- What they do
- ISO 27001 consultancy
- Who they help
- URM Consulting is an ISO 27001 consultancy based in UK. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework National Cyber & Cloud Schemes
NCSC CAF
The Cyber Assessment Framework (CAF) is the UK National Cyber Security Centre's outcome-based framework for assessing the cyber resilience of organizations that run essential functions.
It was created in 2018 to give competent authorities under the NIS Regulations a common assessment tool and is now used by nearly all UK cyber regulators, by the GovAssure scheme for central government departments, and increasingly by devolved administrations and public bodies.
The CAF has four objectives (managing security risk, protecting against cyber attack, detecting cyber security events, minimizing the impact of incidents), 14 principles, and a set of contributing outcomes, each with indicators of good practice used to rate the outcome as Achieved, Partially Achieved, or Not Achieved.
Version 3.1 (April 2022) introduced the Partially Achieved level widely; version 3.2 (April 2024) made targeted changes; version 4.0 (August 2025) added outcomes on secure software development, AI-related risk, and threat hunting and realigned wording for NIS2-style expectations (verify the current version on the NCSC collection page).
The CAF is not a certificate. Operators self-assess against the CAF profile their regulator sets (each competent authority publishes the outcomes it expects for its sector), regulators review and may inspect, and GovAssure uses independent assurance reviewers to verify departmental self-assessments.
In writing, an organization needs the CAF self-assessment with evidence per contributing outcome, its risk management framework and governance records, asset and dependency inventories, security policies and their implementation evidence, monitoring and detection capabilities, incident response and recovery plans with exercise records, and improvement plans agreed with the regulator.
help
Who has to comply
Operators of essential services and relevant digital service providers designated under the UK NIS Regulations (energy, transport, health, water, digital infrastructure), central government departments under GovAssure, and other organizations whose regulators adopt CAF-based profiles. Others may use it voluntarily.
What the assessor asks to see
CAF self-assessment with ratings and evidence per contributing outcome; governance and risk management records; asset, service, and dependency inventories; security policies and standards; identity and access management; system security and patching evidence; data protection and resilience measures; staff awareness and training records; supply chain risk management; monitoring coverage and detection capability; incident response plans, incident records, and exercise reports; recovery plans and tests; lessons learned and improvement plans.
Versions
CAF v3.1 (April 2022) mostly refined wording and consistency and embedded the Partially Achieved rating; v3.2 (April 2024) made targeted updates; v4.0 (August 2025) added new contributing outcomes for secure software development and AI-related risk and strengthened threat hunting expectations. Regulators announce when their sector profiles move to a new version.
Assessors
Who assesses NCSC CAF
Sector competent authorities (for example Ofgem, DfT, DHSC, Ofcom, the Drinking Water Inspectorate) review operator self-assessments and may inspect; independent assurance reviewers verify GovAssure self-assessments; no certificate is issued. competent authorities act under statutory powers, and GovAssure reviewers are selected through Cabinet Office arrangements.
No firm has claimed a NCSC CAF assessor listing yet. Claim yours →
Consultants
Who helps with NCSC CAF
UK cyber consultancies, including NCSC Assured Consultancy scheme members, offer CAF gap assessments, evidence gathering, and remediation roadmaps; GovAssure independent assurance reviewers are drawn from an approved supplier pool. Engagements run from a few weeks for a self-assessment to many months for remediation programs.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
Software
Tools for NCSC CAF
Tools that name this framework in their own material.
No firm has claimed a NCSC CAF tool listing yet. Claim yours →
Related reading
- Understanding and implementing the Cyber Assessment FrameworkIndustry body's guide to using an outcomes-based framework where regulators, not a certificate, decide whether you have achieved an outcome.techUK
- NCSC Cyber Assessment FrameworkExplains the four objectives, fourteen principles and the achieved, partially achieved and not achieved scoring used in assessments.Bridewell
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for NCSC CAF
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with NCSC CAF
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.