UK NCSC CAF v4.0

The UK NCSC Cyber Assessment Framework v4.0 is the framework UK regulators use to assess operators of essential services. XIRIQ presents it the way the CAF document does.

Objectives, principles, outcomes

The CAF has four objectives (A Managing security risk, B Protecting against cyber attack, C Detecting cyber security events, D Minimising the impact of incidents), split into 14 principles, split into 41 contributing outcomes. The contributing outcome is the unit you assess: each one is judged Achieved, Partially Achieved (where the CAF defines that level for it) or Not Achieved.

Example
The three CAF judgement levels as they appear on an outcome, plus the out-of-scope option.

How status is judged

In Quick mode you set the level yourself. In Detailed mode XIRIQ derives it from the indicators: any true Not Achieved indicator forces Not Achieved regardless of everything else; Achieved needs every applicable Achieved indicator true; Partially Achieved (where the column exists) needs every applicable Partially Achieved indicator true. Anything else is left as assessor judgement required, never silently downgraded.

What IGPs are

Indicators of good practice are the CAF's evidence statements: concrete descriptions of what Not Achieved, Partially Achieved and Achieved look like for an outcome. They are indicators, not a checklist; the NCSC is explicit that assessment is a judgement informed by them. Detailed mode puts each indicator in front of you as a true/false/not-applicable question.

Why there is no CAF score

The CAF deliberately has no scoring scheme: adding up outcomes would let strength in one area mask a serious weakness in another. XIRIQ follows that. Results are presented as the distribution of judgements and, where a target profile is set, attainment against it. Where a percentage appears it is labelled indicative and never called a compliance score.

Can't find what you need? Browse the Resources articles or use the feedback button inside the app.