Cyber Assessment Framework
The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.
Pages
Page 8 of 25
Principle A4 Supply Chain

Appropriate organisational structures, policies, processes and procedures in place to understand, assess and systematically manage security risks to network and information systems supporting essential functions.
Principle
The organisation understands and manages security risks to networks and information systems supporting the operation of essential functions that arise as a result of dependencies on suppliers. This includes ensuring that appropriate measures are employed where third party services are used.
Description of principle
If an organisation relies on third parties (such as outsourced or cloud-based technology services) it remains accountable for the protection of any essential function. This means that there should be confidence that all relevant security requirements are met regardless of whether the owning organisation or a third party operates the function.
For many organisations, it may make good sense to use third party technologies and services. Where these are used, it is important that contractual agreements provide provisions for the protection of things upon which the essential function depends.
Guidance
Organisations responsible for essential functions need to ensure that when third party suppliers are used, all relevant security requirements are met. This means that a number of specific supply chain related security considerations should be addressed where relevant to the provision of the essential function. This might include:
-
Ensuring the protection of data shared with a third party. This includes protecting data from actions such as unauthorised access, modification, or deletion that may cause an adverse impact on any essential functions (see Principle B3).
-
Effective specification of the security properties of products or services procured from an external third party, or sourced internally from another part of the organisation, that are important for the protection of the essential function. This should include the security requirements derived from the rest of these Principles.
-
Ensure that any network connections or data sharing with third parties do not introduce unmanaged vulnerabilities that have the potential to affect the security of the essential function.
-
Confidence that third party suppliers are trustworthy such that malicious attempts to subvert the security of products or systems that could affect the essential function are managed.
Supply Chain Security
Our guidance on supply chain security gives an overview of supply chain risks. It also provides references to further reading and guidance.
Secure Software Development and Support
Your organisation needs to have confidence in the software it uses. Robust software development and support practices help organisations better manage the risks from poor software development practices and maintain trust in network and information systems supporting their essential functions.
The NCSC Secure development and deployment guidance can help you improve and evaluate your development practices, and those of your suppliers. Similarly, the Software Security Code of Practice has been developed to improve the security and resilience of software that organisations and businesses rely on.
Cloud service security
Where your organisation relies upon a cloud service, you should have confidence in the cyber security measures in place. Consider cloud-specific supply chain assurance guidance in NCSC cloud security principle 8: supply chain together with many cloud security assurance resources, including industry schemes such as the Cloud Security Alliance (CSA) Security, Trust & Assurance Registry (STAR) academic research and cloud provider information.
A4.a Supply Chain
You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All the following statements are true: | All the following statements are true: |
You do not know what data belonging to you is held by suppliers, or how it is managed. Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors. You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations. Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls. | You understand the general risks suppliers may pose to your essential function(s). You know the extent of your supply chain that supports your essential function(s), including sub-contractors. Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats. You understand which contracts are relevant and you include appropriate security obligations in relevant contracts. You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements. Your approach to security incident management considers incidents that might arise in your supply chain. You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats. | You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces. You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions. Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors. Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors. You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors. You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts. You have a proactive approach to contract management which may include a contract management plan for relevant contracts. Customer / supplier ownership of responsibilities is defined in contracts. All network connections and data sharing with third parties are managed effectively and proportionately. When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents. |
A4.b Secure Software Development and Support
You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).
| Not achieved | Partially achieved | Achieved |
|---|---|---|
| At least one of the following statements is true: | All the following statements are true: | All the following statements are true: |
Your software supplier(s) is unaware of the composition and provenance of software provided to you. Software, including updates and patches, undergoes little to no testing. Updates and patches often introduce new problems or fail to address existing issues. Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations. | Your software supplier leverages secure development principles and practices. Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you. You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats. The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing. You have arrangements in place with your software supplier to receive timely security updates, patches and notifications. Software, including updates and patches, is obtained from your supplier(s) via secure channels. Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities. You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s). If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use. You have appropriate support and maintenance arrangements in place. | Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)). Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product. You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors. The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors. You can attest to the authenticity and integrity of software, including updates and patches. |
Additional information
- Supply chain security guidance
- Cloud security guidance. Principle 8: Supply chain security
- Supply chain guidance
- How to assess and gain confidence in your supply chain cyber security guidance
- NCSC Secure development and deployment guidance
- NCSC Vulnerability Disclosure Toolkit
- NCSC A method to assess 'forgivable' vs 'unforgivable' vulnerabilities
- NCSC Raising software cyber resilience 'at scale'
- NCSC Guidelines for secure AI system development
- Cloud security alliance. Security, Trust, Assurance and Risk (STAR)
- NPSA Supply Chain Guidance
- Embedding cyber resilience in local government supply chains
- NIST SP800-53
- NIST SP800-82
- IEC 62443
- ISO/IEC 27001
- UK Government Software Security Code of Practice
- UK Government AI Cyber Security Code of Practice
- ISO/IEC 29147:2018Information technology - Security techniques - Vulnerability disclosure
- NIST Secure Software Development Framework
- Microsoft Security Development Lifecycle (SDL)
- ETSI Securing Artificial Intelligence (SAI); Baseline Cyber Security Requirements for AI Models and Systems