GRCCopilot
Sign In
National Cyber Security Centre (NCSC), United Kingdom

NCSC Cyber Assessment Framework (CAF)

Outcome-focused cyber resilience assessment framework for critical national infrastructure and essential services

Start Assessment Create Free Account
41
Controls
41
Questions
Active
Status

About this Framework

The Cyber Assessment Framework (CAF) is a cybersecurity assessment framework developed by the UK National Cyber Security Centre to help organizations evaluate and improve cyber resilience. CAF is structured around security objectives and outcomes rather than prescriptive controls, enabling organizations operating essential services and critical national infrastructure to assess their ability to identify, protect, detect, respond to, and recover from cyber threats.

Key Control Domains

Governance
Risk Management
Asset Management
Supply Chain Security
Identity and Access Control
Monitoring and Detection
Incident Response
Business Continuity
Recovery and Resilience

Who Needs This?

  • Critical National Infrastructure operators
  • Essential service providers
  • Government organizations
  • Regulated sectors under NIS Regulations
  • Organizations seeking cyber resilience maturity assessments

Compliance Benefits

  • Outcome-based security assessments
  • Improved operational resilience
  • Alignment with NIS regulatory requirements
  • Enhanced cyber governance and risk management
  • Structured improvement roadmap

Official Reference

NCSC Cyber Assessment Framework (CAF)
https://www.ncsc.gov.uk

Assessment Details

Issuer / AuthorityNational Cyber Security Centre (NCSC), United Kingdom
FrameworkNCSC Cyber Assessment Framework (CAF)
Controls41
Questions41
StatusActive
Assessment Start03 Jun 2026

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/ncsc-caf

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.