Skip to main content
Hero background

Cyber Assessment Framework

What Is the Cyber Assessment Framework?

The Cyber Assessment Framework (CAF) is a cybersecurity framework developed by the U.K.’s National Cyber Security Centre (NCSC) to help organizations assess and strengthen their ability to manage cyber risk, protect essential services, and maintain operational resilience. CAF is primarily used by organizations responsible for essential services and critical infrastructure, including sectors such as energy, healthcare, transport, water, digital infrastructure, and government services. Regulators and competent authorities use CAF to assess whether organizations are achieving expected cybersecurity outcomes under applicable requirements, including the Network and Information Systems (NIS) Regulations. 

Unlike a certification scheme, CAF does not provide a formal pass or fail designation. Instead, it evaluates how effectively organizations achieve defined cybersecurity outcomes through governance, processes, technologies, and operational practices. Organizations can use CAF for self-assessments, independent assurance activities, regulatory reviews, and continuous improvement initiatives. The framework follows an outcomes-based approach, allowing organizations to demonstrate security effectiveness based on their operational environment rather than requiring specific technologies or configurations. This allows organizations with different structures, risk profiles, and technology environments to apply appropriate security measures while maintaining alignment with core cybersecurity objectives. 

The framework is organized around four key objectives: 

  1. Managing security risk 

  2. Protecting against cyber attack 

  3. Detecting cybersecurity events 

  4. Minimizing the impact of cybersecurity incidents 

Each objective includes principles, contributing outcomes, and Indicators of Good Practice (IGPs) that help organizations evaluate cybersecurity maturity and demonstrate effective security practices. Assessments consider areas such as governance, risk management, access control, monitoring, incident response, recovery planning, and third-party risk management. 

Updated CAF guidance introduces Basic and Enhanced Profiles that help organizations align cybersecurity expectations with their threat environment and operational requirements. 

Basic Profile 
Provides foundational expectations for organizations seeking protection against common cyber threats. 

Enhanced Profile 
Addresses more advanced cybersecurity expectations for organizations facing sophisticated threats and higher-risk operational environments. 

As CAF continues to evolve, updates such as CAF 2.0 provide additional guidance to improve consistency, interpretation, and assessment of practices across sectors. 

The Importance of the Cyber Assessment Framework

Essential services depend on reliable digital systems, making cybersecurity a critical component of operational resilience. CAF enables organizations to assess whether cybersecurity measures are actively implemented, monitored, and continually improved while providing evidence to demonstrate security effectiveness. 

By focusing on measurable outcomes, CAF provides a common framework for organizations, regulators, and security stakeholders to evaluate cybersecurity effectiveness consistently. This enables decision-makers to evaluate cybersecurity effectiveness, prioritize investments, and strengthen resilience based on operational risk. 

The framework supports organizations by providing: 

  • Consistent evaluation of cybersecurity capabilities across critical sectors 

  • Evidence-based assessment of security controls, governance practices, and operational resilience 

  • Clear alignment between cybersecurity investments and essential service requirements 

  • Structured identification of security gaps and improvement opportunities 

  • Improved accountability through defined responsibilities, oversight, and risk management processes 

CAF complements recognized cybersecurity frameworks and standards, including ISO/IEC 27001 and the NIST Cybersecurity Framework. Organizations can leverage existing security programs and controls while using CAF outcomes to evaluate resilience and identify areas for improvement. 

For government and critical infrastructure leaders, CAF provides a practical approach for strengthening cybersecurity programs, improving operational readiness, and ensuring essential services remain reliable in an evolving threat environment. 

Key Elements of the Cyber Assessment Framework

CAF assessments evaluate how governance, people, processes, and technologies work together to protect essential services and achieve defined cybersecurity outcomes. Organizations are expected to provide evidence that cybersecurity practices are established, implemented, monitored, and continually improved. Rather than evaluating individual products or technologies, CAF assesses whether organizations have the governance, operational processes, and capabilities needed to manage cyber risk and maintain secure service delivery. 

CAF assessments typically evaluate: 

  • Governance and accountability 

  • Risk management processes 

  • Protective security controls 

  • Monitoring and detection capabilities 

  • Incident response and recovery activities 

  • Evidence supporting cybersecurity outcomes 

These elements help organizations demonstrate cybersecurity effectiveness, support operational resilience, and achieve CAF outcomes. 

Cyber Assessment Framework Objectives and Security Outcomes

CAF is structured around four core objectives that define the key areas required for effective cyber resilience. 

Managing Security Risk 

This objective focuses on ensuring organizations have the governance structures, processes, and oversight needed to identify, assess, and manage cybersecurity risks. 

Key areas include: 

  • Clear ownership and accountability for cybersecurity risk 

  • Defined risk management processes aligned with organizational priorities 

  • Integration of cybersecurity considerations into business and operational decisions 

  • Oversight of suppliers, dependencies, and third-party risks 

  • Regular evaluation of threats, vulnerabilities, and potential service impacts 

The intended outcome is that organizations maintain visibility into cybersecurity risks and have appropriate processes in place to prioritize and address security challenges. 

Protecting Against Cyber Attack 

This objective focuses on implementing proportionate security measures that protect essential systems, services, and information from cyber threats. 

Key areas include: 

  • Secure configuration management for critical systems and devices 

  • Identity and access controls that limit unauthorized activity 

  • Vulnerability management and timely remediation practices 

  • Protection of sensitive information through appropriate safeguards 

  • Security measures that reduce exposure across systems, applications, and networks 

The intended outcome is that essential services operate securely with appropriate protections in place to reduce the likelihood and impact of cyber-attacks. 

Detecting Cybersecurity Events 

This objective evaluates an organization’s ability to identify cybersecurity events through effective monitoring, detection, and analysis capabilities. 

Key areas include: 

  • Security monitoring across critical systems and services 

  • Logging and event management practices 

  • Detection capabilities that identify suspicious activity 

  • Processes for investigating and escalating security events 

  • Visibility into user, device, and system activity 

The intended outcome is that organizations can identify cybersecurity events quickly and accurately, enabling timely investigation and response. 

Minimizing the Impact of Cybersecurity Incidents 

This objective focuses on an organization’s ability to respond to cybersecurity incidents, maintain essential operations, and recover effectively. 

Key areas include: 

  • Documented incident response plans and escalation procedures 

  • Communication processes for internal teams, suppliers, and relevant authorities 

  • Recovery strategies supported by tested backup and restoration procedures 

  • Post-incident reviews that identify opportunities for improvement 

  • Regular exercises that test and improve response capabilities 

The intended outcome is that organizations can limit disruption, restore critical services, and strengthen resilience following cybersecurity incidents. 

Principles and Indicators of Good Practice for the Cyber Assessment Framework

Each CAF objective includes principles, contributing outcomes, and Indicators of Good Practice (IGPs). These components help organizations understand effective cybersecurity practices and provide guidance for demonstrating achievement. 

IGPs describe examples of activities and practices that contribute to achieving CAF outcomes. They are not prescriptive requirements but help organizations and assessors evaluate whether security measures are appropriately designed and operating effectively. 

Evidence used to support CAF assessments may include: 

  • Cybersecurity policies, standards, and governance documentation 

  • Risk assessments and treatment plans 

  • Asset inventories and system documentation 

  • Identity and access management reviews 

  • Security monitoring records and operational dashboards 

  • Incident response plans and exercise outcomes 

  • Supplier security assessments 

  • Vulnerability management reports 

CAF emphasizes the importance of connecting documented processes with operational evidence. Organizations should be able to demonstrate that security measures are actively supporting resilience in real-world environments. 

Cyber Assessment Framework Assessment Challenges

Organizations may encounter challenges when preparing for CAF assessments, particularly when cybersecurity practices are not consistently documented, measured, or integrated into operational processes. 

Common challenges include: 

  • Incomplete asset inventories that limit visibility into critical dependencies 

  • Reliance on policies without supporting operational evidence 

  • Limited monitoring coverage across essential systems 

  • Untested incident response and recovery procedures 

  • Insufficient oversight of third-party and supplier risks 

  • Security improvements that are not prioritized according to operational impact 

Addressing these challenges requires a risk-based approach focused on achieving measurable cybersecurity outcomes. Continuous improvement, supported by evidence and accountability, enables organizations to strengthen resilience as threats and operational requirements evolve. 

Cyber Assessment Framework Use Cases

CAF supports organizations across government, critical infrastructure, and regulated sectors by providing a consistent approach for evaluating cybersecurity resilience. Its outcomes can be adapted to different operational environments, technology architectures, and threat profiles while maintaining a common framework for governance, assurance, and continuous improvement. 

CAF is particularly valuable for organizations responsible for essential services, where cybersecurity directly impacts operational continuity, public safety, and mission delivery. 

Critical Infrastructure Operations 

Critical infrastructure organizations depend on secure and resilient systems to maintain essential services. CAF helps operators evaluate whether cybersecurity practices are effectively protecting operational technology (OT), enterprise systems, and supporting dependencies. 

Common applications include: 

  • Energy and utilities requiring high availability, secure control environments, and resilient operational networks 

  • Water and wastewater services relying on telemetry, access controls, and reliable recovery capabilities 

  • Transport systems managing safety-critical operations and interconnected digital infrastructure 

For critical infrastructure operators, CAF provides a structured approach for assessing whether cybersecurity measures support reliable service delivery. The framework helps connect cybersecurity governance with operational requirements by ensuring risks are identified, prioritized, and addressed based on their impact on essential functions. 

Health and Public Services 

Healthcare and public sector organizations manage sensitive information and deliver services that require strong availability, integrity, and protection against disruption. CAF helps these organizations evaluate cybersecurity practices across clinical systems, administrative platforms, and citizen-facing services. 

Common applications include: 

  • Healthcare systems requiring protection of patient information, clinical applications, and time-sensitive services 

  • Public service platforms requiring secure identity management and reliable access controls 

  • Cross-agency environments requiring secure data exchange and third-party oversight 

By focusing on measurable security outcomes, CAF enables organizations to demonstrate effective management of identity, access, monitoring, incident response, and recovery capabilities. These practices support service continuity while maintaining public trust in essential digital services. 

Digital Infrastructure and Cloud-Enabled Services 

Modern digital infrastructure relies on interconnected platforms, cloud services, and third-party providers. CAF helps organizations establish clear security responsibilities and demonstrate that cybersecurity controls are operating effectively across complex technology environments. 

Common applications include: 

  • Managed service environments supporting essential operations through shared responsibility models 

  • Hybrid and multi-cloud architectures requiring consistent security controls and governance 

  • Data platforms and application interfaces requiring effective monitoring, protection, and response processes 

CAF supports organizations in maintaining visibility across internal systems and external suppliers by connecting cybersecurity outcomes with evidence, accountability, and operational performance. This approach helps organizations demonstrate resilience as technology environments continue to evolve. 

Government and Regulated Organizations 

Government departments and regulated organizations use CAF to strengthen cybersecurity governance, improve assurance processes, and align security practices with operational responsibilities. 

Common applications include: 

  • Government services requiring protection of sensitive information and critical systems 

  • Regulatory environments requiring evidence-based cybersecurity assessments 

  • Organizations seeking to improve resilience through structured security improvement programs 

Through its outcomes-based approach, CAF helps organizations evaluate cybersecurity maturity, prioritize improvements, and demonstrate ongoing commitment to protecting essential services. By connecting security practices with measurable outcomes, CAF enables leaders to make informed decisions that support operational resilience and public confidence. 

 

BlackBerry for Secure Communications

For Environments Where Failure Isn’t an Option

BlackBerry Secure Communications is the leading solution that delivers unmatched expertise to protect the world’s most critical communications.

Explore BlackBerry Secure Communications solutions