Cyber Assessment Framework
Aligning critical infrastructure and major organizations with the NCSC's CAF. Proportionate security for complex operational environments.
what is it & core principles
The Cyber Assessment Framework (CAF) is a collection of 14 principles established by the NCSC, designed primarily for organisations that are necessary to the UK economy and those subject to the NIS Regulations.
It focuses heavily on cyber resilience - ensuring that not only are networks secure, but that essential services can continue operating effectively even during a cyber incident.
why you need it
If you operate in the national infrastructure supply chain, the CAF is rapidly becoming the mandatory standard of compliance. Regulatory bodies use the CAF to assess whether organizations are meeting their statutory security duties under UK law.
Unlike binary pass/fail standards, the CAF utilizes a tiered system of Indicators of Good Practice (IGPs), making it both nuanced and demanding for larger organisations.
how verd standard can help
Translating the CAF's principles into defined engineering tasks is complex. We act as the bridge between regulatory expectations and your currect techincal infrastructure.
We possess expertise in mapping operational technology and IT environments against CAF requirements, developing realistic transition plans that secure your essential functions without disrupting critical uptime.
our process
1. Profiling & System Mapping: Identifying the specific networks and systems that actually deliver your essential functions, separating them from general IT to narrow the assessment scope.
2. IGP Assessment: Conducting a comprehensive gap analysis against the CAF's Indicators of Good Practice to determine your baseline resilience.
3. Strategic Remediation Planning: Creating a prioritized, costed roadmap to move your organization from 'Not Achieved' to 'Achieved' across critical principles.
4. Board & Regulator Reporting: Packaging the technical assessment into clear risk narratives suitable for board members and external regulatory bodies.