If you run a UK business, you need to know about the Cyber Assessment Framework (CAF). More importantly, you need to understand why it matters when choosing or evaluating your IT support provider.
CAF is changing how managed service providers (MSPs) operate in the UK. If you’re working with an IT company that hasn’t mentioned it, you may be carrying more risk than you realise. This guide explains what CAF is, what it actually tests, and how to ask the right questions of your current or prospective IT provider.
Key takeaways
- CAF is a UK government-developed framework run by the National Cyber Security Centre (NCSC).
- It assesses whether organisations (and the IT providers serving them) have the controls to defend against modern cyber threats.
- CAF is required for IT providers serving UK government, NHS, charity sector, and increasingly the wider public sector.
- Even outside regulated sectors, CAF-aligned MSPs are dramatically better-placed to defend client environments.
- Four objectives, fourteen principles, thirty-one outcomes. The framework is structured but practical.

What CAF stands for, and what it covers
CAF is the Cyber Assessment Framework. It was developed by the NCSC (the public-facing arm of GCHQ for cyber matters) to give organisations and their service providers a consistent way to assess and improve cyber resilience.
Think of it as the professional qualification system for cybersecurity in the UK. You wouldn’t hire an unqualified accountant. You wouldn’t use an unregulated solicitor either. The government takes the same view on cyber: don’t trust sensitive data and critical operations to an MSP that hasn’t engaged with CAF principles.
The framework is structured around four high-level objectives:
- Managing security risk, governance, risk management, asset management, supply chain.
- Protecting against cyber attack, service protection, identity & access control, data security, system security, resilient networks, staff awareness.
- Detecting cyber security events, security monitoring, proactive event discovery.
- Minimising the impact of incidents, response planning, lessons learned.
Beneath these are 14 principles and 31 specific outcomes. Each outcome can be rated “Not Achieved”, “Partially Achieved” or “Achieved”, giving organisations a clear roadmap for improvement.
Who needs to comply with CAF?
CAF is mandated for:
- Operators of essential services (energy, transport, water, healthcare, digital infrastructure under NIS regulations).
- UK government departments and arm’s length bodies.
- NHS and the wider public health sector.
- Increasingly, charity sector organisations handling beneficiary data, particularly those with NCSC’s CAF for charities pilot.
- Any IT provider serving the above as part of their supply chain.
Outside those sectors, CAF isn’t legally mandated for private SMBs. However, the supply chain is moving fast. MSPs that engage with CAF are already pulling ahead in tender wins, insurance underwriting and client trust. Increasingly, CAF readiness becomes a marker of provider seriousness.
Why your IT provider being CAF-aligned matters
Your MSP holds the keys to your environment. They have admin access to your Microsoft 365 tenant, your devices, and your security tooling. Therefore, if they aren’t operating to a serious cyber standard, that’s a back door into your business waiting to be exploited.
The single biggest cyber breach pattern of 2024 wasn’t a customer being directly attacked. It was the attackers compromising the customer’s MSP and pivoting from there.
A CAF-aligned MSP is one that has, at minimum:
- Documented governance and risk management processes covering their own operations.
- Strict access controls and admin separation for their engineers.
- Logging, monitoring and incident response specifically for their tooling and access.
- Supply chain risk management covering the platforms and tools they rely on.
- Cyber awareness training for their own staff, not just yours.
Eight questions to ask your current IT provider
Whether you’re evaluating a new provider or auditing your existing one, these eight questions reveal CAF maturity faster than any sales pitch.
- “How are your engineers’ admin accounts secured?” Look for: separate admin accounts, MFA on every one, just-in-time elevation.
- “What happens to your access to my tenant when an engineer leaves?” Look for: documented offboarding within 24 hours, audit log of all admin actions.
- “How do you log and review your access to my environment?” Look for: centralised audit logging, monthly access review.
- “What’s your incident response plan if YOU get breached?” Look for: a written plan, with notification timeline to clients.
- “Are you Cyber Essentials Plus certified?” The minimum bar.
- “Do you align to CAF or other recognised frameworks?” Look for: a clear answer, not “we’ll have to check”.
- “What’s your annual cyber awareness training programme for your own engineers?” Look for: at least quarterly, with phishing simulations.
- “Can I see your most recent risk assessment?” Mature providers will share a redacted summary.
If your provider is uncomfortable with these questions, that itself is a data point.
How CAF connects to other standards
CAF doesn’t replace other frameworks; it sits alongside them.
- Cyber Essentials / CE Plus, the technical baseline. Most CAF outcomes assume CE-level controls are already in place.
- ISO 27001, the international information security management standard. ISO is broader (covers people and process more deeply); CAF is more outcome-focused.
- NIST CSF, the US-developed equivalent. NIST CSF and CAF map closely; many providers map their controls to both.
- UK GDPR, data protection law. CAF outcomes cover most of what GDPR’s “appropriate technical measures” requires.
Frequently asked questions
Is Initial IT CAF-aligned?
Yes. Our internal controls map directly to CAF outcomes. We also run our managed-IT delivery in a way that supports clients in regulated sectors. Happy to walk through the specifics on a IT review.
Do I need to comply with CAF if I’m a private SMB?
Not legally, in most cases. But if you’re in the supply chain of any government, NHS or critical infrastructure customer, expect CAF questions on procurement. And the underlying controls just make for a more secure business regardless.
How does CAF relate to Cyber Essentials?
Cyber Essentials is the technical baseline. In contrast, CAF assumes CE-level controls are already in place. It then goes further into governance, monitoring, response and supply chain. Therefore, most organisations should achieve CE first, then look at CAF maturity.
How long does it take to get CAF-aligned?
For an organisation already running Cyber Essentials Plus and ISO 27001, getting to CAF maturity is typically 3-6 months of process work. Starting from scratch, allow 12-18 months.
Where can I read the official CAF documentation?
The NCSC publishes the full framework openly at ncsc.gov.uk/collection/caf. It’s worth bookmarking. You can dig into the specific outcomes and indicators there.
Initial IT operates internal controls aligned to the NCSC Cyber Assessment Framework. We support clients in legal, professional services, healthcare and charity sectors where CAF readiness is increasingly a procurement requirement.
