Cyber assessment Framework

NCSC-ASSURED
CAF EXPERTS

Assessing cyber risk across organisations that play a vital role in the daily life of the UK is essential.

This is why the Cyber Assessment Framework (CAF) was developed. The CAF is a collection of cybersecurity guidance designed to help organisations achieve and demonstrate an appropriate level of cyber resilience in essential functions.

The CAF is outcome-based, focusing on results rather than prescribing solutions. It evaluates each system using a baseline or enhanced profile, depending on the perceived threat level.

Our risk experts can assist organisations with their CAF assessments and also help train companies conducting these assessments.

Driving CAF Technical Development

Our team of risk specialists provided in-depth technical analysis to help shape the NCSC’s Cyber Assessment Framework during its development.

Creating CAF Profiles

Our experts worked to construct a robust empirical model for generating the CAF profiles.

Empowering CAF Assessors

We designed and delivered tailored, hands-on training programs for independent assurance firms performing CAF assessments.

Why choose
2T Security

2T Security’s risk experts helped create the GovAssure process, writing the CAF profiles which direct organisations on the level they are expected to be working towards achieving.

Our services encompass advisory to CNI and central government clients.

CAF Advisory

Enhance your organisation’s understanding and application of the Cyber Assessment Framework (CAF), driving tangible improvements to your security posture.

CNI

Strengthen your Critical National Infrastructure (CNI) with our comprehensive client review against the CAF. Identify gaps, reinforce defences, and protect vital operations.

 

Training

Empower your assessors and risk teams with specialised training. Refine assessment accuracy, strengthen risk management, and build a more resilient organisation.

BUILT ON REAL-WORLD RISK MANAGEMENT

When it comes to risk assessment and delivering the CAF, 2T Security has your back. We offer comprehensive, cost-effective, and expert risk advisory services.

We can operate as trusted advisors to your team or take on the assessment on your behalf, meeting compliance and maintaining the integrity of your organisation.

Get in touch to learn more about our approach to risk and how we can help you.

CAF chord diagram

CAF Chord diagram

This diagram shows the dependencies between the 39 Contributing Outcomes defined in the Cyber Assessment Framework created by the NCSC.

To simplify the diagram, it is assumed that Risk Management (A2.a), Asset Management (A3.a), and Cyber Security Training (B6.b) are already in place, and hence not all links are shown back to these.

Thanks to the Government Security Group, National Cyber Security Centre, and Cyber GSeC Team for the work that we did in compiling the data for this diagram.

PROCURE OUR SERVICES

Get In Touch

You can access our GovAssure services through the Crown Commercial Services Dynamic Purchasing System, under the Cyber Security Supplier 3 framework.