The UK Cyber Assessment Framework (CAF) is the UK National Cyber Security Centre's official framework for assessing cyber resilience, used to enforce the UK NIS Regulations 2018 across operators of essential services and relevant digital service providers. It's built around 4 objectives, 14 principles, and Indicators of Good Practice (IGPs), assessed against a target CAF Profile (Basic or Enhanced), with mandatory incident notification to your competent authority within 72 hours of becoming aware of a qualifying incident. Non-compliance can carry fines of up to £17 million.
The article below covers exactly what regulators check, what "achieved" actually means at assessment time, and what documentation and incident-reporting evidence you need to have ready before an assessor asks for it.
The CAF was developed by the NCSC to give a consistent, outcome-based method for judging whether an organisation is managing cyber risk to its essential functions appropriately, not a pass/fail checklist, but a structured judgement of maturity against real-world attack capability.
It's the technical backbone behind the UK NIS Regulations 2018, which apply to two groups of organisations:
|
Entity type |
Who this covers |
Competent authority example |
|
Operators of Essential Services (OES) |
Energy, transport, water, health, digital infrastructure providers whose disruption would significantly affect the UK |
Ofgem (energy), DfT/ORR (transport), DWI (water), DHSC (health) |
|
Relevant Digital Service Providers (RDSPs) |
Online marketplaces, online search engines, cloud computing services |
ICO |
If you're an OES, your sector regulator uses the CAF (or a sector-adapted version of it) to assess you directly. If you're not formally in scope but supply into a regulated operator's supply chain, you'll increasingly meet CAF-derived questions in vendor security assessments regardless — the framework has become the de facto reference model UK organisations use to benchmark cyber resilience even outside strict NIS scope. Source: WALLIX
Everything in a CAF assessment traces back to four objectives. Get comfortable with this table. It's the map assessors use, and it's the map your documentation needs to mirror.
|
Objective |
Focus |
Principles |
|
A — Managing security risk |
Governance, risk management, asset management, supply chain |
A1 Governance, A2 Risk Management, A3 Asset Management, A4 Supply Chain |
|
B — Protecting against cyber attack |
Access control, data security, system resilience, staff awareness |
B1 Service Protection Policies, B2 Identity & Access Control, B3 Data Security, B4 System Security, B5 Resilient Networks, B6 Staff Awareness & Training |
|
C — Detecting cyber security events |
Monitoring and anomaly detection |
C1 Security Monitoring, C2 Proactive Security Event Discovery |
|
D — Minimising the impact of incidents |
Response, recovery, and continuous improvement |
D1 Response and Recovery Planning, D2 Lessons Learned |
Each principle breaks down into contributing outcomes. 39 of them across the full framework and each contributing outcome is judged against detailed Indicators of Good Practice (IGPs), which describe the specific evidence an assessor looks for to conclude that outcome is "achieved," "partially achieved," or "not achieved."
This is the structural reason a spreadsheet doesn't scale as a CAF evidence base: you're not tracking 4 things, you're tracking 39 outcomes, each with its own IGP checklist, each needing a live link to the document or control that proves it.
The CAF doesn't set one universal bar. Instead, a CAF Profile defines the target level of cyber resilience your organisation needs against a given level of attacker capability and NCSC defines two reference profiles.
|
Profile |
Target attacker capability |
Typical use case |
|
Basic |
Commodity capabilities available to less sophisticated attackers |
Baseline expectation for most OES |
|
Enhanced |
Bespoke capabilities available to sophisticated, well-resourced threat actors |
Higher-criticality operators, or sectors facing elevated targeted threat |
In practice, a CAF profile is a mixture: some contributing outcomes need to be met at "achieved," others might be acceptable at "partially achieved," depending on which profile your regulator has set for your sector and risk tier. NCSC Meeting "achieved" across all 39 contributing outcomes at the Enhanced level requires a genuinely different order of maturity, capability, and investment than scraping by at Basic.
The practical takeaway: know which profile your regulator expects of you before you start building evidence, because it changes which IGPs you need to satisfy and how rigorously.
Objective D exists because the CAF assumes incidents will happen — the real test is how fast you detect, report, and recover. Under the UK NIS Regulations, an OES must notify its designated competent authority of an incident causing (or likely to cause) significant disruption to its essential service no later than 72 hours after becoming aware of it. legislation.gov.uk RDSPs face broadly equivalent notification duties, with the ICO as their competent authority.
What assessors and regulators actually want to see as evidence of D1 (Response and Recovery Planning) and D2 (Lessons Learned):
If you can't produce these on request, in an assessment window, you don't have a resilient incident response function — you have an intention.
Across CAF assessments and sector regulator reviews, the same gaps recur:
The CAF's own structure — objectives, principles, contributing outcomes, IGPs — is effectively a taxonomy waiting to be operationalised. The organisations that sail through assessments aren't the ones with the most documents; they're the ones where every one of the 39 contributing outcomes maps cleanly to a specific piece of evidence, owned by a named person, kept current.
That's exactly the gap a UK CAF IR Document Library and Register is built to close:
Once you know your CAF profile and objective gaps, the next step is mapping your existing evidence against the framework in your Register — that's where scattered documents turn into an assessment-ready system.
1. What is the UK Cyber Assessment Framework (CAF)?
The CAF is a framework developed by the NCSC to help organisations and regulators assess how well cyber security risks to essential functions are being managed. It's built around 4 objectives, 14 principles, and 39 contributing outcomes, each assessed using detailed Indicators of Good Practice (IGPs), and it underpins enforcement of the UK NIS Regulations 2018.
2. Who has to comply with the CAF in the UK?
Operators of Essential Services (OES) in sectors like energy, transport, water, health, and digital infrastructure, and Relevant Digital Service Providers (RDSPs) such as online marketplaces, search engines, and cloud providers, are assessed against the CAF by their sector's competent authority (for example, Ofgem for energy, or the ICO for RDSPs) under the UK NIS Regulations 2018.
3. What are the four objectives of the CAF?
The four objectives are: Objective A, managing security risk (governance, risk management, asset management, supply chain); Objective B, protecting against cyber attack (access control, data security, system resilience, staff training); Objective C, detecting cyber security events (monitoring); and Objective D, minimising the impact of incidents (response, recovery, lessons learned).
4. What's the difference between the Basic and Enhanced CAF Profile?
A CAF Profile sets the target level of resilience against a defined level of attacker capability. The Basic Profile targets resilience against commodity attack capabilities used by less sophisticated actors, while the Enhanced Profile targets resilience against bespoke capabilities used by sophisticated, well-resourced threat actors. Your regulator assigns which profile applies to your organisation based on sector and risk tier.
5. How quickly must I report an incident under the UK NIS Regulations?
Operators of Essential Services must notify their competent authority no later than 72 hours after becoming aware of an incident that has caused, or is likely to cause, significant disruption to their essential service. Relevant Digital Service Providers face broadly equivalent notification obligations to the ICO.
6. What happens if my organisation fails a CAF assessment or breaches the NIS Regulations?
Competent authorities can issue fines of up to £17 million for the most serious breaches of the UK NIS Regulations, alongside enforcement notices and increased regulatory scrutiny. Beyond financial penalties, a failed assessment typically triggers a remediation plan and follow-up review, and repeated non-compliance can affect an organisation's ability to operate in a regulated capacity.
7. What is an Indicator of Good Practice (IGP)?
An Indicator of Good Practice is the specific, detailed evidence criterion an assessor uses to judge whether a contributing outcome under the CAF has been "achieved," "partially achieved," or "not achieved." Each of the CAF's 39 contributing outcomes has its own set of IGPs, which together make up the practical checklist behind an assessment.
8. How do I prepare documentation and evidence for a CAF assessment?
Preparation means mapping every one of the 39 contributing outcomes to a specific, current document or control, with clear ownership and an audit trail showing it's operational (not just written policy). Maintaining this mapping in a live document library and register, rather than rebuilding evidence from scratch before each assessment cycle, is what keeps an organisation consistently audit-ready rather than scrambling under deadline.