UK Cyber Assessment Framework (CAF) v3.1

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The UK Cyber Assessment Framework (CAF) v3.1 is a cybersecurity and risk management framework that helps organizations assess, manage, and improve their cyber resilience and compliance with relevant regulations. It provides structured guidance for organizations to identify strengths and address gaps in their cybersecurity posture.
Developed and published by the UK National Cyber Security Centre (NCSC), the CAF is primarily used by organizations operating critical national infrastructure, regulators, and other sectors requiring strong cyber risk management. The framework covers areas such as cybersecurity controls, operational resilience, incident response, governance, and supply chain security.
Organizations implement the UK CAF by conducting self-assessments or regulator-led reviews against defined objectives and indicators of good practice. The framework supports risk management and compliance efforts by aligning controls with industry standards and helps demonstrate robust security governance within broader security and regulatory programs.
Why it Matters
The UK Cyber Assessment Framework (CAF) v3.1 enables organizations to systematically evaluate and strengthen their cybersecurity and risk management capabilities.
Key benefits include:
- Strengthen cyber risk governance
Improve leadership oversight and establish clear accountability for safeguarding critical assets and operational processes.
- Enhance regulatory compliance
Align cyber risk management activities with industry standards and legal obligations to support compliance with national requirements.
- Promote operational resilience
Enable organizations to withstand and recover from cyber incidents by systematically addressing risk across business functions and supply chains.
- Improve incident response capabilities
Support rapid identification, reporting, and mitigation of security incidents to minimize operational impact and service disruption.
- Support informed decision-making
Provide structured, evidence-based assessments that guide investment and resource allocation for cybersecurity improvements.
How it Works
The UK Cyber Assessment Framework (CAF) v3.1 structures cybersecurity and operational resilience through a set of 14 high-level security and governance principles, grouped into four overarching objectives: Managing Security Risk, Protecting Against Cyber Attack, Detecting Cyber Security Events, and Minimizing the Impact of Incidents. Each objective is underpinned by detailed indicators of good practice and supporting guidance, allowing organizations to assess the completeness and maturity of their security management processes.
Organizations implement the UK CAF by conducting self-assessments or third-party audits against each principle and indicator, identifying gaps in security controls, risk management practices, and governance measures. Typical activities include reviewing current safeguards, mapping CAF requirements to internal policies, performing compliance monitoring, and documenting evidence of effective security operations to meet regulatory and industry expectations for resilience.
SmartSuite enables organizations to operationalize the UK CAF by leveraging built-in control libraries aligned to CAF principles, maintaining risk registers, and centralizing policy governance. The platform supports collection of assurance evidence, ongoing compliance tracking, and management of remediation actions through structured workflows. Integrated dashboards allow organizations to monitor assessment status, track risk mitigation progress, and prepare audit-ready reports for regulators or stakeholders.
Key Elements
- Governance and Risk Management
Establishes organizational leadership, risk assessment processes, and accountability for cybersecurity decision-making.
- Protective Security Controls
Defines safeguards for networks, systems, and data to prevent unauthorized access and mitigate vulnerabilities.
- Operational Resilience Measures
Describes procedures for ensuring continuity of critical services during disruptive cyber incidents.
- Incident Detection and Response
Specifies mechanisms for identifying, reporting, and managing security incidents and breaches.
- Supply Chain Security Oversight
Outlines requirements for assessing and assuring the security of external suppliers and partners.
- Continuous Improvement Processes
Details how organizations monitor cyber posture and evolve practices based on new threats or regulatory changes.
Framework Scope
The UK Cyber Assessment Framework (CAF) v3.1 is used by organizations managing critical national infrastructure, operators of essential services, and sectors requiring robust cyber risk management. It governs information systems, industrial control systems, and operational technology in contexts such as complying with national regulations, improving cyber resilience, and supporting assurance programs for operational continuity and regulatory oversight.
Framework Objectives
The UK Cyber Assessment Framework (CAF) v3.1 provides a foundation for organizations to enhance cyber resilience and regulatory compliance.
Strengthen cybersecurity risk management across critical systems and processes
Establish effective governance and oversight of cybersecurity controls
Enhance regulatory compliance within national and sector-specific requirements
Improve operational resilience to withstand and recover from cyber incidents
Safeguard data protection and reduce exposure to security threats
Demonstrate robust security governance through ongoing assessment and audit readiness
Framework in Context
The UK Cyber Assessment Framework (CAF) v3.1 is aligned with operational resilience standards and maps to frameworks such as NIST Cybersecurity Framework, ISO/IEC 27001, and CIS Critical Security Controls. Organizations typically implement CAF to meet regulatory cybersecurity requirements, strengthen operational resilience, and demonstrate assurance to sector regulators, especially in critical national infrastructure sectors.
Common Framework Mappings
The UK Cyber Assessment Framework (CAF) v3.1 is often mapped to major global standards to streamline compliance, support operational resilience, and enable organizations to meet multiple regulatory and best practice requirements efficiently.
Mapped frameworks include:
CIS Critical Security Controls
Cyber Essentials
ISO/IEC 27001
ISO/IEC 27002
ISO/IEC 27701
MITRE ATT&CK
NIST Cybersecurity Framework
NIST SP 800-53
- ClassificationCategoryOperational ResilienceDomainCybersecurityFramework FamilyOther
- Regulatory ContextTypeFrameworkLegal InstrumentFrameworkSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionUnited KingdomRegion DetailUnited KingdomPublisherNational Cyber Security Centre (NCSC)
- VersioningVersionCAF v3.1Effective DateJune 2024Issue DateFebruary 2024
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The Cyber Assessment Framework is published by the UK National Cyber Security Centre and is publicly available through official UK government resources.
How SmartSuite Supports EMEA UK CAF v3.1
Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.
CAF Outcome Mapping
Map CAF outcomes to controls, owners, and evidence sources.
Self-Assessment and Gap Tracking
Run assessments, record scores, and convert gaps into a prioritized roadmap.
Evidence and Verification Hub
Centralize proof for governance, protection, detection, response, and recovery.
Resilience Tests and Exercises
Schedule resilience tests and exercises and capture results and lessons learned.
Provider Risk, Monitoring, and Contingency Planning
Track provider risk, monitoring, and contingency planning evidence.
Leadership Reporting
Report maturity, gaps, and progress by outcome and business unit.
Related frameworks

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Cyber Essentials is a UK government-backed certification specifying basic controls to protect organizations against common cyber threats.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.
Frequently Asked Questions For UK Cyber Assessment Framework (CAF) v3.1
The UK Cyber Assessment Framework (CAF) v3.1 is used to help organizations assess, manage, and improve their cyber resilience in line with regulatory requirements. It provides a structured approach for evaluating cybersecurity controls, operational resilience, and incident response capabilities, especially for critical national infrastructure.
The UK CAF itself is not a certification, nor is it universally mandatory. However, regulators may require organizations in critical sectors to demonstrate adherence to the CAF as part of their regulatory compliance, and it is often referenced during audits or sector-specific inspections.
The CAF primarily applies to organizations operating critical infrastructure or essential services within the UK, as defined by relevant regulators. It may also be used by other organizations seeking to benchmark their cybersecurity practices or meet sector-specific compliance obligations.
The framework is structured around high-level objectives covering areas such as managing security risk, protecting systems, detecting cyber events, and minimizing the impact of cybersecurity incidents. Each objective is supported by indicators of good practice, which guide organizations in achieving consistent security outcomes.
Organizations typically implement the CAF through self-assessments or regulator-led reviews, examining their current security controls against the framework’s objectives and indicators. This process involves identifying gaps, prioritizing improvements, and ensuring that cyber risk management aligns with regulatory and business needs.
The UK CAF aligns closely with widely used cybersecurity standards, such as ISO 27001 and NIST CSF, but is adapted for the UK regulatory context and critical services. It provides a consistent, outcome-focused framework for evidence-based assessment that can complement other compliance programs.
Maintaining compliance with the CAF requires continuous monitoring, regular gap assessments, updating risk management processes, and documenting evidence of cybersecurity practices and improvements. Organizations should also be prepared for periodic regulatory reviews and demonstrate progress on remediation activities.
SmartSuite can help organizations operationalize the CAF by mapping objectives to specific cybersecurity policies and controls, managing risk assessments, tracking remediation efforts and control implementation, collecting compliance evidence, and supporting audit readiness. Its reporting capabilities enable ongoing monitoring and demonstration of compliance with the framework’s requirements.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

