Information & Cyber Security

NCSC Cyber Assessment Framework (CAF)

Practical support to help you assess cyber resilience, protect essential functions and demonstrate alignment with NCSC CAF expectations.

Build confidence in your cyber resilience 

Cyber incidents can disrupt critical services, damage trust and create significant operational, financial and regulatory consequences.  For organisations delivering essential services, or supporting those that do, it is no longer enough to have security controls in place.  You need to understand whether those controls are effective, proportionate and capable of protecting the functions your organisation depends on. 

The NCSC Cyber Assessment Framework (CAF) provides a structured way to assess cyber security and resilience against recognised outcomes.  Teamwork IMS helps organisations interpret the framework, identify gaps, prioritise improvement and prepare clear evidence for internal assurance, external review or regulator engagement.

What is the NCSC Cyber Assessment Framework?

The Cyber Assessment Framework, developed by the National Cyber Security Centre, is a UK cyber resilience framework designed to help organisations assess how effectively they manage risks to essential functions and services. 

CAF is outcome-based.  It does not simply ask whether individual controls exist; it considers whether an organisation can demonstrate that the right governance, protection, detection and response arrangements are working in practice. The framework is structured around four core objectives: 

  • Managing security risk 
  • Protecting against cyber attack 
  • Detecting cyber security events 
  • Minimising the impact of cyber security incidents 

CAF is primarily used by organisations operating or supporting essential services, including sectors such as healthcare, energy, transport, digital infrastructure, government and local government.  It is also increasingly useful for organisations that want a credible, risk-based benchmark for cyber resilience, even where formal regulation does not apply.

Padlock representing ISO 27001 certification for information security

How CAF can benefit your organisation

Regulatory Confidence

Demonstrate a structured approach to NCSC and sector regulator expectations, including requirements linked to the NIS Regulations where applicable

Reduce the risk of financial losses

Improved Cyber Resilience

Focus on the services, systems and suppliers that matter most to operational continuity

Risk-Based Investment

Prioritise improvement activity where it will reduce the greatest risk to essential functions

Clear Maturity Insight

Understand current capability against CAF outcomes and target profiles, such as Basic or Enhanced

Stronger Governance

Clarify ownership, oversight, decision-making and accountability for cyber risk

Better Evidence

Prepare meaningful evidence that shows how controls operate and how outcomes are achieved

Our CAF Support Services

Gap analysis

CAF gap analysis and maturity assessment

We assess your current arrangements against CAF objectives, principles, contributing outcomes and relevant target profiles. This gives you a clear view of strengths, gaps and areas where evidence needs to be improved.

Gap analysis

Risk-based improvement planning

We translate assessment findings into a practical improvement roadmap, helping you focus on the actions that will make the greatest difference to resilience, assurance and regulatory confidence.

Find out more

Evidence and assurance support

We help you prepare proportionate, meaningful evidence for internal review, external assessment or regulator engagement. This may include policies, risk records, control evidence, supplier information, monitoring outputs, incident response arrangements and improvement plans.

Find out more

CAF alignment with ISO and other frameworks

If you already use ISO 27001, Cyber Essentials, ISO 22301 or other management systems, we help map existing controls and evidence to CAF outcomes. This reduces duplication and helps you get more value from the systems you already have.

Maintain & improve

CAF is not a one-off exercise. We support ongoing improvement as your organisation, technology, suppliers, threats and regulatory expectations change.

Managing Compliance

Our approach:

  • Assess: understand your essential functions, risk context, current controls and existing evidence. 
  • Prioritise: identify the most important gaps and agree a realistic improvement plan. 
  • Evidence: build clear, audit-ready evidence that demonstrates how CAF outcomes are being met. 
  • Improve: embed improvements into day-to-day governance, risk management, security operations and business continuity arrangements. 

 

Why choose Teamwork IMS? 

Teamwork IMS combines cyber security, compliance, business continuity and management system expertise.  This means we can help you interpret CAF in a practical way, align it with the standards and frameworks you already use and avoid unnecessary duplication. 

Our consultants work collaboratively with your team to understand your organisation, your risk profile and the services that matter most.  We focus on clear outcomes, proportionate recommendations and plain-English guidance, helping you move from assessment to measurable improvement. 

  • Experienced cyber, compliance and management system consultants 
  • Practical interpretation of CAF objectives, principles and contributing outcomes 
  • Support aligning CAF with ISO 27001, ISO 22301, Cyber Essentials and NIS expectations 
  • Clear evidence mapping and improvement planning 
  • Collaborative, jargon-free support focused on resilience, not tick-box compliance 

CAF and related standards

CAF works well alongside established cyber security and resilience frameworks.  ISO 27001 can provide a strong management system foundation for information security, Cyber Essentials can support baseline technical controls and ISO 22301 can strengthen continuity and recovery planning.  Used together, these frameworks can provide a more complete and defensible approach to cyber resilience.

Frequently asked questions

Is CAF a certification standard?

No.  CAF is not a certifiable standard in the same way as ISO 27001.  It is an assessment framework used to understand and demonstrate cyber security and resilience outcomes.  It can, however, be supported by evidence from certified management systems and other assurance activities. 

Do we need to be regulated to use the CAF?

No.  CAF is primarily designed for organisations operating or supporting essential services, but it can also be used voluntarily by organisations that want a structured, credible way to assess and improve cyber resilience.

How does CAF differ from ISO 27001?

ISO 27001 provides a certifiable information security management system.  CAF focuses on cyber resilience outcomes for essential functions and asks whether governance, protection, detection and response arrangements are effective in practice.  Many organisations use ISO 27001 as a valuable evidence source for CAF.

What is CAF 4.0?

CAF 4.0 is the latest version of the framework and reflects increased expectations around cyber resilience, evidence, threat understanding, monitoring and assurance. Organisations using earlier versions may need to review their current evidence and improvement plans to ensure they remain aligned.

How can Teamwork IMS help us get started?

We can begin with a focused CAF readiness review to understand your essential functions, current controls, existing evidence and key gaps.  From there, we can help you prioritise practical improvements and prepare for internal or external assurance. 

Get in touch today

    Name

    Email address

    Phone number

    Where did you first hear about us?

    Message