UK NCSC Cyber Assessment Framework
The NCSC Cyber Assessment Framework v4.0 (August 2025): 4 objectives, 14 principles and 41 contributing outcomes, each assessed as achieved, partially achieved or not achieved against indicators of good practice, used by regulators and oversight bodies to assess the cyber resilience of organisations delivering essential functions. 41 leaves read against v4.0.
UK NCSC Cyber Assessment Framework is a compliance framework from United Kingdom with 4 domains and 41 controls. The largest domains are Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework (20 controls), Objective A: Managing security risk – UK NCSC Cyber Assessment Framework (9 controls), Objective C: Detecting cyber security events – UK NCSC Cyber Assessment Framework (7 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
Objective A: Managing security risk – UK NCSC Cyber Assessment Framework
| Code | Title |
|---|---|
| uk-ncsc-caf::A1.a | A1.a Board direction |
| uk-ncsc-caf::A1.b | A1.b Roles and responsibilities |
| uk-ncsc-caf::A1.c | A1.c Decision-making |
| uk-ncsc-caf::A2.a | A2.a Risk management process |
| uk-ncsc-caf::A2.b | A2.b Understanding threat |
| uk-ncsc-caf::A2.c | A2.c Assurance |
| uk-ncsc-caf::A3.a | A3.a Asset management |
| uk-ncsc-caf::A4.a | A4.a Supply chain |
| uk-ncsc-caf::A4.b | A4.b Secure software development and support |
Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework
| Code | Title |
|---|---|
| uk-ncsc-caf::B1.a | B1.a Policy, process and procedure development |
| uk-ncsc-caf::B1.b | B1.b Policy, process and procedure implementation |
| uk-ncsc-caf::B2.a | B2.a Identity verification, authentication and authorisation |
| uk-ncsc-caf::B2.b | B2.b Device management |
| uk-ncsc-caf::B2.c | B2.c Privileged user management |
| uk-ncsc-caf::B2.d | B2.d Identity and access management |
| uk-ncsc-caf::B3.a | B3.a Understanding data |
| uk-ncsc-caf::B3.b | B3.b Data in transit |
| uk-ncsc-caf::B3.c | B3.c Stored data |
| uk-ncsc-caf::B3.d | B3.d Mobile data |
| uk-ncsc-caf::B3.e | B3.e Media and equipment sanitisation |
| uk-ncsc-caf::B4.a | B4.a Secure by design |
| uk-ncsc-caf::B4.b | B4.b Secure configuration |
| uk-ncsc-caf::B4.c | B4.c Secure management |
| uk-ncsc-caf::B4.d | B4.d Vulnerability management |
| uk-ncsc-caf::B5.a | B5.a Resilience preparation |
| uk-ncsc-caf::B5.b | B5.b Design for resilience |
| uk-ncsc-caf::B5.c | B5.c Backups |
| uk-ncsc-caf::B6.a | B6.a Cyber security culture |
| uk-ncsc-caf::B6.b | B6.b Cyber security training |
Objective C: Detecting cyber security events – UK NCSC Cyber Assessment Framework
| Code | Title |
|---|---|
| uk-ncsc-caf::C1.a | C1.a Sources and tools for logging and monitoring |
| uk-ncsc-caf::C1.b | C1.b Securing logs |
| uk-ncsc-caf::C1.c | C1.c Generating alerts |
| uk-ncsc-caf::C1.d | C1.d Triage of security alerts |
| uk-ncsc-caf::C1.e | C1.e Personnel skills for monitoring and detection |
| uk-ncsc-caf::C1.f | C1.f Understanding user and system behaviour, and threat intelligence |
| uk-ncsc-caf::C2.a | C2.a Threat hunting |
Objective D: Minimising the impact of cyber security incidents – UK NCSC Cyber Assessment Framework
| Code | Title |
|---|---|
| uk-ncsc-caf::D1.a | D1.a Response plan |
| uk-ncsc-caf::D1.b | D1.b Response and recovery capability |
| uk-ncsc-caf::D1.c | D1.c Testing and exercising |
| uk-ncsc-caf::D2.a | D2.a Post incident analysis |
| uk-ncsc-caf::D2.b | D2.b Using incidents to drive improvements |
What is UK NCSC Cyber Assessment Framework and who does it apply to?
UK NCSC Cyber Assessment Framework is a compliance framework from United Kingdom with 4 domains and 41 controls. The NCSC Cyber Assessment Framework v4.0 (August 2025): 4 objectives, 14 principles and 41 contributing outcomes, each assessed as achieved, partially achieved or not achieved against indicators of good practice, used by regulators and oversight bodies to assess the cyber resilience of organisations delivering essential functions. 41 leaves read against v4.0. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does UK NCSC Cyber Assessment Framework actually require?
UK NCSC Cyber Assessment Framework has 41 controls organised across 4 domains. The largest domains are Objective B: Protecting against cyber attack – UK NCSC Cyber Assessment Framework (20 controls), Objective A: Managing security risk – UK NCSC Cyber Assessment Framework (9 controls), Objective C: Detecting cyber security events – UK NCSC Cyber Assessment Framework (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of UK NCSC Cyber Assessment Framework do I already cover?
UK NCSC Cyber Assessment Framework does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement UK NCSC Cyber Assessment Framework?
Start your UK NCSC Cyber Assessment Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK NCSC Cyber Assessment Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 41 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.
Get Started Free →Free forever — no credit card required