 72-hour clock.
- Evidence of exercises or drills — a plan that's never been tested is a common gap assessors flag.
- A post-incident review process that feeds identified weaknesses back into your risk register and controls — this is what separates D1 from D2 in an assessment.
- A running log of past incidents (even near-misses), because "we've never had one" is not the same as "we have a working process."
If you can't produce these on request, in an assessment window, you don't have a resilient incident response function — you have an intention.
Where Organisations Actually Lose Marks
Across CAF assessments and sector regulator reviews, the same gaps recur:
- Supply chain (A4) treated as a one-off exercise. Regulators expect an active, current view of third-party risk, not a supplier list compiled once for the last audit.
- Evidence scattered across drives, emails, and personal folders. Assessors need to trace a contributing outcome to a specific, current document — if that takes your team three days to assemble, the outcome effectively isn't demonstrable at assessment time.
- Policies that exist but were never operationalised. A written access control policy that nobody follows fails B2 in practice, even if it reads well on paper.
- Incident response plans that were never rehearsed. This is the single most common Objective D finding — the plan exists, but there's no evidence it works under pressure.
- No clear ownership per contributing outcome. With 39 outcomes across 4 objectives, "everyone's responsible" usually means no one is, and it shows the moment an assessor asks who owns a specific control.
Turning the CAF into a Live Compliance System
The CAF's own structure — objectives, principles, contributing outcomes, IGPs — is effectively a taxonomy waiting to be operationalised. The organisations that sail through assessments aren't the ones with the most documents; they're the ones where every one of the 39 contributing outcomes maps cleanly to a specific piece of evidence, owned by a named person, kept current.
That's exactly the gap a UK CAF IR Document Library and Register is built to close:
- The Document Library gives you pre-mapped policies and templates aligned to each CAF objective and principle — governance frameworks, access control policies, supply chain risk policies, and incident response plans structured around Objective D and the 72-hour notification clock — so you're not drafting 39 outcomes' worth of evidence from a blank page.
- The UK CAF Master Document Register keeps your asset inventory, supply chain risk register, and incident log live and audit-ready, with each entry linked back to the contributing outcome and IGP it satisfies — so when your competent authority asks for evidence against a specific principle, you have the answer in minutes, not days.
Once you know your CAF profile and objective gaps, the next step is mapping your existing evidence against the framework in your Register — that's where scattered documents turn into an assessment-ready system.
FAQs about UK CAF Compliance
1. What is the UK Cyber Assessment Framework (CAF)?
The CAF is a framework developed by the NCSC to help organisations and regulators assess how well cyber security risks to essential functions are being managed. It's built around 4 objectives, 14 principles, and 39 contributing outcomes, each assessed using detailed Indicators of Good Practice (IGPs), and it underpins enforcement of the UK NIS Regulations 2018.
2. Who has to comply with the CAF in the UK?
Operators of Essential Services (OES) in sectors like energy, transport, water, health, and digital infrastructure, and Relevant Digital Service Providers (RDSPs) such as online marketplaces, search engines, and cloud providers, are assessed against the CAF by their sector's competent authority (for example, Ofgem for energy, or the ICO for RDSPs) under the UK NIS Regulations 2018.
3. What are the four objectives of the CAF?
The four objectives are: Objective A, managing security risk (governance, risk management, asset management, supply chain); Objective B, protecting against cyber attack (access control, data security, system resilience, staff training); Objective C, detecting cyber security events (monitoring); and Objective D, minimising the impact of incidents (response, recovery, lessons learned).
4. What's the difference between the Basic and Enhanced CAF Profile?
A CAF Profile sets the target level of resilience against a defined level of attacker capability. The Basic Profile targets resilience against commodity attack capabilities used by less sophisticated actors, while the Enhanced Profile targets resilience against bespoke capabilities used by sophisticated, well-resourced threat actors. Your regulator assigns which profile applies to your organisation based on sector and risk tier.
5. How quickly must I report an incident under the UK NIS Regulations?
Operators of Essential Services must notify their competent authority no later than 72 hours after becoming aware of an incident that has caused, or is likely to cause, significant disruption to their essential service. Relevant Digital Service Providers face broadly equivalent notification obligations to the ICO.
6. What happens if my organisation fails a CAF assessment or breaches the NIS Regulations?
Competent authorities can issue fines of up to £17 million for the most serious breaches of the UK NIS Regulations, alongside enforcement notices and increased regulatory scrutiny. Beyond financial penalties, a failed assessment typically triggers a remediation plan and follow-up review, and repeated non-compliance can affect an organisation's ability to operate in a regulated capacity.
7. What is an Indicator of Good Practice (IGP)?
An Indicator of Good Practice is the specific, detailed evidence criterion an assessor uses to judge whether a contributing outcome under the CAF has been "achieved," "partially achieved," or "not achieved." Each of the CAF's 39 contributing outcomes has its own set of IGPs, which together make up the practical checklist behind an assessment.
8. How do I prepare documentation and evidence for a CAF assessment?
Preparation means mapping every one of the 39 contributing outcomes to a specific, current document or control, with clear ownership and an audit trail showing it's operational (not just written policy). Maintaining this mapping in a live document library and register, rather than rebuilding evidence from scratch before each assessment cycle, is what keeps an organisation consistently audit-ready rather than scrambling under deadline.



