---
title: "NCSC Cyber Assessment Framework Guide: Objectiv… | Firevault"
description: "A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/ncsc-caf-guide#webpage",
      "url": "https://fire-vault.com/learn/guides/ncsc-caf-guide",
      "name": "NCSC Cyber Assessment Framework Guide: Objectiv…",
      "description": "A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/ncsc-caf-guide.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/ncsc-caf-guide#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/ncsc-caf-guide#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence",
          "item": "https://fire-vault.com/learn/guides/ncsc-caf-guide"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence",
      "description": "A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what evidence satisfies an assessor.",
      "url": "https://fire-vault.com/learn/guides/ncsc-caf-guide",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/ncsc-caf-guide.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-08-28T07:20:17.403956+00:00",
      "dateModified": "2026-08-28T10:12:43.171224+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/ncsc-caf-guide"
      },
      "inLanguage": "en-GB",
      "articleSection": "Standards & Frameworks",
      "wordCount": 1121,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What the CAF is forThe four objectivesHow assessment worksThe outcomes organisations most …Building an assessment that surv…CAF alongside other frameworksWhere physical controls contributeFrequently asked questionsMore

[Guides](/learn/knowledge?filter=guides)/ Standards & Frameworks 

Standards & Frameworks · 28 August 2026 

# NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence

A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what evidence satisfies an assessor.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

6 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fncsc-caf-guide)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fncsc-caf-guide&text=NCSC%20Cyber%20Assessment%20Framework%20Guide%3A%20Objectives%2C%20Principles%20and%20Evidence%0A%0AA%20practical%20guide%20to%20the%20NCSC%20Cyber%20Assessment%20Framework%3A%20the%20four%20objectives%2C%20the%20fourteen%20principles%2C%20how%20contributing%20outcomes%20are%20assessed%2C%20and%20what%20evidence%20satisfies%20an%20assessor.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fncsc-caf-guide)[](mailto:?subject=NCSC%20Cyber%20Assessment%20Framework%20Guide%3A%20Objectives%2C%20Principles%20and%20Evidence&body=A%20practical%20guide%20to%20the%20NCSC%20Cyber%20Assessment%20Framework%3A%20the%20four%20objectives%2C%20the%20fourteen%20principles%2C%20how%20contributing%20outcomes%20are%20assessed%2C%20and%20what%20evidence%20satisfies%20an%20assessor.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fncsc-caf-guide)

![NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/ncsc-caf-guide.jpg)

Standards & Frameworks 

Why it matters

## What this means for organisations holding critical data

A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what evidence satisfies an assessor.

**On this page**[What the CAF is for](#section-0)[The four objectives](#section-1)[How assessment works](#section-2)[The outcomes organisations most …](#section-3)[Building an assessment that surv…](#section-4)[CAF alongside other frameworks](#section-5)[Where physical controls contribute](#section-6)[Frequently asked questions](#section-7)

On this page

1.  [What the CAF is for](#section-0)
2.  [The four objectives](#section-1)
3.  [How assessment works](#section-2)
4.  [The outcomes organisations most often over-claim](#section-3)
5.  [Building an assessment that survives scrutiny](#section-4)
6.  [CAF alongside other frameworks](#section-5)
7.  [Where physical controls contribute](#section-6)
8.  [Frequently asked questions](#section-7)

**Written by Mark Fermor.** The Cyber Assessment Framework is the assessment model the National Cyber Security Centre publishes for organisations that operate essential functions. This guide explains its structure, how assessment actually works, and where organisations most often fail to evidence an outcome they believe they achieve.

## What the CAF is for

The CAF exists to answer a specific question: is the cyber risk to an essential function being managed appropriately? It is outcome-focused rather than prescriptive. It does not tell you to buy a technology, adopt a topology, or hold a certificate. It sets out what must be true, and asks you to demonstrate that it is.

That design is deliberate. Essential functions vary enormously, from water treatment to transport to health, and a prescriptive control list would be wrong for most of them. It also means the CAF is harder to game than a checklist, because an assessor is judging the sufficiency of your arrangements against the consequence of failure.

The CAF is used in several regulatory contexts, most visibly in support of the UK NIS Regulations for operators of essential services and relevant digital service providers, and by government departments under their own assurance arrangements. Individual regulators publish their own profiles and expectations, so the target you are assessed against is set by your regulator rather than by the NCSC.

## The four objectives

-   **Objective A: Managing security risk.** Governance, risk management, asset management and supply chain. The organisational arrangements that make security decisions sound.
-   **Objective B: Protecting against cyber attack.** Service protection policies, identity and access control, data security, system security, resilient networks and systems, and staff awareness and training.
-   **Objective C: Detecting cyber security events.** Security monitoring and proactive security event discovery.
-   **Objective D: Minimising the impact of cyber security incidents.** Response and recovery planning, and lessons learned.

Beneath the objectives sit fourteen principles, and beneath those sit contributing outcomes, each with indicators of good practice.

## How assessment works

Each contributing outcome is assessed as Not Achieved, Partially Achieved, or Achieved. Partially Achieved is only available for some outcomes. The indicators of good practice are written in three columns matching those states, which makes self-assessment more honest than a numeric maturity score, because you have to read the description of failure and decide whether it describes you.

Three points about assessment consistently surprise organisations on their first cycle:

-   **An outcome is judged against the essential function, not the organisation.** Excellent enterprise IT security does not evidence an outcome for an operational estate that sits outside its scope.
-   **Proportionality cuts both ways.** Arrangements that would be adequate for a low-consequence service can be judged Not Achieved where the consequence of failure is severe.
-   **Documentation is not evidence.** A plan that has never been exercised does not evidence an outcome about response and recovery capability.

## The outcomes organisations most often over-claim

Four areas account for a disproportionate share of downgraded outcomes.

1.  **Asset management under A3.** Incomplete or stale inventories, particularly for operational technology, legacy systems and third-party-managed assets. If you cannot enumerate what supports the essential function, most downstream outcomes weaken.
2.  **Supply chain under A4.** Contracts that assign security obligations without any mechanism to verify them, and no understanding of which suppliers hold privileged access to the essential function.
3.  **Data security and resilient networks under B3 and B5.** Recovery data that shares an administrative domain, an authentication provider or a network path with the environment it exists to restore. This is the single most common architectural weakness we encounter.
4.  **Response and recovery under D1.** Plans that assume the availability of the systems the incident has taken away, including identity, email, telephony, documentation and the recovery tooling itself.

## Building an assessment that survives scrutiny

1.  **Define the essential function precisely,** then map the systems, data, people and suppliers it depends on. Everything else follows from this boundary.
2.  **Assess against the indicators, not against your own maturity model.** Read the Not Achieved column first.
3.  **Collect evidence generated by the control,** not descriptions of it. Logs, test reports, approval records, timings.
4.  **Record justified deviations.** An outcome achieved by a different route than the indicators suggest is legitimate, provided the reasoning is documented and the outcome holds.
5.  **Exercise the response and recovery outcomes.** A tabletop is a start. A technical restore under realistic constraints is evidence.
6.  **Track improvement as a plan with owners and dates,** because assessors and regulators are interested in trajectory as well as position.

## CAF alongside other frameworks

-   **[NIST CSF](/solutions/control/frameworks/nist-csf) 2.0** covers similar ground with six Functions and a Profile mechanism. Mapping between the two is straightforward at objective level and useful if you report internationally.
-   **ISO/IEC 27001** provides a certifiable management system. It evidences much of Objective A but relatively little of Objective D.
-   **ISA/[IEC 62443](/solutions/control/frameworks/iec-62443)** is the natural companion for the operational technology in scope, particularly for the segmentation and boundary questions inside B4 and B5.
-   **[Cyber Essentials](/solutions/oss/compliance/cyber-essentials)** is a baseline scheme, not an alternative to the CAF, and does not evidence CAF outcomes for an essential function.

## Where physical controls contribute

Several CAF outcomes ask, in effect, whether a control would still hold if an attacker held legitimate privileged credentials. That question is difficult to answer with logical controls alone when the control, the evidence and the protected asset all sit inside the same administrative domain.

Firevault addresses a narrow part of that problem. **[Offline Secure Storage](/offline-secure-storage)®** holds selected recovery, configuration and evidential material on storage that is physically disconnected when it is not in use, which contributes to data security under B3 and to recovery capability under D1. **Control by Firevault** is a suite of nine purpose-built tools and techniques that give physical control over the paths into and across an estate, applied through Blueprints that treat a specific risk, which is relevant to identity and access control under B2, resilient networks under B4 and B5, and containment during an incident under D1.

This is a contribution to specific outcomes, not a route to an Achieved rating. Governance, asset management, monitoring and exercised plans remain the substance of a CAF assessment.

## Frequently asked questions

### Is the CAF mandatory?

The framework itself is not legislation. Its use is mandated or expected by particular regulators and government assurance regimes, so whether it applies to you depends on your sector and your regulator.

### Can you be certified against the CAF?

No. It is an assessment framework. Organisations self-assess, and regulators or independent assessors validate.

### How often should we reassess?

Follow your regulator's cycle, and reassess after material architectural change, a significant incident, or a change in the essential function itself.

### Does the CAF apply to operational technology?

Yes, where OT supports the essential function. Scoping OT out is one of the fastest ways to produce an assessment an assessor will not accept.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### MITRE ATT&CK Guide: Mapping Controls to Real Adversary Behaviour
    
    How to use MITRE ATT&CK properly: tactics, techniques and sub-techniques, the Enterprise and ICS matrices, coverage mapping without self-deception, and why version changes matter.
    
    Read guide ](/learn/guides/mitre-attack-mapping-guide)
-   [
    
    ### ISA/IEC 62443 Guide: Zones, Conduits and Security Levels in Practice
    
    A practical guide to ISA/IEC 62443 for asset owners: how the series is structured, how zones and conduits are defined, what Security Levels mean, and how the standard relates to the Purdue Model.
    
    Read guide ](/learn/guides/iec-62443-guide)
-   [
    
    ### NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence
    
    A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile, and where physical controls contribute evidence.
    
    Read guide ](/learn/guides/nist-csf-2-0-guide)
-   [
    
    ### Crown Jewels Audit: What Deserves Disconnection
    
    Not everything needs to go offline. The Crown Jewels Audit is a structured framework for identifying exactly which assets deserve the protection that only physical disconnection can provide.
    
    Read guide ](/learn/guides/crown-jewels-audit)

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up