Cyber Security Blog

UK CAF: Why You Need an Assessment-Ready Document Library and Register

Written by Aditi Uberoi | 20 August 2026

Passing a UK Cyber Assessment Framework (CAF) assessment isn't about having policies. It's about proving, for each of the 39 contributing outcomes across Objectives A-D, exactly which document satisfies it, who owns it, and when it was last reviewed. A pre-mapped CAF Document Library paired with a live UK CAF Master Document Register turns that proof from a weeks-long scramble into something you can produce on request, because every policy is already tagged to the objective, principle, and Indicator of Good Practice (IGP) it evidences.

The CAF doesn't fail organisations for lacking documents, it fails them for having documents nobody can locate, link to a control, or prove is current. Everything below explains exactly where that breaks down, and what a proper Library-plus-Register setup fixes.

Why CAF Assessments Are Actually Document Assessments in Disguise

The CAF looks like a technical security framework — four objectives, fourteen principles, monitoring, incident response. But when an assessor or your competent authority actually sits down to score you, what they're doing is checking evidence against Indicators of Good Practice for each of the 39 contributing outcomes. Evidence, in nearly every case, means a document: a policy, a risk register entry, a training record, a test report, an incident log.

That means your real CAF deliverable isn't "good security" in the abstract — it's a defensible, current, traceable set of documents that maps one-to-one onto the framework's own structure. Most organisations don't fail the CAF because their controls are weak. They fail or stall for months mid-assessment because:

  • Policies exist but live in someone's inbox, a departed employee's OneDrive, or three conflicting versions on a shared drive.
  • Nobody can say, in the room, which specific document satisfies Principle B2 (Identity and Access Control) versus B3 (Data Security).
  • A policy was written for the last audit cycle and never updated, so its "last reviewed" date undercuts its own credibility as evidence.
  • Ownership is diffuse — three people think someone else owns the supply chain risk policy, and none of them can produce the current version fast.

This is a structural problem, not a security-maturity problem. And it's exactly the problem a Document Library and Master Document Register are built to solve.

What a Proper CAF Document Library Actually Needs to Contain

A generic policy template pack doesn't map to the CAF — it maps to whatever framework its authors had in mind (often ISO 27001, sometimes nothing in particular). A CAF-specific library is structured around the framework's own taxonomy, so every document has an unambiguous home.

CAF Objective

Principle examples

Document types the library should provide

A — Managing security risk

Governance, Risk Management, Asset Management, Supply Chain

Governance charter, risk management policy, asset inventory procedure, supply chain security policy

B — Protecting against cyber attack

Access Control, Data Security, System Security, Staff Awareness

Access control policy, data classification & handling policy, system hardening standard, security awareness training programme

C — Detecting cyber security events

Security Monitoring, Proactive Discovery

Monitoring and logging policy, threat detection procedure

D — Minimising impact of incidents

Response & Recovery, Lessons Learned

Incident response plan, business continuity plan, post-incident review procedure

The difference between a useful library and a folder of downloaded templates is in three things:

  1. Every document is pre-tagged to its objective, principle, and contributing outcome. So when an assessor asks "show me evidence for A4," you're not hunting, you're filtering.
  2. Every document is written to the IGP language the framework actually uses. Therefore, the policy reads as evidence an assessor recognises, not a generic security policy that happens to cover similar ground.
  3. Every document carries a version history and review date built in — because "achieved" requires currency, not just existence.

Why A Static Library Alone Still isn't Enough — You Need the Register

Documents describe what your organisation is supposed to do. A Register proves what's actually true right now — your live asset inventory, your current supplier list and their risk tier, your open and closed incidents, your control ownership. This is where most CAF preparation quietly breaks, because a policy document can say "we maintain an up-to-date asset inventory" while the actual inventory is nine months stale in a spreadsheet nobody's opened.

A Master Document Register closes that gap by giving you one live, structured source of truth that:

  • Lists every document required across all 39 contributing outcomes, with its current version, owner, and last review date visible at a glance.
  • Flags documents that are overdue for review before an assessor does.
  • Links each register entry directly to the CAF objective, principle, and IGP it evidences — so evidence retrieval during an assessment is a lookup, not an investigation.
  • Tracks your asset inventory and supply chain risk entries as living data, not static attachments, satisfying Objective A's expectation that these are genuinely maintained, not just documented once.
  • Gives you an audit trail showing who changed what and when — itself a piece of evidence, since assessors increasingly want to see governance of the evidence, not just the evidence. 
 

Static template folder

Document Library + Master Register

Mapped to CAF objectives/principles

Rarely, or manually by your team

Pre-mapped by design

Ownership visibility

Tribal knowledge

Named owner per document, always visible

Currency

Unknown until someone checks

Review dates tracked and flagged automatically

Evidence retrieval during assessment

Manual search across drives/inboxes

Direct lookup by objective, principle, or IGP

Supply chain and asset data

Static snapshot, ages immediately

Live register, continuously current

Incident log and lessons learned

Scattered emails and tickets

Structured record linked to D1/D2 evidence

What This Looks Like at Assessment Time

Picture the moment your competent authority (Ofgem, the ICO, DfT, or whichever regulator applies to your sector) asks you to demonstrate Principle A4 — supply chain risk management. With a static folder, that means someone tracking down the last supplier risk assessment, checking whether it's actually current, confirming who signed it off, and hoping the version they find is the real one. That can eat days, and every day of delay reads to an assessor as evidence the control isn't actually operational day-to-day.

With a Library and Register working together, the same request becomes: filter to A4, pull the current supply chain security policy and the live supplier risk register, both already showing their last review date and owner. The evidence isn't reconstructed for the assessment — it's the same evidence your organisation uses to run supply chain risk management on an ordinary Tuesday. That distinction, evidence that's lived-in versus evidence that's produced on demand, is often what separates a smooth Basic-Profile pass from a stalled Enhanced-Profile review with follow-up remediation requests.

Getting Started: Mapping What You Have Against What the CAF Needs

Before rebuilding anything, most organisations benefit from a gap exercise: take your four objectives and fourteen principles, and for each, ask whether you have (a) a current document that addresses it, (b) a named owner, and (c) a review date within the last twelve months. Anywhere you can't answer all three cleanly is where the CAF assessment will find you first.

Rather than running that exercise once and letting it go stale again, running it inside a UK CAF IR Document Library and Master Document Register keeps the answer current permanently — every document pre-mapped to its objective and principle from day one, every asset and supplier entry live rather than static, and every review date tracked automatically instead of discovered under deadline pressure.

FAQs on UK CAF Documentation  

1. What documents do I need for a UK CAF assessment?

You need a document mapped to each of the CAF's 39 contributing outcomes across the four objectives — governance and risk management policies for Objective A, access control and data security policies for Objective B, monitoring procedures for Objective C, and incident response and lessons-learned procedures for Objective D. Each needs a clear owner and a recent review date to count as valid evidence.

2. What's the difference between a Document Library and a Document Register in CAF compliance?

A Document Library is the set of policies, procedures, and templates themselves — the written evidence. A Document Register is the live index that tracks which document satisfies which CAF objective and principle, who owns it, when it was last reviewed, and where current asset and supplier data lives. The Library provides the evidence; the Register proves it's current and locatable.

3. Why do organisations fail CAF assessments even when their security is reasonably strong?

Most CAF assessment delays come from documentation problems, not security gaps: policies that exist but can't be quickly located, ownership that's unclear, or evidence that's outdated relative to its "last reviewed" date. Assessors score against Indicators of Good Practice, and an unlocatable or stale document doesn't count as evidence even if the underlying control is actually sound.

4. How often do CAF documents need to be reviewed?

There's no single fixed interval mandated across all documents, but assessors expect evidence that policies are actively maintained, not written once and forgotten. A live register that flags documents approaching or past their review date is the practical way to keep every policy demonstrably current rather than discovering staleness during an assessment.

5. Does my supply chain risk register need to be a live document?

Yes. Objective A's supply chain principle expects an active, current view of your suppliers and their risk profile, not a one-time snapshot. A static list compiled for a previous audit cycle will read as evidence the control isn't genuinely operational, since supplier relationships and risk levels change continuously.

6. Who should own each document in a CAF Document Library?

Every document should have one named individual accountable for its accuracy and review cycle — diffuse or shared ownership is one of the most common reasons evidence retrieval stalls during an assessment. A Master Document Register makes ownership visible at a glance rather than something your team has to work out under time pressure.

7. Can a Document Library and Register help with both Basic and Enhanced CAF Profiles?

Yes. The mapping structure (objective, principle, contributing outcome, IGP) is the same regardless of which profile your regulator has assigned; what changes is the rigour expected in the evidence itself. A properly mapped Register makes it straightforward to see which contributing outcomes need to move from "partially achieved" to "achieved" as you progress toward an Enhanced Profile.

8. How does a Document Register help during incident response evidence for Objective D?

A Register keeps your incident log, response plan version, and post-incident review records linked directly to Objective D's contributing outcomes, so you can show not just that a plan exists but that it's been exercised and that lessons learned have fed back into your controls. That link between plan and evidence of testing is exactly what separates D1 and D2 evidence from a document that was never used.