Cyber Assessment Framework v4.0 released in response to growing threat
Updates to the CAF helps providers of essential services to better manage their cyber risks.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Updates to the CAF helps providers of essential services to better manage their cyber risks.

The Cyber Assessment Framework (CAF) is a tool provided by the NCSC to help organisations improve their cyber security and resilience, so they can protect critical services from cyber threats.
It is now used by nearly all UK cyber regulators and is established in the public sector via GovAssure, the cyber security assurance scheme for assessing the critical systems of government organisations.
At the same time, the cyber threat to the UK’s CNI has continued to increase. Keeping pace with the evolution of attack methods is essential to close the widening gap between the escalated cyber threats to critical services, and our collective ability to defend against them.
These two themes have driven our updates to the CAF to ensure the framework remains relevant, and that organisations' defences are up-to-date. Version 4.0 of the CAF introduces four major changes:
A new section on building a deeper understanding of attacker methods and motivations to inform better cyber risk decisions.
Updates to the section on security monitoring and threat hunting to improve the detection of cyber threats.
And finally, there is improved coverage of AI-related cyber risks throughout the CAF.
The CAF is primarily designed for CNI organisations operating essential services across energy, healthcare, transport, digital infrastructure and government sectors, helping them to meet legal and regulatory requirements such as the NIS Regulations. It does this by providing a comprehensive framework for assessing how well an organisation is meeting expected security and resilience outcomes, identified as appropriate in relation to a particular level of threat.
The NCSC has produced this update in full consultation with the cyber regulators and other cyber oversight bodies that use the CAF. Their feedback was extremely helpful and it was carefully considered throughout the development of CAF v4.0.
We are already looking ahead to future iterations of the CAF, ensuring that it keeps pace with the regulatory proposals within the Cyber Security and Resilience Bill, which will be laid before parliament later this year. Please let us know (via our Support to Regulation mailbox) if you have any feedback that you would like to see reflected in subsequent versions.
In the meantime, we’d encourage all system owners to adopt CAF 4.0 to improve their organisation’s cyber security and resilience. And the CAF is of course part of a broader suite of tools we provide to regulators and operators to build confidence and resilience. These include Cyber Essentials, the Cyber Resilience Audit, and our Cyber Adversary Simulation services.


