Skip to content
All frameworks

What is NCSC Cyber Assessment Framework v4.0?

The UK National Cyber Security Centre's Cyber Assessment Framework. It is an outcome-based framework — it describes what good looks like rather than prescribing controls — and is the assessment method behind the UK's NIS Regulations.

Who it binds

Operators of essential services and relevant digital service providers under the NIS Regulations 2018, and increasingly UK public sector bodies through GovAssure. Any organisation may use it voluntarily.

4
objectives

Managing risk, protecting against attack, detecting events, minimising impact.

14
principles

Grouped under the four objectives.

41
contributing outcomes

The level assessments are actually made at.

Dates that matter

  • 4 August 2025Version 4.0 published.
  • Before ParliamentThe Cyber Security and Resilience Bill would replace the NIS Regulations 2018 and bring managed service providers into scope.

What people get wrong

Outcomes, not a checklist

Each contributing outcome is assessed as Achieved, Partially Achieved or Not Achieved against indicators of good practice. There is no score and no pass mark — the framework is explicitly a basis for informed judgement, which is why any tool claiming a CAF percentage is telling you something the framework does not define.

The UK is not under NIS2, and the distinction is substantive

Directive (EU) 2022/2555 binds member states. UK operators are under the NIS Regulations 2018 (SI 2018/506). Vivid Risk cites the CAF and UK GDPR for UK organisations and emits no NIS2 article — six places in this product said otherwise until September 2026, and a test now pins every one of them.

MSPs are being brought into scope

The Cyber Security and Resilience Bill would regulate managed service providers as entities in their own right, not merely as suppliers. If you run a practice, that is a change to your own obligations, not just your clients'.

What Vivid Risk does with NCSC Cyber Assessment Framework v4.0

Contributing-outcome citations on every scored control, read against the CAF v4.0 document published 4 August 2025.

A self-assessment against the framework, not an NCSC or regulator assessment.

Questions

Is a CAF self-assessment the same as an NCSC assessment?

No. What Vivid Risk produces is a self-assessment against the framework with a citation on every scored control. A regulator or an NCSC-led assessment is a different exercise with a different standing.

Which CAF version do you use?

v4.0, released 4 August 2025, read directly from the published document. All 41 contributing outcomes are held with their exact titles.

One assessment, every framework

The same answers produce your citations across every framework we cover at once, rather than one questionnaire per regulation.