Praeferre/Frameworks/CAF 4.0
Security, Resilience & Assurance · United Kingdom

NCSC Cyber Assessment Framework, version 4.0

An outcome-based framework from the UK's National Cyber Security Centre, used to assess cyber resilience across four objectives and fourteen principles. It underpins regulatory assessment for UK operators of essential services and is increasingly referenced by the Cyber Security and Resilience Bill.

REGULATORNational Cyber Security Centre (NCSC) REGIONUnited Kingdom EFFECTIVEPublished 6 August 2025

Who it applies to

  • UK operators of essential services assessed by a Competent Authority
  • Organisations voluntarily benchmarking their cyber resilience maturity
  • Suppliers to CAF-assessed organisations, via the framework's supply chain principle

Key requirements

  • Governance: board-level ownership of cyber risk (Objective A)
  • Protecting against attack: access control, data security, system hardening (Objective B)
  • Detecting events: security monitoring and proactive threat hunting (Objective C)
  • Minimising impact: response, recovery and lessons learned (Objective D)
  • Evidenced, not merely claimed, supplier risk management under Principle A4

Maximum penaltyNot a statutory penalty regime itself — outcomes feed into regulatory decisions under the NIS Regulations and its successor legislation

Go to the source

Official resources

Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.

Start your compliance journey

See how Praeferre automates CAF 4.0 compliance

Continuous monitoring, evidence and reporting for CAF 4.0 — alongside every other framework you need to satisfy.