Security, Resilience & Assurance · United Kingdom
NCSC Cyber Assessment Framework, version 4.0
An outcome-based framework from the UK's National Cyber Security Centre, used to assess cyber resilience across four objectives and fourteen principles. It underpins regulatory assessment for UK operators of essential services and is increasingly referenced by the Cyber Security and Resilience Bill.
REGULATORNational Cyber Security Centre (NCSC)
REGIONUnited Kingdom
EFFECTIVEPublished 6 August 2025
Who it applies to
- UK operators of essential services assessed by a Competent Authority
- Organisations voluntarily benchmarking their cyber resilience maturity
- Suppliers to CAF-assessed organisations, via the framework's supply chain principle
Key requirements
- Governance: board-level ownership of cyber risk (Objective A)
- Protecting against attack: access control, data security, system hardening (Objective B)
- Detecting events: security monitoring and proactive threat hunting (Objective C)
- Minimising impact: response, recovery and lessons learned (Objective D)
- Evidenced, not merely claimed, supplier risk management under Principle A4
Maximum penaltyNot a statutory penalty regime itself — outcomes feed into regulatory decisions under the NIS Regulations and its successor legislation
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates CAF 4.0 compliance
Continuous monitoring, evidence and reporting for CAF 4.0 — alongside every other framework you need to satisfy.