Skip to main content

Cyber Assessment Framework v4.0 released in response to growing threat

Updates to the CAF helps providers of essential services to better manage their cyber risks.

VM via Getty Images

The Cyber Assessment Framework (CAF) is a tool provided by the NCSC to help organisations improve their cyber security and resilience, so they can protect critical services from cyber threats.

It is now used by nearly all UK cyber regulators and is established in the public sector via  GovAssure, the cyber security assurance scheme for assessing the critical systems of government organisations.

At the same time, the cyber threat to the UK’s CNI has continued to increase. Keeping pace with the evolution of attack methods is essential to close the widening gap between the escalated cyber threats to critical services, and our collective ability to defend against them.

These two themes have driven our updates to the CAF to ensure the framework remains relevant, and that organisations' defences are up-to-date. Version 4.0 of the CAF introduces four major changes:

The CAF is primarily designed for CNI organisations operating essential services across energy, healthcare, transport, digital infrastructure and government sectors, helping them to meet legal and regulatory requirements such as the NIS Regulations. It does this by providing a comprehensive framework for assessing how well an organisation is meeting expected security and resilience outcomes, identified as appropriate in relation to a particular level of threat. 

The NCSC has produced this update in full consultation with the cyber regulators and other cyber oversight bodies that use the CAF. Their feedback was extremely helpful and it was carefully considered throughout the development of CAF v4.0. 

We are already looking ahead to future iterations of the CAF, ensuring that it keeps pace with the regulatory proposals within the Cyber Security and Resilience Bill, which will be laid before parliament later this year. Please let us know (via our Support to Regulation mailbox) if you have any feedback that you would like to see reflected in subsequent versions.

In the meantime, we’d encourage all system owners to adopt CAF 4.0 to improve their organisation’s cyber security and resilience. And the CAF is of course part of a broader suite of tools we provide to regulators and operators to build confidence and resilience. These include Cyber Essentials, the Cyber Resilience Audit, and our Cyber Adversary Simulation services.

Stephen D
Support to Regulation Team

Written by

Stephen D Support to Regulation Team