NCSC Cyber Assessment Framework
The CAF is outcome-based rather than control-based: 14 principles across four objectives, each with contributing outcomes assessed as achieved, partially achieved, or not achieved, supported by indicators of good practice. It is an assessment framework, not a certification scheme — there is no CAF certificate to hold.
Does this apply to you?
The CAF was written for organisations whose disruption would have national consequence. That is a much narrower group than most security vendors imply, and it is worth checking before you spend anything against it.
You are likely in scope if
- You are an operator of essential services or a relevant digital service provider under the UK NIS Regulations 2018, and your competent authority has adopted the CAF as its assessment method.
- You are a UK government department or arm’s-length body assessed under GovAssure.
- A regulator, or a customer in one of the above categories, has asked you to self-assess against the CAF as part of assurance.
You are probably not in scope if
- You are a small or medium business with no sector regulator and no public-sector contract naming it. This is where most readers of this page will land, and the honest answer is that the CAF is not your framework — Cyber Essentials almost certainly is.
- You are looking for something to be certified against. The CAF produces a profile of achieved and not-achieved outcomes; nobody issues a CAF certificate.
What the framework asks for.
Named as the framework names them, with its own references, so you can check this page against the source below.
Managing security risk
Four principles: A1 governance, A2 risk management, A3 asset management, and A4 supply chain. Appropriate structures, policies and processes to understand, assess and systematically manage security risks to essential functions.
Protecting against cyber attack
Six principles: B1 service protection policies and processes, B2 identity and access control, B3 data security, B4 system security, B5 resilient networks and systems, and B6 staff awareness and training. Proportionate security measures to protect essential functions from cyber attack.
Detecting cyber security events
Two principles: C1 security monitoring, and C2 proactive security event discovery. Capabilities to ensure security defences remain effective and to detect cyber security events affecting, or with the potential to affect, essential functions.
Minimising the impact of cyber security incidents
Two principles: D1 response and recovery planning, and D2 lessons learned. Capabilities to minimise the adverse impact of a cyber security incident on the operation of essential functions.
What Fortoxa puts against each requirement.
Fortoxa evidences parts of objectives B, C and D from server telemetry. Objective A is governance and is not telemetry at all — it does not appear in the register, and that is the correct outcome rather than a gap in coverage.
NCSC Cyber Assessment Framework — control register
Identity and access control
LiveSystem security
StaleResilient networks and systems
Not supported yetSecurity monitoring
LiveProactive security event discovery
LiveResponse and recovery planning
Awaiting telemetry
What stays your job.
Fortoxa evidences what it can observe on the servers you install the agent on. Everything below is outside that, and the register marks it as not measured rather than as a pass.
Objective A, in full
Governance, risk management, asset management and supply chain are organisational outcomes. They are evidenced by board minutes, risk registers, asset inventories and supplier contracts — none of which is server telemetry, and none of which Fortoxa produces.
B6 — staff awareness and training
Training records, awareness campaigns and their effectiveness. Fortoxa observes machines, not people.
D2 — lessons learned
Post-incident review is a process you run. Fortoxa gives you the timeline the review reads from; it does not conduct the review or record its conclusions.
The assessment itself
Contributing outcomes are judged against indicators of good practice by you or your competent authority. Fortoxa supplies evidence toward some of them and takes no position on whether an outcome is achieved.
Check this page against the text.
Everything above is Fortoxa's reading of the framework. It is not the framework, and it is not advice about your obligations. The publishers below are authoritative; this page is not.
See what your own servers produce.
Install the agent on one server and the register builds itself from what it finds — including the requirements it cannot see.