UK · Cyber Assessment Framework, published by the NCSC

NCSC Cyber Assessment Framework

The CAF is outcome-based rather than control-based: 14 principles across four objectives, each with contributing outcomes assessed as achieved, partially achieved, or not achieved, supported by indicators of good practice. It is an assessment framework, not a certification scheme — there is no CAF certificate to hold.

Scope

Does this apply to you?

The CAF was written for organisations whose disruption would have national consequence. That is a much narrower group than most security vendors imply, and it is worth checking before you spend anything against it.

You are likely in scope if

  • You are an operator of essential services or a relevant digital service provider under the UK NIS Regulations 2018, and your competent authority has adopted the CAF as its assessment method.
  • You are a UK government department or arm’s-length body assessed under GovAssure.
  • A regulator, or a customer in one of the above categories, has asked you to self-assess against the CAF as part of assurance.

You are probably not in scope if

  • You are a small or medium business with no sector regulator and no public-sector contract naming it. This is where most readers of this page will land, and the honest answer is that the CAF is not your framework — Cyber Essentials almost certainly is.
  • You are looking for something to be certified against. The CAF produces a profile of achieved and not-achieved outcomes; nobody issues a CAF certificate.

Which competent authority applies to you, whether it has adopted the CAF, and which target profile it expects are set by that authority under the NIS Regulations, not by the framework itself. Fortoxa does not determine whether you are an operator of essential services.

Requirements

What the framework asks for.

Named as the framework names them, with its own references, so you can check this page against the source below.

  • Objective A

    Managing security risk

    Four principles: A1 governance, A2 risk management, A3 asset management, and A4 supply chain. Appropriate structures, policies and processes to understand, assess and systematically manage security risks to essential functions.

  • Objective B

    Protecting against cyber attack

    Six principles: B1 service protection policies and processes, B2 identity and access control, B3 data security, B4 system security, B5 resilient networks and systems, and B6 staff awareness and training. Proportionate security measures to protect essential functions from cyber attack.

  • Objective C

    Detecting cyber security events

    Two principles: C1 security monitoring, and C2 proactive security event discovery. Capabilities to ensure security defences remain effective and to detect cyber security events affecting, or with the potential to affect, essential functions.

  • Objective D

    Minimising the impact of cyber security incidents

    Two principles: D1 response and recovery planning, and D2 lessons learned. Capabilities to minimise the adverse impact of a cyber security incident on the operation of essential functions.

The register

What Fortoxa puts against each requirement.

Fortoxa evidences parts of objectives B, C and D from server telemetry. Objective A is governance and is not telemetry at all — it does not appear in the register, and that is the correct outcome rather than a gap in coverage.

NCSC Cyber Assessment Framework — control register

4 of 6 evidenced

  • B2

    Identity and access control

    Accounts on the workspace, role held, when granted, and API keys outstanding

    workspace_members · 2 min ago

    Live
  • B4

    System security

    Host configuration and patch state per monitored server, with drift since the last collection

    fortoxa-agent · 1 day ago

    Stale
  • B5

    Resilient networks and systems

    Resilience testing and failover evidence are not produced by Fortoxa

    not collected by Fortoxa · never collected

    Not supported yet
  • C1

    Security monitoring

    Continuous event ingest with retained detection records

    log_events · 1 min ago

    Live
  • C2

    Proactive security event discovery

    Detections raised from ingested telemetry

    log_events · 1 min ago

    Live
  • D1

    Response and recovery planning

    Response actions taken, by whom, and when

    blocked_ips · never collected

    Awaiting telemetry

Rows marked as not measured are shown, not hidden. A register with every requirement satisfied is the outcome this product exists to prevent.

Example workspace, sample data. Your own register is built from your servers once an agent is installed.

Not covered

What stays your job.

Fortoxa evidences what it can observe on the servers you install the agent on. Everything below is outside that, and the register marks it as not measured rather than as a pass.

  • Objective A, in full

    Governance, risk management, asset management and supply chain are organisational outcomes. They are evidenced by board minutes, risk registers, asset inventories and supplier contracts — none of which is server telemetry, and none of which Fortoxa produces.

  • B6 — staff awareness and training

    Training records, awareness campaigns and their effectiveness. Fortoxa observes machines, not people.

  • D2 — lessons learned

    Post-incident review is a process you run. Fortoxa gives you the timeline the review reads from; it does not conduct the review or record its conclusions.

  • The assessment itself

    Contributing outcomes are judged against indicators of good practice by you or your competent authority. Fortoxa supplies evidence toward some of them and takes no position on whether an outcome is achieved.

Sources

Check this page against the text.

Everything above is Fortoxa's reading of the framework. It is not the framework, and it is not advice about your obligations. The publishers below are authoritative; this page is not.

Next

See what your own servers produce.

Install the agent on one server and the register builds itself from what it finds — including the requirements it cannot see.

The control register and the evidence export are Business features, £349/month. Monitoring, alerts and the live activity feed start at £29 on Micro, which does not include the register. Starter and Business include a 14-day trial on a new subscription.