Compliance & Regulations/United Kingdom/NCSC CAF
Critical Infrastructure · United Kingdom — essential services, NIS Regulations, public sector

NCSC Cyber Assessment Framework (CAF)

The UK NCSC's national cyber baseline for operators of essential services and the public sector.

Regulator
UK National Cyber Security Centre
Jurisdiction
United Kingdom — essential services, NIS Regulations, public sector
Status
Active — CAF v3.2.
In force since
Active
Regulator's source
Who it applies to

Operators of Essential Services under the UK NIS Regulations 2018, central government, and many public-sector buyers.

Audit / certification status

Continuous evidence pipeline available; audit support included for all customers.

What it requires

What NCSC CAF actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

Four objectives (A–D), 14 principles, and 39 contributing outcomes.

02

Indicators of Good Practice (IGP) used as evidence anchors.

03

Self-assessment moderated by sector regulator or NCSC.

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

CAF-aligned control narrative for each of the 39 contributing outcomes.

IGP evidence binding to telemetry where automated, with manual attestation where required.

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

CAF self-assessment data pack.

Per-principle evidence with IGP traceability.

Ready for NCSC CAF?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing