Skip to main content

Stewart Hogg

Associate Director - Cyber

The Cyber Assessment Framework, better known as the CAF, is a set of guidelines developed by the UK’s National Cyber Security Centre (NCSC) that plays a significant role in helping organisations demonstrate a gold standard approach to cyber resilience. Though it's been around since 2019, It's gaining broader attention now due to the upcoming expansion of the UK’s cyber legislation; bringing a wider range of sectors, including health, housing, and various areas of the public sector into scope. But it won’t stop there; many organisations outside of these categories will also be affected due to their roles in critical supply chains. So even if your organisation isn’t directly in scope, you may still be required to demonstrate cyber resilience through your connections to those that are.

All you need to know about the CAF in one place

Our experts have curated a practitioner's guide specifically tailored to give you everything you need to not only understand what CAF means to your business, but the next steps to take to make sure you're up to date with the legislation.

Download the guide
click the link to download

Our CAF services

 

CAF implementation support

Working closely with your internal teams, our consultants design and deploy controls aligned with CAF principles, covering governance, risk management, protective measures, and incident response.  

This also includes policy development, technical improvements, and cultural change initiatives such as staff training – all tailored to your sector and maturity level, ensuring that implementation is proportionate and sustainable. Our collaborative approach accelerates progress, builds internal capability, and ensures that CAF adoption delivers real-world resilience and compliance outcomes. 

CAF audit readiness assessment

We’ll conduct a structured review of your existing cyber controls, policies, and practices against CAF requirements, identifying gaps and strengths, then make recommendations remediation and prioritisation, helping you understand what needs to be addressed before undergoing an independent audit.  

This is particularly valuable for regulated entities facing upcoming compliance deadlines - by simulating audit conditions, we’ll help you and your team not only be technically ready, but also confident in your ability to demonstrate compliance and resilience to regulators and stakeholders. 

CAF independent audit

As an NCSC Assured Consultancy, we provide independent audits to validate your CAF compliance. Our auditors hold chartered credentials and adopt a pragmatic, value-focused approach.

The audit – which is a requirement for many public sector and regulated organisations - covers governance, risk management, technical controls, and operational resilience, producing a detailed report suitable for submission to regulators.

This service offers assurance to oversight bodies and internal stakeholders, confirming that cyber risks are being managed effectively and that the organisation meets sector-specific CAF expectations. 

Free CAF briefing

We help organisations understand the Cyber Assessment Framework and its implications through an introductory briefing session. Delivered by experienced consultants, the briefing covers CAF principles, sector-specific requirements, and common challenges, and is ideal for leadership teams, IT managers, and compliance officers seeking clarity on what CAF means for their organisation.  

The session includes practical advice, examples, and Q&A, helping participants assess their current position and plan next steps. It’s a no-obligation way to engage with our experts and begin your journey toward CAF compliance with confidence. 

CAF gap analysis

We’ll conduct a gap analysis to determine how your current cyber maturity compares to the Cyber Assessment Framework (CAF) requirements through assessing existing controls, policies, and practices, identifying strengths and areas for improvement.  

The output is a clear roadmap for achieving CAF compliance, highlighting priority actions and potential risks.  

If you’re starting out on your CAF journey, or simply seeking to benchmark progress, we can help provide clear, targeted, and proportionate actions – avoiding unnecessary work and helping you to focus on what matters most for resilience, regulatory alignment, and operational continuity. 

image

Find out how ready your business is for CAF compliance

In 14 simple questions based on the Cyber Assessment Framework principles, we can understand how prepared your organisation is for CAF compliance. You’ll receive a FREE report tailored to your business, which will allow you to take the steps needed to improve your cyber security and be CAF compliant.

Start the questionnaire
image

Partners and accreditations

logo

NCSC Cyber Resilience Audit Scheme – Assured Service Providers

logo

NCSC Consultancy: Audit and review service provider

logo

NCSC Consultancy: risk management service provider

Cyber Essentials Logo

Cyber Essentials

Cyber Security Council 24-25

UK Cyber Security Council Affiliate Member

CREST PEN testing

CREST Penetration Testing

CREST SOC

CREST SOC

Cyber Essentials Pus

Cyber Essentials PLUS

Ready to reimagine your business?

We’re with you.

Stewart Hogg

Associate Director - Cyber