NCSC Cyber Assessment Framework (CAF) v4.0 compliance software
Assess and evidence the NCSC Cyber Assessment Framework v4.0 per group or per organisation: all 41 contributing outcomes and their indicators of good practice, each outcome scored Achieved, Partially achieved or Not achieved against the target profile your regime sets, whether NIS, GovAssure Basic or Enhanced, local government or the NHS DSPT.
- Owner and versionNCSC; CAF v4.0, released 4 August 2025
- Hierarchy4 objectives, 14 principles and 41 contributing outcomes (A 9, B 20, C 7, D 5)
- Assessable items373 indicators of good practice (225 Achieved, 148 Partially achieved), 136 of them critical
- ScoringAchieved, Partially achieved or Not achieved per contributing outcome, against the target profile
- ProfilesNIS Regulations, GovAssure Basic and Enhanced, local government CAF, NHS DSPT
- Reporting clockNIS Regulations: an operator notifies its competent authority within 72 h of becoming aware of a significant incident
What UK NCSC CAF requires
Who it applies to
- Operators of essential services in energy, transport, health, drinking water and digital infrastructure, and relevant digital service providers, under the NIS Regulations 2018
- Central government departments and arm's-length bodies assuring critical systems through GovAssure, against the Basic or Enhanced profile
- Local authorities in England using MHCLG's CAF for local government, and NHS bodies whose DSPT v9 submission is aligned to CAF v4.0
- CNI suppliers and managed service providers adopting the CAF as a benchmark ahead of the Cyber Security and Resilience Bill
The Cyber Assessment Framework is the National Cyber Security Centre's method for judging how well an organisation manages the cyber risk to the systems behind its essential functions, across both IT and operational technology. Version 4.0, released on 4 August 2025, has 4 objectives (managing security risk, protecting against cyber attack, detecting cyber security events and minimising the impact of incidents), 14 principles and 41 contributing outcomes, up from 39 in v3.2. It added outcomes on understanding threat, secure software development and support, and understanding user and system behaviour with threat intelligence, merged the two v3.2 outcomes of principle C2 into a single threat-hunting outcome, and addressed AI risk throughout.
The CAF is guidance, not law. It becomes binding through the bodies that adopt it: the competent authorities under the NIS Regulations 2018, GovAssure for central government's critical systems, MHCLG's CAF for local government in England, and the NHS Data Security and Protection Toolkit, whose 2026-27 version (v9, released 2 October 2026) is aligned to CAF v4.0. NCSC says the CAF is now used by nearly all UK cyber regulators, and advises organisations subject to cyber regulation to talk to their regulator before using it.
Each contributing outcome is judged against indicators of good practice in an Achieved column and, for 32 of the 41 outcomes, a Partially achieved column. An outcome is Achieved only when every relevant Achieved indicator holds, Partially achieved when every relevant Partially achieved indicator holds, and Not achieved otherwise. What a regulator or scheme expects is expressed as a profile, the minimum result per outcome: GovAssure assigns a Basic or Enhanced profile to each government system, and Ofgem uses Basic and Enhanced profiles for downstream gas and electricity.
How GRCLens supports UK NCSC CAF
UK NCSC CAF runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Outcomes scored the way NCSC defines them
Every indicator of good practice is a questionnaire item. Each contributing outcome is derived from its indicators as Achieved, Partially achieved or Not achieved, then compared with the target the selected profile sets for it: NIS, GovAssure Basic or Enhanced, local government or NHS DSPT. Outcomes below target are the gaps.
Group and organisation assessment with roll-up
The group answers the governance, risk and supply-chain outcomes once, and each organisation or system in scope is assessed on its own. Every assessment rolls up into a group view with a heat map across 15 risk areas, so a board sees which kind of exposure a weak organisation carries.
Four stakeholder dashboards
The board sees outcomes against the profile and the critical gaps; the CISO and risk team the heat map and the objective and principle scores; operations the control validation and open remediation; third-party and supply-chain teams the supply-chain outcomes and supplier checks.
Continuous assurance from connectors
Incident records, backup and restore, vulnerability and patch, identity and MFA, the third-party register, resilience testing, training (LMS) and log monitoring are read against the questionnaire, alongside the existing Entra, Tenable, Qualys, Splunk and ITSM connectors. A failing check whose requirement was answered Implemented is flagged as a contradiction.
Assurance register, remediation and KRIs
Each requirement can carry several owners in the assurance register. Gaps become owned, dated actions in the remediation and risk treatment plan, and key risk indicators name the requirements they measure, so a KRI outside appetite beside an answer of Implemented is a finding.
Baseerah summary, Word and PDF reports
Baseerah, the platform's AI assistant running on a self-hosted language model, writes a one-paragraph executive summary for the board and the CISO. Organisation and group reports export as Word and PDF.
UK NCSC CAF frequently asked questions
Is the NCSC CAF mandatory?
Not in itself. The CAF is NCSC guidance, and it becomes binding through the bodies that adopt it: NIS competent authorities for operators of essential services, GovAssure for central government's critical systems, MHCLG for councils in England and NHS England through the CAF-aligned DSPT. NCSC advises organisations subject to cyber regulation to talk to their regulator before using the CAF.
What changed in CAF v4.0?
Released on 4 August 2025, v4.0 has 41 contributing outcomes, up from 39 in v3.2. It added A2.b Understanding threat, A4.b Secure software development and support, and C1.f Understanding users' and systems' behaviour and threat intelligence; replaced the two v3.2 outcomes in C2 with a single C2.a Threat hunting; renamed C1.d and C1.e; moved Assurance from A2.b to A2.c; and addressed AI risk throughout.
How is a contributing outcome scored?
Against its indicators of good practice. It is Achieved when every relevant Achieved indicator is true, Partially achieved when every relevant Partially achieved indicator is true (32 of the 41 outcomes have that column), and Not achieved otherwise. NCSC is explicit that the indicators inform expert judgement rather than form a tick-box checklist.
Does GRCLens carry the GovAssure and sector profiles?
It carries the regimes (NIS, GovAssure Basic and Enhanced, local government CAF and NHS DSPT) and scores each outcome against the target the regime sets. The per-outcome targets of the Government CAF profiles, the local government profile and the DSPT are not publicly listed, so GRCLens ships starting targets built from NCSC's published guidance, marked unverified until the published values replace them.
When must an incident be reported under the NIS Regulations?
An operator of essential services notifies its competent authority of an incident with a significant impact on the continuity of its essential service without undue delay and no later than 72 hours after becoming aware of it; a relevant digital service provider notifies the Information Commission on the same clock. The Cyber Security and Resilience Bill would require an initial notification within 24 hours and a full report within 72, but it was not yet law in October 2026.
One platform, many obligations
See all supported frameworks → Every framework that applies in United Kingdom →

Talk to us about UK NCSC CAF
Security Solution Consultants provides UK CAF readiness and advisory alongside the platform, so you can combine tooling with hands-on expertise.