%3Aquality(100)&w=3840&q=75)
Cyber Assessment Framework
What Is the Cyber Assessment Framework?
The Cyber Assessment Framework (CAF) is a cybersecurity framework developed by the U.K.’s National Cyber Security Centre (NCSC) to help organizations assess and strengthen their ability to manage cyber risk, protect essential services, and maintain operational resilience. CAF is primarily used by organizations responsible for essential services and critical infrastructure, including sectors such as energy, healthcare, transport, water, digital infrastructure, and government services. Regulators and competent authorities use CAF to assess whether organizations are achieving expected cybersecurity outcomes under applicable requirements, including the Network and Information Systems (NIS) Regulations.
Unlike a certification scheme, CAF does not provide a formal pass or fail designation. Instead, it evaluates how effectively organizations achieve defined cybersecurity outcomes through governance, processes, technologies, and operational practices. Organizations can use CAF for self-assessments, independent assurance activities, regulatory reviews, and continuous improvement initiatives. The framework follows an outcomes-based approach, allowing organizations to demonstrate security effectiveness based on their operational environment rather than requiring specific technologies or configurations. This allows organizations with different structures, risk profiles, and technology environments to apply appropriate security measures while maintaining alignment with core cybersecurity objectives.
The framework is organized around four key objectives:
Managing security risk
Protecting against cyber attack
Detecting cybersecurity events
Minimizing the impact of cybersecurity incidents
Each objective includes principles, contributing outcomes, and Indicators of Good Practice (IGPs) that help organizations evaluate cybersecurity maturity and demonstrate effective security practices. Assessments consider areas such as governance, risk management, access control, monitoring, incident response, recovery planning, and third-party risk management.
Updated CAF guidance introduces Basic and Enhanced Profiles that help organizations align cybersecurity expectations with their threat environment and operational requirements.
Basic Profile
Provides foundational expectations for organizations seeking protection against common cyber threats.
Enhanced Profile
Addresses more advanced cybersecurity expectations for organizations facing sophisticated threats and higher-risk operational environments.
As CAF continues to evolve, updates such as CAF 2.0 provide additional guidance to improve consistency, interpretation, and assessment of practices across sectors.
The Importance of the Cyber Assessment Framework
Essential services depend on reliable digital systems, making cybersecurity a critical component of operational resilience. CAF enables organizations to assess whether cybersecurity measures are actively implemented, monitored, and continually improved while providing evidence to demonstrate security effectiveness.
By focusing on measurable outcomes, CAF provides a common framework for organizations, regulators, and security stakeholders to evaluate cybersecurity effectiveness consistently. This enables decision-makers to evaluate cybersecurity effectiveness, prioritize investments, and strengthen resilience based on operational risk.
The framework supports organizations by providing:
Consistent evaluation of cybersecurity capabilities across critical sectors
Evidence-based assessment of security controls, governance practices, and operational resilience
Clear alignment between cybersecurity investments and essential service requirements
Structured identification of security gaps and improvement opportunities
Improved accountability through defined responsibilities, oversight, and risk management processes
CAF complements recognized cybersecurity frameworks and standards, including ISO/IEC 27001 and the NIST Cybersecurity Framework. Organizations can leverage existing security programs and controls while using CAF outcomes to evaluate resilience and identify areas for improvement.
For government and critical infrastructure leaders, CAF provides a practical approach for strengthening cybersecurity programs, improving operational readiness, and ensuring essential services remain reliable in an evolving threat environment.
Key Elements of the Cyber Assessment Framework
CAF assessments evaluate how governance, people, processes, and technologies work together to protect essential services and achieve defined cybersecurity outcomes. Organizations are expected to provide evidence that cybersecurity practices are established, implemented, monitored, and continually improved. Rather than evaluating individual products or technologies, CAF assesses whether organizations have the governance, operational processes, and capabilities needed to manage cyber risk and maintain secure service delivery.
CAF assessments typically evaluate:
Governance and accountability
Risk management processes
Protective security controls
Monitoring and detection capabilities
Incident response and recovery activities
Evidence supporting cybersecurity outcomes
These elements help organizations demonstrate cybersecurity effectiveness, support operational resilience, and achieve CAF outcomes.
Cyber Assessment Framework Objectives and Security Outcomes
CAF is structured around four core objectives that define the key areas required for effective cyber resilience.
Managing Security Risk
This objective focuses on ensuring organizations have the governance structures, processes, and oversight needed to identify, assess, and manage cybersecurity risks.
Key areas include:
Clear ownership and accountability for cybersecurity risk
Defined risk management processes aligned with organizational priorities
Integration of cybersecurity considerations into business and operational decisions
Oversight of suppliers, dependencies, and third-party risks
Regular evaluation of threats, vulnerabilities, and potential service impacts
The intended outcome is that organizations maintain visibility into cybersecurity risks and have appropriate processes in place to prioritize and address security challenges.
Protecting Against Cyber Attack
This objective focuses on implementing proportionate security measures that protect essential systems, services, and information from cyber threats.
Key areas include:
Secure configuration management for critical systems and devices
Identity and access controls that limit unauthorized activity
Vulnerability management and timely remediation practices
Protection of sensitive information through appropriate safeguards
Security measures that reduce exposure across systems, applications, and networks
The intended outcome is that essential services operate securely with appropriate protections in place to reduce the likelihood and impact of cyber-attacks.
Detecting Cybersecurity Events
This objective evaluates an organization’s ability to identify cybersecurity events through effective monitoring, detection, and analysis capabilities.
Key areas include:
Security monitoring across critical systems and services
Logging and event management practices
Detection capabilities that identify suspicious activity
Processes for investigating and escalating security events
Visibility into user, device, and system activity
The intended outcome is that organizations can identify cybersecurity events quickly and accurately, enabling timely investigation and response.
Minimizing the Impact of Cybersecurity Incidents
This objective focuses on an organization’s ability to respond to cybersecurity incidents, maintain essential operations, and recover effectively.
Key areas include:
Documented incident response plans and escalation procedures
Communication processes for internal teams, suppliers, and relevant authorities
Recovery strategies supported by tested backup and restoration procedures
Post-incident reviews that identify opportunities for improvement
Regular exercises that test and improve response capabilities
The intended outcome is that organizations can limit disruption, restore critical services, and strengthen resilience following cybersecurity incidents.
Principles and Indicators of Good Practice for the Cyber Assessment Framework
Each CAF objective includes principles, contributing outcomes, and Indicators of Good Practice (IGPs). These components help organizations understand effective cybersecurity practices and provide guidance for demonstrating achievement.
IGPs describe examples of activities and practices that contribute to achieving CAF outcomes. They are not prescriptive requirements but help organizations and assessors evaluate whether security measures are appropriately designed and operating effectively.
Evidence used to support CAF assessments may include:
Cybersecurity policies, standards, and governance documentation
Risk assessments and treatment plans
Asset inventories and system documentation
Identity and access management reviews
Security monitoring records and operational dashboards
Incident response plans and exercise outcomes
Supplier security assessments
Vulnerability management reports
CAF emphasizes the importance of connecting documented processes with operational evidence. Organizations should be able to demonstrate that security measures are actively supporting resilience in real-world environments.
Cyber Assessment Framework Assessment Challenges
Organizations may encounter challenges when preparing for CAF assessments, particularly when cybersecurity practices are not consistently documented, measured, or integrated into operational processes.
Common challenges include:
Incomplete asset inventories that limit visibility into critical dependencies
Reliance on policies without supporting operational evidence
Limited monitoring coverage across essential systems
Untested incident response and recovery procedures
Insufficient oversight of third-party and supplier risks
Security improvements that are not prioritized according to operational impact
Addressing these challenges requires a risk-based approach focused on achieving measurable cybersecurity outcomes. Continuous improvement, supported by evidence and accountability, enables organizations to strengthen resilience as threats and operational requirements evolve.
Cyber Assessment Framework Use Cases
CAF supports organizations across government, critical infrastructure, and regulated sectors by providing a consistent approach for evaluating cybersecurity resilience. Its outcomes can be adapted to different operational environments, technology architectures, and threat profiles while maintaining a common framework for governance, assurance, and continuous improvement.
CAF is particularly valuable for organizations responsible for essential services, where cybersecurity directly impacts operational continuity, public safety, and mission delivery.
Critical Infrastructure Operations
Critical infrastructure organizations depend on secure and resilient systems to maintain essential services. CAF helps operators evaluate whether cybersecurity practices are effectively protecting operational technology (OT), enterprise systems, and supporting dependencies.
Common applications include:
Energy and utilities requiring high availability, secure control environments, and resilient operational networks
Water and wastewater services relying on telemetry, access controls, and reliable recovery capabilities
Transport systems managing safety-critical operations and interconnected digital infrastructure
For critical infrastructure operators, CAF provides a structured approach for assessing whether cybersecurity measures support reliable service delivery. The framework helps connect cybersecurity governance with operational requirements by ensuring risks are identified, prioritized, and addressed based on their impact on essential functions.
Health and Public Services
Healthcare and public sector organizations manage sensitive information and deliver services that require strong availability, integrity, and protection against disruption. CAF helps these organizations evaluate cybersecurity practices across clinical systems, administrative platforms, and citizen-facing services.
Common applications include:
Healthcare systems requiring protection of patient information, clinical applications, and time-sensitive services
Public service platforms requiring secure identity management and reliable access controls
Cross-agency environments requiring secure data exchange and third-party oversight
By focusing on measurable security outcomes, CAF enables organizations to demonstrate effective management of identity, access, monitoring, incident response, and recovery capabilities. These practices support service continuity while maintaining public trust in essential digital services.
Digital Infrastructure and Cloud-Enabled Services
Modern digital infrastructure relies on interconnected platforms, cloud services, and third-party providers. CAF helps organizations establish clear security responsibilities and demonstrate that cybersecurity controls are operating effectively across complex technology environments.
Common applications include:
Managed service environments supporting essential operations through shared responsibility models
Hybrid and multi-cloud architectures requiring consistent security controls and governance
Data platforms and application interfaces requiring effective monitoring, protection, and response processes
CAF supports organizations in maintaining visibility across internal systems and external suppliers by connecting cybersecurity outcomes with evidence, accountability, and operational performance. This approach helps organizations demonstrate resilience as technology environments continue to evolve.
Government and Regulated Organizations
Government departments and regulated organizations use CAF to strengthen cybersecurity governance, improve assurance processes, and align security practices with operational responsibilities.
Common applications include:
Government services requiring protection of sensitive information and critical systems
Regulatory environments requiring evidence-based cybersecurity assessments
Organizations seeking to improve resilience through structured security improvement programs
Through its outcomes-based approach, CAF helps organizations evaluate cybersecurity maturity, prioritize improvements, and demonstrate ongoing commitment to protecting essential services. By connecting security practices with measurable outcomes, CAF enables leaders to make informed decisions that support operational resilience and public confidence.
%3Aquality(100)&w=3840&q=75)
BlackBerry for Secure Communications
For Environments Where Failure Isn’t an Option
BlackBerry Secure Communications is the leading solution that delivers unmatched expertise to protect the world’s most critical communications.
Explore BlackBerry Secure Communications solutions