Insights · 28 July 2026

The 5 stages of GovAssure, explained

GovAssure stages describe five formal steps to assure UK government systems; implement Stage 1 to Stage 5 and reduce duplicated evidence in 2026. You get a clear roadmap.

GovAssure stages are five formal, repeatable steps UK departments use to assure government systems: Stage 1 Define your organisation's context and services; Stage 2 Identify in‑scope systems and assign Cyber Assessment Framework (CAF) profiles; Stage 3 Complete a WebCAF self‑assessment; Stage 4 Independent Assurance Review producing a Peer Review Report; Stage 5 Create a Targeted Improvement Plan (TIP) agreed with the Government Security Group (GSG). The GovAssure programme maps to the NCSC Cyber Assessment Framework version 4 (NCSC, 2025), the ENISA Threat Landscape analysed 4,875 incidents in 2025 (ENISA, 2025), and the 2025 Data Breach Investigations Report reviewed 22,052 incidents and 12,195 confirmed breaches (Verizon, 2025). Official GovAssure guidance is hosted on the UK Government Security site (GovAssure and GovAssure guidance hub).

  • What: GovAssure stages are five formal steps for assuring UK government systems, from scoping to a Targeted Improvement Plan agreed with the Government Security Group.
  • Why: GovAssure aligns to the NCSC Cyber Assessment Framework v4 (NCSC, 2025) to reduce duplicated evidence collection.
  • Context: Official material and step‑by‑step guidance are on the UK Government Security pages (GovAssure, GovAssure guidance hub).
  • Risk signal: Recent reports show high incident volumes: ENISA logged 4,875 incidents in 2025 (ENISA, 2025) and Verizon reviewed 22,052 incidents in 2025 (Verizon, 2025), underlining the need for repeatable assurance.

What is GovAssure and who runs it?

What are the five stages of GovAssure?

The five GovAssure stages are Initiation, Pre-assessment, Assessment, Reporting and Remediation, and Assurance closure.

Initiation

Initiation sets scope, governance, acceptance criteria and accountable owners so the assurance effort has clear boundaries and decision rights. The UK Government's GovAssure guidance explains the need to classify the system, name sponsors and establish evidence requirements before evidence collection begins (GovAssure guidance - UK Government Security).

Pre-assessment

Pre-assessment builds an evidence map and aligns existing controls to objectives so the formal Assessment focuses on remaining gaps. The National Cyber Security Centre's Cyber Assessment Framework (CAF) is the reference used to map controls during this phase, helping teams identify which CAF objectives already have demonstrable coverage (NCSC Cyber Assessment Framework collection).

Assessment

Assessment is the structured evaluation of mapped evidence against CAF objectives, producing verified findings and a statement of residual risk. The GovAssure guidance expects assessors to validate evidence, interview responsible staff and run targeted technical checks; assessment may be carried out by approved scheme partners, independent assessors, or suitably qualified internal teams where GovAssure permits and governance requires independence to be demonstrated (GovAssure guidance - UK Government Security, NCSC Cyber Assessment Framework collection).

Reporting and Remediation

Reporting and Remediation turns findings into a prioritised action plan with named owners, deadlines and verification steps so issues are tracked to closure. This stage requires evidence of validation for fixed items and clear linkage back to CAF objectives so decision makers can see residual risk reducing over time (NCSC Cyber Assessment Framework collection).

Assurance closure

Assurance closure records formal sign-off when agreed remediation meets the required CAF objectives and acceptance criteria. The GovAssure model encourages reuse of assurance artefacts for procurement and peer review, which reduces duplicated evidence collection across government programmes (GovAssure - UK Government Security).

At CyPro, we treat the five stages as a project plan: set clear owners at Initiation, invest effort in Pre-assessment to avoid rework, insist on mapped CAF objectives during Assessment, and require verification steps in Reporting and Remediation to speed Assurance closure.

The 5 stages of GovAssure, explained - supporting illustration

Stage 1: Define your organisation's context and services

Stage 1 should map services, stakeholders and data flows to business outcomes, producing a scoped inventory and testable boundaries that the assurance team will use throughout the GovAssure stages.

Purpose and outcome

The purpose is a measurable scope: a service catalogue, stakeholder list, data flow diagrams and a clear statement of what success looks like for the assurance activity. Mapping these outputs makes the later assessment efficient and repeatable, and ensures assumptions are visible to officials and auditors.

Inputs required

Inputs include service owners, system owners, the service catalogue, network and hosting details, supplier lists, high level architecture and any existing accreditation evidence. Departments should provide business impact levels, compliance drivers such as the Cyber Assessment Framework (CAF) and UK GDPR, and details of any mission-essential services. The ENISA Threat Landscape 2025 is useful context for threat assumptions used during scoping, and the Information Commissioner's Office Data security incident trends dataset helps departments judge likely incident types and evidence needs.

Practical tasks and partner-delivered engagement

Practically, tasks are: run workshops to confirm service boundaries, produce data-flow diagrams, record supplier touchpoints and confirm evidence sources. A partner-delivered engagement will typically add interview templates, evidence checklists and a draft statement of scope for executive sign-off. Where organisations reuse these artefacts across the GovAssure stages, they reduce duplication and speed up subsequent assurance activities.

Implication for later stages

A tight Stage 1 scope reduces rework in Pre-assessment and Assessment, shortens testing time and clarifies remediation responsibility. Clear Stage 1 outputs also make assurance findings easier to translate into formal remediation plans and accreditation evidence later in the GovAssure stages.

Stage 2: Identify in-scope systems and assign Government CAF profiles

Stage 2 identifies which systems are in scope and assigns either a Baseline or Enhanced Government Cyber Assessment Framework (CAF) profile, chosen on impact to services, sensitivity of data and exposure to threat actors.

Key Takeaway

A precise inventory and a justified Baseline or Enhanced CAF profile cut testing time, direct remediation effort and determine how deep Stage 4 assurance must go.

Profile types

Baseline profiles cover lower‑impact systems and focus on core CAF outcomes such as access control and patching, while Enhanced profiles require deeper evidence across governance, supply chain and incident response. The NCSC updated the Cyber Assessment Framework to reflect growing threats, which informs profile selection (NCSC, 2025).

Step-by-step tasks

Begin with a validated inventory of services, endpoints and data flows within the boundary defined in Stage 1. Next, map each asset to a service impact statement and classify data sensitivity. For each service, assign a CAF profile with written rationale, then record exclusions and compensating controls. Practical outputs here are a scoped inventory, a profile register and a test plan for Stage 3. Organisations following the govassure stages often find this step reduces duplicate testing later because the assessment scope is stable and repeatable.

Why profile choice matters

Profile choice determines assessment depth and the assurance evidence required in Stage 4: Enhanced profiles trigger deeper control testing, external supplier checks and forensic readiness evidence, while Baseline profiles accept lighter sampling and documentary proof. The 2025 Data Breach Investigations Report shows large numbers of incidents in complex estates, underscoring why careful scoping at Stage 2 matters (Verizon, 2025).

Assigning profiles defensibly also helps procurement and supplier assurance, because a documented CAF profile aligns expectations for third‑party testing. Following the govassure stages means procurement teams can reuse the Stage 2 outputs during contracts and accreditation, avoiding repeated evidence requests and speeding assurance closure.

Stage 3: Complete your self-assessment using WebCAF

Complete your WebCAF self-assessment by mapping each Cyber Assessment Framework outcome to recorded evidence, declaring the achieved level in WebCAF and saving testable artefacts for future assurance checks.

What to record in WebCAF?

Record clear evidence items for each CAF (Cyber Assessment Framework) outcome: policies, configuration screenshots, logs, design diagrams, test results and supplier attestations. Each evidence item should state scope, date, owner and how it demonstrates the CAF outcome. The WebCAF entry should let an independent assessor reproduce your judgement without additional questions. In our experience, treating the govassure stages as an evidence road map reduces later remediation cycles and speeds assessment closure.

Practical evidence examples include architecture diagrams that show trusted boundaries, MFA (Multi-Factor Authentication) configuration exports, vulnerability scan summaries, and minutes from supplier security review meetings. Where controls rely on supplier activity, embed third-party certificates or service evidence so the WebCAF record is self-contained.

Practical tips for central government teams and partner support

Gather evidence incrementally rather than waiting for a big collection push at the end of the programme. Assign a single evidence owner per CAF outcome to prevent gaps when systems or staff change. Use a consistent naming convention in WebCAF so assessors can find artefacts quickly.

Coordinate with procurement and your suppliers early so evidence such as penetration test reports and SLAs are ready during the govassure stages rather than requested mid-assessment. For complex services, create a short evidence index document that explains how each artefact maps to the CAF outcomes to save assessor time.

Expect independent assurance to probe your WebCAF entries: examiners will test that artefacts are genuine and recent, and that declared levels match practice. If you need a refresher on CAF expectations, consult the NCSC guidance and use external threat reporting to prioritise which controls need stronger evidence, for example the IBM threat index or Mandiant trend summaries for 2025.

Stage 4: Independent Assurance Review and the Peer Review Report

Stage 4 is an independent assurance review that validates evidence, tests declared Cyber Assessment Framework (CAF) profiles and produces a Peer Review Report used by the Government Security Group (GSG).

Who performs the review?

Independent assurance is carried out by accredited reviewers who are separate from any supplier who delivered earlier stages, and they verify that artefacts and operation match the declared CAF profile. The NCSC maintains scheme partners lists and guidance for reviewers, which shows the approved roles and competence needed for these assessments, and organisations should expect examiners to request live demonstrations as well as documents (NCSC scheme partners).

What the Peer Review Report contains

The Peer Review Report summarises findings, states whether the CAF profile is supported by evidence, and highlights gaps and mandatory actions for closure. The report records scope, the review methods used, where controls meet the declared level, and where corrective actions are required. In practice, the Peer Review Report becomes the artefact that the Government Security Group (GSG) uses to accept or escalate assurance outcomes under the govassure stages sequence.

How this differs from ISO 27001 audits and supplier checks

Stage 4 independent assurance focuses on CAF control levels and operational reality rather than a management system certification. ISO/IEC 27001 audits assess an information security management system against ISO/IEC 27001, while supplier security checks typically verify contractual controls. The govassure stages independent assurance therefore probes live effectiveness and conformity to CAF, not merely policy existence.

For UK organisations preparing for Stage 4, the implication is clear: keep artefacts current, preserve audit trails and be ready to demonstrate live processes. External threat reporting and sector incident trends should inform which controls reviewers scrutinise most closely, because reviewers prioritise evidence where risk and impact are highest (ENISA Threat Landscape 2025). Reviewers will also compare supplier-delivered artefacts against independent logs and live evidence, so maintain original system logs and change records to speed closure (Verizon 2025 DBIR).

Keeping evidence current shortens the assurance loop, reduces rework in later govassure stages and helps the Government Security Group accept outcomes faster.

The 5 stages of GovAssure, explained - supporting illustration

Stage 5: Create a Targeted Improvement Plan (TIP) agreed with GSG

The TIP is a documented set of remedial actions, owners, timescales and acceptance criteria that the Government Security Group (GSG) must agree before re-assessment. The TIP turns reviewer findings into a tracked delivery plan for the system owner and suppliers.

Key Takeaway

A TIP makes GovAssure stages actionable: it maps each Peer Review finding to who fixes it, by when, and how success will be measured ahead of any re-assessment with the GSG.

What the TIP contains

The TIP must list each finding, the risk that the finding addresses, a named owner, a clear remedial action, target completion dates and measurable acceptance criteria. The TIP should also record relevant dependencies such as supplier work, configuration changes and evidence sources for re-assessment. In our experience a TIP that lacks measurable acceptance criteria delays re-assessment and increases time under review, so be precise about the artefacts you will present.

Agreeing the TIP with the GSG

The Government Security Group (GSG) will review the TIP to confirm the planned actions address the Peer Review report and that timescales are realistic given the risk profile. Expect iterative feedback: the GSG may require tighter acceptance criteria, additional evidence, or shorter deadlines for high‑risk findings. The TIP only becomes the formal remediation baseline once the GSG signs off, and any later scope changes should be managed through a documented update to the TIP.

Practical choices: in-house remediation or partner support

Departments must choose whether to deliver TIP tasks in-house or use partners for specific workstreams such as patching, secure configuration, identity and access management, or supplier assurance. Use external threat research and incident trends to prioritise actions inside the TIP, for example ENISA's threat analysis or large incident datasets to justify earlier fixes. ENISA Threat Landscape 2025 provides UK and EU sector trends that help set which findings need urgent remediation. Similarly, the scale of breaches in broad industry studies can help argue for external resource; for example the 2025 DBIR data shows the prevalence of supply chain and credential attacks that often drive TIP priorities. Verizon 2025 DBIR

How the TIP affects re-assessment and longer term planning

The TIP creates a clear route to re-assessment: once agreed actions are complete and evidence aligns with the acceptance criteria, the system owner requests re-assessment with the GSG. The TIP should also feed into longer term security planning, because repeat findings expose capability gaps that need investment, not one-off fixes. Including measurable acceptance criteria in the TIP reduces rework, shortens the timespan across the govassure stages and makes the final assurance pass more predictable.

How should a department choose and engage a partner for GovAssure?

Choose a partner by matching the partner's scope to the specific govassure stages you are at, your in-house capability, and whether you need assessor-led remediation or only peer review.

The UK Government Security GovAssure guidance - UK Government Security sets the scheme and shows how assessors must align to the National Cyber Security Centre's (NCSC) Cyber Assessment Framework (CAF), so require partners to map deliverables to CAF controls early in procurement.

Decision checkpoints

  • Evidence scope, mapped to CAF controls: ask for an artefact list per govassure stages milestone.
  • Assessor credentials and Peer Review experience: request named assessors and past GovAssure or CAF work.
  • Remediation model: fixed-price remediation, time-and-materials, or advisory only, with clear boundaries on sign-off during re-assessment.
  • Data handling and evidence retention: confirm secure transfer and storage for logs and configuration records requested in Stage 4 evidence collection.

Partner types compared

Dimension Full-service partner Peer-review only partner Specialist assessor
Scope Runs assessment, remediation and re-assessment across all govassure stages Reviews evidence and provides gap analysis for specific stages Performs technical testing or ITHC for Stage 4
Pricing model Priced project or phased retainer Fixed-scope quote for review work Daily rates or fixed-test fee
UK government experience Designed for departments with limited internal capability Best for strong in-house teams seeking external validation Needed where technical assurance or ITHC is mandated
Time to re-assessment Shorter, if partner manages fixes Depends on departmental remediation pace Fast, focused testing windows

Procurement practicalities

In the UK, align procurement to the govassure stages by asking for a two-phase bid: an initial fixed-scope assessment quote for the current govassure stages, followed by a priced remediation and re-assessment plan. The ENISA Threat Landscape 2025 gives useful context on which CAF control areas departments often prioritise when preparing Stage 3 and Stage 4 evidence.

At CyPro, we recommend written artefact maps to CAF, named assessors, and three priced engagement options: review only, remediation-managed, and full delivery. That approach shortens timelines and reduces procurement risk for departments of all sizes.

Frequently asked questions

What is GovAssure used for?

GovAssure is used to provide assurance of government IT services against the National Cyber Security Centre's Cloud Assessment Framework version 4.0 (NCSC CAF v4.0). It applies only to central government departments and arms length bodies, not to private suppliers. GovAssure is an assurance process, not a supplier certification or a procurement gate.

Who needs to run GovAssure?

Central government departments and arms length bodies must run GovAssure when required by policy or programme sponsors. Private suppliers and most wider public sector bodies are not eligible for GovAssure. Departments may engage external partners or specialist consultancies to support scoping, evidence collection and Peer Review Report preparation.

How long does a GovAssure assessment take?

Timelines vary, typically from a few weeks to several months, depending on scope, chosen profile and evidence readiness. Stage 1 scoping and Stage 3 WebCAF completion usually dominate calendar time. Allow planning buffers and use partner support to speed document collation, technical testing and Peer Review Report drafting.

Do suppliers need GovAssure certification?

Suppliers do not receive GovAssure certification. GovAssure is for central government assurance of services, not a supplier credential. Suppliers instead may need other proofs such as MOD Secure by Design compliance, an Infrastructure Testing and Health Check (ITHC) report, or evidence requested in procurement guidance.

What evidence does WebCAF require?

WebCAF commonly requires architecture diagrams, security policies, access controls, audit logs, configuration baselines and test reports such as penetration tests. Each piece of evidence maps to specific NCSC CAF controls, so organise files by control and include a short index for the Peer Review Report to speed review and reduce rework.

Rocket above the CAF Assessment call to action

Talk to us about your framework obligation

Find out what a CAF or GovAssure assessment involves for you

The scoping call is free, lasts 45 minutes and is taken by a consultant, not a salesperson. It covers which framework applies to you, the profile or stage you need to meet, and the indicative fixed-scope cost of a managed, partner-delivered assessment.