In August 2025 the NCSC released version 4.0 of the Cyber Assessment Framework, the framework nearly every UK cyber regulator now uses to assess operators of essential services, and the basis of GovAssure for government systems. If your organisation runs energy, water, transport or other critical infrastructure, this is the yardstick you will be measured against.

Most summaries of v4.0 are written for CISOs. This one is written for the people who actually have to answer the questions: OT engineers, control system leads, and the compliance managers who work with them.

The headline: 39 outcomes became 41

CAF v3.2 had 39 contributing outcomes across four objectives (A: Managing security risk, B: Protecting against cyber attack, C: Detecting cyber security events, D: Minimising the impact of incidents). Version 4.0 has 41, but the change is bigger than two extra rows, because several outcomes were restructured and the indicators of good practice were substantially expanded (over a hundred new IGPs across the framework).

Objectives B and D are structurally unchanged. The movement is all in A and C.

Change 1: you must now understand your attackers (new A2.b)

A new outcome, "Understanding Threat", asks whether you actually know who is likely to attack your essential function, what they are capable of, and what their attack would look like step by step, using documented, repeatable analysis, not gut feel.

For an OT team this means being able to answer questions like: which threat groups target electricity generation or grid operators? What would their path look like through our estate: from a phished corporate laptop, across the IT/OT boundary, to the SCADA servers or protection relays? If your answer today is a shrug or a generic risk register entry, this outcome is a gap.

(Existing outcome A2.a, the risk management process, was also updated to cover risks from newer technologies, including AI and automated decision-making systems. And the old A2.b "Assurance" still exists, it has simply moved to A2.c.)

Change 2: software now has its own outcome (new A4.b)

"Secure Software Development and Support" is new, sitting alongside supply chain security. It covers secure-by-design development, patching and ongoing support, and integrity across the software supply chain, whether the software is written in-house or bought.

In OT terms: your SCADA packages, HMI applications, historians, and the firmware in your IEDs are all "software supporting your essential function." Can you show they are supported, patchable (or compensated where patching isn't possible), and that you would notice if their integrity were compromised? Vendor contracts that are silent on security support are exactly what this outcome exposes.

Change 3: detection grew teeth, with Threat Hunting (C2 rebuilt)

The old Objective C2, "proactive security event discovery", with its two outcomes about spotting system abnormalities, has been replaced by a single, more demanding outcome: Threat Hunting. The expectation is that your monitoring team can proactively hunt for adverse activity that has evaded your automated detection, using documented methods (hypothesis-driven, data-driven or anomaly-based), at a frequency that matches your risk, and that hunt findings feed back into improved automated detections.

For most OT operators this is the hardest new ask. Passive monitoring of the OT network was already a stretch for many; structured hunting across it is a genuine capability step. Note the framework's own realism, though: doing hunts occasionally, for example in response to a government tip-off, earns "partially achieved". It doesn't demand a 24/7 hunt team on day one.

A related new outcome, C1.f, asks whether you understand normal user and system behaviour and integrate threat intelligence into monitoring, the foundation that makes hunting possible at all.

Why this matters on a deadline

Two clocks are ticking for UK operators.

Clock one: Ofgem. Energy operators have been directed to work towards the CAF Enhanced Profile by the end of 2027, and the Enhanced Profile is assessed against v4.0, not whichever version you last self-assessed under.

Clock two: the Cyber Security and Resilience Bill. Introduced to Parliament in late 2025, the Bill has passed the House of Commons and is before the Lords, with Royal Assent expected during 2026. Rather than replacing the NIS Regulations 2018, it extends them: wider scope, faster reporting, and much bigger penalties.

Who gets pulled into scope, and what it means on the ground:

Newly regulated Rough threshold Overseen by Why OT teams should care
Data centres ~1 MW IT load and above Ofcom If your SCADA, historians or backups sit in a colo or cloud region, your hosting provider becomes a regulated dependency, so expect security questions flowing both ways.
Managed service providers Medium and large MSPs with UK customers ICO The vendor remotely supporting your control system or network is now regulated too. Their compliance posture becomes part of your supply-chain evidence (CAF A4, NIS2 Art. 21(d)).
Large load controllers ~300 MW of controllable electrical load Sector regulator Aggregators and flexibility platforms controlling generation or demand at scale join the regulated perimeter, which is directly relevant to wind, solar and storage operators.

Two further teeth worth knowing: the Bill brings 24-hour initial incident reporting (with a fuller report at 72 hours), and tiered penalties reaching up to £17 million or 4% of worldwide turnover for the most serious failures. And scope can arrive indirectly: suppliers to an Operator of Essential Services can be designated critical suppliers and regulated regardless of their own sector.

The practical consequence stands: if your last CAF assessment was against v3.1 or v3.2, you have unexamined gaps by definition: at minimum the three new outcomes above, plus expanded expectations across the ones you already assessed, on a timeline that is no longer optional.

Where to start

You don't need a consultancy engagement to find out where you stand. A structured self-assessment against the 41 outcomes of v4.0, answered honestly by the engineers who know the estate, with evidence noted against each outcome, will show you your position, your worst sections, and the gap list your remediation plan should start from. That is exactly what XIRIQ does, for free, in an afternoon.

Sources