The Plain English Version

The CAF is the UK National Cyber Security Centre's framework for assessing how well an organisation manages cyber risk to its essential functions. It is used by UK regulators to assess operators of essential services, and by government departments through the GovAssure programme.

Unlike a checklist standard, the CAF is outcome-based. It does not tell you which products to buy or which controls to tick. It asks whether you actually achieve a set of security outcomes, and you evidence how.

Who Does the CAF Apply To?

Operators of essential services regulated under the UK NIS Regulations (energy, transport, health, water, digital infrastructure), government organisations under GovAssure, and increasingly the wider public sector and critical national infrastructure supply chain. If you supply any of these, expect CAF-shaped questions.

The Four Objectives

  • A: Managing security risk - Governance, risk management, asset management and supply chain
  • B: Protecting against cyber attack - Service protection policies, identity and access, data security, system security, resilient networks and staff awareness
  • C: Detecting cyber security events - Security monitoring and proactive event discovery
  • D: Minimising the impact of incidents - Response and recovery planning, and lessons learned

The objectives break down into fourteen principles, each assessed against indicators of good practice as achieved, partially achieved, or not achieved.

Why This Matters for SMEs

The CAF is spreading beyond its original regulated audience. Public sector buyers and critical infrastructure operators are pushing CAF-style outcome evidence into procurement, so suppliers increasingly need to show how they achieve the outcomes rather than just naming a certificate.

Getting Prepared

Start by identifying your essential functions and mapping which of the fourteen principles apply. Gather evidence per outcome rather than per control: a single well-run process often covers several indicators. If you already run ISO 27001 or Cyber Essentials, much of the work maps across, but the CAF will probe whether the outcomes are genuinely achieved in practice.