Back to Frameworks

UK NCSC Cyber Assessment Framework

United Kingdom
vCyber Assessment Framework v4.0 (published 6 August 2025)
4 domains
41 controls

The NCSC Cyber Assessment Framework v4.0 (August 2025): 4 objectives, 14 principles and 41 contributing outcomes, each assessed as achieved, partially achieved or not achieved against indicators of good practice, used by regulators and oversight bodies to assess the cyber resilience of organisations delivering essential functions. 41 leaves read against v4.0.

Verified

UK NCSC Cyber Assessment Framework is a compliance framework from United Kingdom with 4 domains and 41 controls. The largest domains are Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework (20 controls), Objective A: Managing security risk – UK NCSC Cyber Assessment Framework (9 controls), Objective C: Detecting cyber security events – UK NCSC Cyber Assessment Framework (7 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Objective A: Managing security risk – UK NCSC Cyber Assessment Framework

9 controls
Controls in the Objective A: Managing security risk – UK NCSC Cyber Assessment Framework domain of UK NCSC Cyber Assessment Framework — 9 controls
CodeTitle
uk-ncsc-caf::A1.aA1.a Board direction
uk-ncsc-caf::A1.bA1.b Roles and responsibilities
uk-ncsc-caf::A1.cA1.c Decision-making
uk-ncsc-caf::A2.aA2.a Risk management process
uk-ncsc-caf::A2.bA2.b Understanding threat
uk-ncsc-caf::A2.cA2.c Assurance
uk-ncsc-caf::A3.aA3.a Asset management
uk-ncsc-caf::A4.aA4.a Supply chain
uk-ncsc-caf::A4.bA4.b Secure software development and support

Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework

20 controls
Controls in the Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework domain of UK NCSC Cyber Assessment Framework — 20 controls
CodeTitle
uk-ncsc-caf::B1.aB1.a Policy, process and procedure development
uk-ncsc-caf::B1.bB1.b Policy, process and procedure implementation
uk-ncsc-caf::B2.aB2.a Identity verification, authentication and authorisation
uk-ncsc-caf::B2.bB2.b Device management
uk-ncsc-caf::B2.cB2.c Privileged user management
uk-ncsc-caf::B2.dB2.d Identity and access management
uk-ncsc-caf::B3.aB3.a Understanding data
uk-ncsc-caf::B3.bB3.b Data in transit
uk-ncsc-caf::B3.cB3.c Stored data
uk-ncsc-caf::B3.dB3.d Mobile data
uk-ncsc-caf::B3.eB3.e Media and equipment sanitisation
uk-ncsc-caf::B4.aB4.a Secure by design
uk-ncsc-caf::B4.bB4.b Secure configuration
uk-ncsc-caf::B4.cB4.c Secure management
uk-ncsc-caf::B4.dB4.d Vulnerability management
uk-ncsc-caf::B5.aB5.a Resilience preparation
uk-ncsc-caf::B5.bB5.b Design for resilience
uk-ncsc-caf::B5.cB5.c Backups
uk-ncsc-caf::B6.aB6.a Cyber security culture
uk-ncsc-caf::B6.bB6.b Cyber security training

Objective C: Detecting cyber security events – UK NCSC Cyber Assessment Framework

7 controls
Controls in the Objective C: Detecting cyber security events – UK NCSC Cyber Assessment Framework domain of UK NCSC Cyber Assessment Framework — 7 controls
CodeTitle
uk-ncsc-caf::C1.aC1.a Sources and tools for logging and monitoring
uk-ncsc-caf::C1.bC1.b Securing logs
uk-ncsc-caf::C1.cC1.c Generating alerts
uk-ncsc-caf::C1.dC1.d Triage of security alerts
uk-ncsc-caf::C1.eC1.e Personnel skills for monitoring and detection
uk-ncsc-caf::C1.fC1.f Understanding user and system behaviour, and threat intelligence
uk-ncsc-caf::C2.aC2.a Threat hunting

Objective D: Minimising the impact of cyber security incidents – UK NCSC Cyber Assessment Framework

5 controls
Controls in the Objective D: Minimising the impact of cyber security incidents – UK NCSC Cyber Assessment Framework domain of UK NCSC Cyber Assessment Framework — 5 controls
CodeTitle
uk-ncsc-caf::D1.aD1.a Response plan
uk-ncsc-caf::D1.bD1.b Response and recovery capability
uk-ncsc-caf::D1.cD1.c Testing and exercising
uk-ncsc-caf::D2.aD2.a Post incident analysis
uk-ncsc-caf::D2.bD2.b Using incidents to drive improvements

What is UK NCSC Cyber Assessment Framework and who does it apply to?

UK NCSC Cyber Assessment Framework is a compliance framework from United Kingdom with 4 domains and 41 controls. The NCSC Cyber Assessment Framework v4.0 (August 2025): 4 objectives, 14 principles and 41 contributing outcomes, each assessed as achieved, partially achieved or not achieved against indicators of good practice, used by regulators and oversight bodies to assess the cyber resilience of organisations delivering essential functions. 41 leaves read against v4.0. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does UK NCSC Cyber Assessment Framework actually require?

UK NCSC Cyber Assessment Framework has 41 controls organised across 4 domains. The largest domains are Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework (20 controls), Objective A: Managing security risk – UK NCSC Cyber Assessment Framework (9 controls), Objective C: Detecting cyber security events – UK NCSC Cyber Assessment Framework (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of UK NCSC Cyber Assessment Framework do I already cover?

UK NCSC Cyber Assessment Framework does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement UK NCSC Cyber Assessment Framework?

Start your UK NCSC Cyber Assessment Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK NCSC Cyber Assessment Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 41 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.

Get Started Free →

Free forever — no credit card required