Standards & Frameworks·28 August 2026

NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence

A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what evidence satisfies an assessor.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
6 min read
Share
NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence
Standards & Frameworks

Why it matters

What this means for organisations holding critical data

A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what evidence satisfies an assessor.

Written by Mark Fermor. The Cyber Assessment Framework is the assessment model the National Cyber Security Centre publishes for organisations that operate essential functions. This guide explains its structure, how assessment actually works, and where organisations most often fail to evidence an outcome they believe they achieve.

What the CAF is for

The CAF exists to answer a specific question: is the cyber risk to an essential function being managed appropriately? It is outcome-focused rather than prescriptive. It does not tell you to buy a technology, adopt a topology, or hold a certificate. It sets out what must be true, and asks you to demonstrate that it is.

That design is deliberate. Essential functions vary enormously, from water treatment to transport to health, and a prescriptive control list would be wrong for most of them. It also means the CAF is harder to game than a checklist, because an assessor is judging the sufficiency of your arrangements against the consequence of failure.

The CAF is used in several regulatory contexts, most visibly in support of the UK NIS Regulations for operators of essential services and relevant digital service providers, and by government departments under their own assurance arrangements. Individual regulators publish their own profiles and expectations, so the target you are assessed against is set by your regulator rather than by the NCSC.

The four objectives

  • Objective A: Managing security risk. Governance, risk management, asset management and supply chain. The organisational arrangements that make security decisions sound.
  • Objective B: Protecting against cyber attack. Service protection policies, identity and access control, data security, system security, resilient networks and systems, and staff awareness and training.
  • Objective C: Detecting cyber security events. Security monitoring and proactive security event discovery.
  • Objective D: Minimising the impact of cyber security incidents. Response and recovery planning, and lessons learned.

Beneath the objectives sit fourteen principles, and beneath those sit contributing outcomes, each with indicators of good practice.

How assessment works

Each contributing outcome is assessed as Not Achieved, Partially Achieved, or Achieved. Partially Achieved is only available for some outcomes. The indicators of good practice are written in three columns matching those states, which makes self-assessment more honest than a numeric maturity score, because you have to read the description of failure and decide whether it describes you.

Three points about assessment consistently surprise organisations on their first cycle:

  • An outcome is judged against the essential function, not the organisation. Excellent enterprise IT security does not evidence an outcome for an operational estate that sits outside its scope.
  • Proportionality cuts both ways. Arrangements that would be adequate for a low-consequence service can be judged Not Achieved where the consequence of failure is severe.
  • Documentation is not evidence. A plan that has never been exercised does not evidence an outcome about response and recovery capability.

The outcomes organisations most often over-claim

Four areas account for a disproportionate share of downgraded outcomes.

  1. Asset management under A3. Incomplete or stale inventories, particularly for operational technology, legacy systems and third-party-managed assets. If you cannot enumerate what supports the essential function, most downstream outcomes weaken.
  2. Supply chain under A4. Contracts that assign security obligations without any mechanism to verify them, and no understanding of which suppliers hold privileged access to the essential function.
  3. Data security and resilient networks under B3 and B5. Recovery data that shares an administrative domain, an authentication provider or a network path with the environment it exists to restore. This is the single most common architectural weakness we encounter.
  4. Response and recovery under D1. Plans that assume the availability of the systems the incident has taken away, including identity, email, telephony, documentation and the recovery tooling itself.

Building an assessment that survives scrutiny

  1. Define the essential function precisely, then map the systems, data, people and suppliers it depends on. Everything else follows from this boundary.
  2. Assess against the indicators, not against your own maturity model. Read the Not Achieved column first.
  3. Collect evidence generated by the control, not descriptions of it. Logs, test reports, approval records, timings.
  4. Record justified deviations. An outcome achieved by a different route than the indicators suggest is legitimate, provided the reasoning is documented and the outcome holds.
  5. Exercise the response and recovery outcomes. A tabletop is a start. A technical restore under realistic constraints is evidence.
  6. Track improvement as a plan with owners and dates, because assessors and regulators are interested in trajectory as well as position.

CAF alongside other frameworks

  • NIST CSF 2.0 covers similar ground with six Functions and a Profile mechanism. Mapping between the two is straightforward at objective level and useful if you report internationally.
  • ISO/IEC 27001 provides a certifiable management system. It evidences much of Objective A but relatively little of Objective D.
  • ISA/IEC 62443 is the natural companion for the operational technology in scope, particularly for the segmentation and boundary questions inside B4 and B5.
  • Cyber Essentials is a baseline scheme, not an alternative to the CAF, and does not evidence CAF outcomes for an essential function.

Where physical controls contribute

Several CAF outcomes ask, in effect, whether a control would still hold if an attacker held legitimate privileged credentials. That question is difficult to answer with logical controls alone when the control, the evidence and the protected asset all sit inside the same administrative domain.

Firevault addresses a narrow part of that problem. Offline Secure Storage® holds selected recovery, configuration and evidential material on storage that is physically disconnected when it is not in use, which contributes to data security under B3 and to recovery capability under D1. Control by Firevault is a suite of nine purpose-built tools and techniques that give physical control over the paths into and across an estate, applied through Blueprints that treat a specific risk, which is relevant to identity and access control under B2, resilient networks under B4 and B5, and containment during an incident under D1.

This is a contribution to specific outcomes, not a route to an Achieved rating. Governance, asset management, monitoring and exercised plans remain the substance of a CAF assessment.

Frequently asked questions

Is the CAF mandatory?

The framework itself is not legislation. Its use is mandated or expected by particular regulators and government assurance regimes, so whether it applies to you depends on your sector and your regulator.

Can you be certified against the CAF?

No. It is an assessment framework. Organisations self-assess, and regulators or independent assessors validate.

How often should we reassess?

Follow your regulator's cycle, and reassess after material architectural change, a significant incident, or a change in the essential function itself.

Does the CAF apply to operational technology?

Yes, where OT supports the essential function. Scoping OT out is one of the fastest ways to produce an assessment an assessor will not accept.

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

HardwareYour copy sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
RecoveryA known-clean copy to rebuild from, on your timetable
LocationHeld in a secure Firevault Bunker
Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up