What is the NCSC CAF 4.0 and who is it for?
The NCSC CAF 4.0 (Cyber Assessment Framework) is a collection of cybersecurity guidance published by the UK National Cyber Security Centre. Specifically, it targets organizations that play a vital role in the day-to-day life of the UK. Moreover, NCSC released version 4.0 in August 2025. In fact, this makes it the most significant update since the framework launched in 2018.
In practice, the NCSC CAF 4.0 helps organizations assess how effectively they manage cyber risks to their essential functions. As a result, nearly all UK cyber regulators now use it. Furthermore, GovAssure applies it to central government systems, and operators of critical national infrastructure (CNI) across energy, healthcare, transport, digital infrastructure, and finance use it as their primary assessment reference.
How does the NCSC CAF 4.0 structure its requirements?
The NCSC CAF 4.0 organizes its requirements around four high-level objectives, 14 top-level principles, and 41 contributing outcomes. Moreover, it deliberately avoids a checklist approach. Instead, each contributing outcome defines a specific security goal that organizations must demonstrate through evidence.
Specifically, the four objectives cover:
- Objective A – Managing Security Risk: governance, risk management, asset management, and supply chain security
- Objective B – Protecting Against Cyber Attack: identity and access control, data security, system security, and network resilience
- Objective C – Detecting Cyber Security Events: security monitoring and the new threat hunting outcome that CAF 4.0 introduced
- Objective D – Minimising the Impact of Cyber Security Incidents: response and recovery planning, and lessons learned
How do CAF 4.0 assessments work?
Organizations can run assessments internally as self-assessments. Alternatively, an independent external entity can lead the assessment, such as a regulator or an NCSC-assured Cyber Resilience Audit (CRA) service provider. Moreover, the method stays the same in both cases. Specifically, assessors evaluate each contributing outcome against its Indicators of Good Practice (IGP) table and apply expert judgment.
In practice, each contributing outcome receives one of three ratings:
- Achieved (GREEN): the organization fully meets the outcome with sufficient evidence
- Partially Achieved (AMBER): the outcome is in progress or only partially met, where this intermediate state is permitted
- Not Achieved (RED): the organization does not meet the outcome
What is a CAF Profile and how do regulators use it?
A CAF Profile is a prioritized subset of contributing outcomes. Specifically, it represents an appropriate and proportionate cybersecurity target for a specific organization or sector. Moreover, regulators and cyber oversight bodies use profiles to set meaningful target levels of cyber resilience. As a result, different sectors operate against different target profiles that reflect their distinct risk environments.
In practice, CAF 4.0 introduces two standard profile types. The Basic Profile sets the target for all sectors when they face attackers with basic attack capability. The Enhanced Profile targets organizations that face more sophisticated threat actors. Furthermore, a working profile typically mixes outcomes targeted as Achieved, Partially Achieved, or Not Applicable. In other words, organizations do not need every outcome to reach full Achieved status.
Can regulators customize the NCSC CAF 4.0 for specific sectors?
Yes. The core of the NCSC CAF 4.0 applies broadly across all critical sectors. However, regulators and oversight bodies can extend it in three ways to meet sector-specific needs. As a result, the same framework serves energy operators, NHS trusts, financial market infrastructure providers, and central government departments, each with tailored expectations.
Specifically, the three customization levers are:
- Sector-specific CAF Profiles: defining which contributing outcomes organizations in the sector must target, and at what level
- Sector-specific interpretations: clarifying how existing contributing outcomes and IGPs apply in a particular operational context, such as operational technology environments
- Sector-specific additional outcomes: defining entirely new contributing outcomes and IGPs where the generic framework does not fully address the sector’s unique risks