ncsc caf 4.0 is the National Cyber Security Centre's Cyber Assessment Framework, published in August 2025 (NCSC, 2025). The CAF changelog records that version 4.0 replaces CAF v3.2 and lists the formal record of changes (NCSC changelog, 2025). The update raises evidence expectations for cloud, secure software supply and Artificial Intelligence (AI), aligning with concerns set out in ENISA's Threat Landscape (ENISA, 2025) and recent IBM analysis of AI-related incidents (IBM, 2025).
- What changed: CAF v4.0 replaces CAF v3.2 and updates evidence expectations on cloud, secure software supply and AI (NCSC, 2025).
- Who is affected: UK essential service operators, central government departments and their suppliers should expect broader evidence requests around software supply and AI controls (NCSC changelog, 2025).
- Context to watch: ENISA's Threat Landscape and IBM's reporting flag growing AI-related risks that increase scrutiny of build, dependency and access controls (ENISA, 2025, IBM, 2025).
- Immediate action: Read the CAF v4.0 PDF and map your existing Indicators of Good Practice against the updated cloud, DevOps and AI evidence requests (NCSC, 2025).
What is the NCSC Cyber Assessment Framework version 4.0?
The Cyber Assessment Framework version 4.0 is the National Cyber Security Centre's UK assurance framework published on 6 August 2025, replacing CAF v3.2 and updating objectives, principles and Indicators of Good Practice.
CAF v4.0 formalises outcomes and Indicators of Good Practice for cloud, DevOps and AI; UK essential service operators, critical infrastructure owners and many government bodies will use it for assurance.
Core structure and changes
CAF v4.0 retains the CAF’s four high-level objectives and 14 principles while revising the contributing outcomes and Indicators of Good Practice to reflect cloud adoption, DevOps pipelines and AI-related risks. The National Cyber Security Centre publishes the full framework PDF with the full text and scope (NCSC, Cyber Assessment Framework 4) and maintains a changelog that records the move from v3.2 to v4.0 (NCSC, CAF changelog).
Who uses CAF v4.0 and how to treat it
In the UK, operators of essential services under the Network and Information Systems Regulations (NIS Regulations), owners of critical national infrastructure, central government departments and arms length bodies use CAF v4.0 for assurance and audit. The National Cyber Security Centre does not make CAF a mandatory supplier tender requirement, but many procurers and assurance teams map supplier controls to the CAF during procurement benchmarking and internal audit.
Organisations preparing for CAF assessment should map policies, technical controls and evidence to the updated Indicators of Good Practice, then prioritise gaps affecting availability, integrity or confidentiality. The emphasis on AI and automation in CAF v4.0 aligns with ENISA's findings on shifting threats (ENISA, Threat Landscape 2025) and with IBM's 2025 analysis of AI's role in breach detection (IBM, 2025 UK Cost of a Data Breach), so include AI controls and model access governance in your mapping to ncsc caf 4.0.
Practical next steps: download the official CAF v4.0 PDF, compare the NCSC changelog to your current assurance mapping, and run a targeted gap analysis against the most relevant CAF principles. Treat the phrase ncsc caf 4.0 as a normative reference when presenting evidence to auditors or boards.
What changed between CAF v3.2 (April 2024) and CAF v4.0 (August 2025)?
CAF v4.0, published in August 2025, reworks the CAF outcome structure from v3.2 and adds clearer expectations on attacker methods, secure software development, monitoring and threat hunting, plus explicit AI governance and new Indicators of Good Practice (National Cyber Security Centre (NCSC), Cyber Assessment Framework 4).
At CyPro, we see this as a structural change rather than a wholesale new regime: outcome mapping in the NCSC changelog lets teams trace where v3.2 requirements moved or merged, which keeps evidence migration manageable (National Cyber Security Centre (NCSC), CAF changelog).
Side-by-side changes: quick comparison
| Dimension | CAF v3.2 (April 2024) | CAF v4.0 (August 2025) |
|---|---|---|
| Structure | Outcomes organised around people, process, technology evidence | Reordered outcomes with cross-cutting Indicators of Good Practice |
| Software security | High-level requirements for secure build and patching | Explicit artefacts requested, such as CI/CD build outputs and dependency scans |
| Monitoring and detection | Expectations for logging and incident detection | Greater emphasis on proactive threat hunting and longer retention for key logs |
| AI and automation | Implicit controls under change management | Explicit AI governance, model access controls and evidence of model testing |
Practical implications for UK organisations follow directly from those changes. The NCSC changelog lets you map evidence items from v3.2 to the new v4.0 outcomes, which reduces duplication when preparing assessment packs (National Cyber Security Centre (NCSC), CAF changelog).
Expect assessors to request more artefacts that prove how controls operate in practice: example items include threat-hunt playbooks, CI/CD build artefacts, dependency scan results, log retention policies and AI model access lists. The Information Commissioner’s Office (ICO) Data Security Incident Trends dataset remains a useful comparator when mapping confidentiality and reporting controls to CAF outcomes (Information Commissioner’s Office (ICO), Data security incident trends).
How teams should act now: run a targeted mapping exercise from v3.2 evidence to the v4.0 outcomes in the NCSC changelog; prioritise producing software artefacts and monitoring evidence that assessors can verify quickly; and document any AI use with access controls and governance notes so those items are ready for requests.
How does CAF v4.0 work in practice?
CAF v4.0 is an outcome-based assessment model: assessors map evidence to contributing outcomes and Indicators of Good Practice (IGPs), then judge control effectiveness against the four objectives and 14 principles defined by the National Cyber Security Centre (NCSC).
Outcome-based model
The NCSC Cyber Assessment Framework (CAF) v4.0 focuses on what controls must achieve, not which specific products to buy. The assessor looks for evidence that a contributing outcome is met, using the IGPs as concrete examples of acceptable practice. This shifts conversations from checklists to demonstrable results, so logs, playbooks and build artefacts must show the outcome, not just the control name.
How assessments map evidence
Assessors map submitted artefacts to contributing outcomes, then rate whether the IGPs show the outcome is delivered consistently. The mapping expects traceability: evidence should link a requirement (for example secure build) to an artefact (a build pipeline configuration) and to the operating evidence (build logs, dependency-scan results). For organisations using AI or CI/CD pipelines, assessors will seek model access controls and secure-build artefacts as part of the evidence set.
What assessors ask and produce
Assessors produce a judgement that a contributing outcome is met, partially met or not met, and they record gaps against the IGPs. The NCSC intends CAF v4.0 to support third-party assurance and use in schemes such as GovAssure, so expect formal findings and follow-up queries. Practical assessor questions commonly probe retention settings, detection coverage and how threat-hunt playbooks were used in prior incidents.
Evidence expectations in CAF v4.0 increase the amount of operational artefacts organisations must hold. Organisations should review their evidence catalogue, map items to CAF outcomes and plan short sprints to fill missing artefacts before an external assessment. For context on broader incident patterns that inform CAF priorities, see Verizon, 2025 and market analysis from Gartner, 2025.
Who needs to use CAF v4.0 in the UK?
Operators of essential services under the NIS Regulations, owners of critical national infrastructure and central government departments or arm's-length bodies using GovAssure are the primary users of the Cyber Assessment Framework v4.0 (CAF v4.0).
Primary users
Under the NIS Regulations, organisations designated as operators of essential services must expect assessors to map controls to CAF v4.0 outcomes when asked, and many critical national infrastructure operators will be measured against the new CAF v4.0 evidence requirements.
Government departments and arm's-length bodies that participate in GovAssure will also be expected to align to CAF v4.0 as part of assurance reviews, because GovAssure uses the NCSC (National Cyber Security Centre) baseline for cyber assurance.
Where adoption is voluntary or expected
Adoption of CAF v4.0 is voluntary for most private-sector organisations, but UK regulators and sector regulators increasingly reference CAF mapping during supervisory activity and audits. For regulated firms in financial services, healthcare and transport, expect regulators to ask for CAF v4.0-aligned evidence even if formal direction is absent.
Supply chains and supplier requirements
CAF v4.0 is not a mandatory supplier tender requirement by default, so buyers should not assume every supplier must be CAF-assessed. Instead, many procurement teams now ask for CAF-aligned artefacts or mappings as a proportionate assurance step. Where suppliers host AI models or automation, expect examiners to request model access controls and development artefacts because AI-related incidents rose in 2025; IBM reported 13% of organisations had breaches affecting AI models in 2025 (IBM, 2025), which strengthens the case for CAF evidence for AI use. IBM's UK briefing also shows firms using extensive automation reduce breach cost, which is relevant when assessors review CAF v4.0 resilience artefacts (IBM, 2025).
Common UK sectors where CAF v4.0 assessments are triggered include energy, telecoms, health, transport and financial services, typically when an organisation is listed under the NIS Regulations, supports critical national infrastructure, or is subject to GovAssure reviews.
How much does a CAF v4.0 assessment cost in the UK?
At CyPro, we price CAF v4.0 assessments by scope, not by a fixed catalogue price, because evidence collection and assessor independence drive most of the cost. The National Cyber Security Centre's Cyber Assessment Framework 4.0 notes increased evidence expectations compared with earlier versions, so time spent gathering and verifying artefacts is often the principal cost driver (NCSC, 2025).
Typical UK market ranges and what moves the price
Typical market ranges in the UK vary by organisation size, number of CAF outcomes assessed, and how much evidence already exists. For a simple, single-site review targeting a limited set of outcomes, expect lower-end fees. For enterprise-wide assessments across multiple sites with remediation work, expect materially higher fees. Ask bidders to break down charges by assessor days, evidence collection days, and remediation effort. Organisations that rely on automation and mature controls tend to reduce assessment effort and downstream incident costs, a pattern reflected in IBM's 2025 findings on automation and breach costs (IBM, 2025).
What to ask for in quotes
- Written scope, listing the exact CAF outcomes and tailored success criteria.
- Number of assessor days and number of evidence items expected per outcome.
- Who will perform independent sign-off, and their accreditation or assessor status.
- Three priced scenarios: evidence review only, assessment plus report, assessment plus remediation support.
- Estimated timeline tied to evidence readiness, with milestones for evidence submission and assessor validation.
How evidence maturity affects cost
Evidence maturity is the single biggest variable. If your organisation already maps controls to artefacts and keeps a discoverable evidence catalogue, assessor time falls. If not, assessors must collect and validate artefacts, which extends timelines and increases cost. The CAF v4.0 changelog stresses traceable artefacts and measurable controls, so vendors will price the extra verification work into quotes (NCSC changelog, 2025).
Practical step: when you shortlist suppliers, give them a small evidence sample and ask for a firm day-rate and a capped fixed-price for a defined bundle of outcomes. That makes bids comparable, and separates the assessor's independent validation cost from optional remediation work.
What is the difference between CAF v4.0 and related frameworks or tools?
CAF v4.0 differs from the NIST Cybersecurity Framework, ISO 27001 and the NCSC Cloud Security Principles by being outcome-focused, requiring explicit evidence for each outcome and aimed at UK operational assurance rather than certification alone.
The Cyber Assessment Framework 4.0 (CAF v4.0) maps desired outcomes to measurable evidence, while the NIST Cybersecurity Framework (CSF) provides a voluntary, risk-based taxonomy for functions and categories and ISO 27001 is an auditable management system standard for information security. The NCSC Cloud Security Principles set cloud-specific controls rather than organisation-wide assurance.
CAF v4.0 is a UK operational assurance tool that complements ISO 27001 and NIST CSF by demanding outcome-based evidence, making it more prescriptive for regulators and buyers.
Overlap and gaps
CAF v4.0 overlaps with ISO 27001 and NIST CSF on core security goals such as asset management, access control and incident response, but CAF v4.0 asks for evidence items tied to specific outcomes rather than just policies or a management system. Organisations with ISO 27001 will find many control topics familiar, however CAF v4.0 increases the labour of evidence collection because assessors look for artefacts mapped to outcomes.
Where MITRE ATT&CK, CVE and Cyber Essentials fit
MITRE ATT&CK and the Common Vulnerabilities and Exposures (CVE) list remain operational threat and vulnerability resources that feed evidence into CAF v4.0 assessments, for example through detection metrics and patching records. Cyber Essentials is a minimum baseline technical certification that can supply specific evidence for a subset of CAF v4.0 outcomes, but Cyber Essentials alone rarely satisfies the broader evidence catalogue CAF v4.0 expects.
Practical mapping and tooling advice
Map CAF v4.0 outcomes to specific artefacts: logs, configuration snapshots, process tickets and test reports. Use threat intelligence feeds and MITRE ATT&CK telemetry to justify detection capability, and reference CVE IDs to prove patch prioritisation. For automation benefits and detection speed, note that IBM found AI and automation materially affect breach outcomes in 2025, which matters when you justify CAF v4.0 detection evidence (IBM Report, 2025).
For change history and the CAF v4.0 release details consult the NCSC changelog and CAF documentation to see which outcomes moved or tightened evidence requirements (NCSC changelog).
What this means for you is straightforward: use ISO 27001 for your management system, use NIST CSF to structure risk conversations, and use CAF v4.0 when a UK regulator, buyer or internal assurance programme demands outcome-based evidence. Implementing one does not replace the others, but expect extra evidence work when adopting ncsc caf 4.0.
When should your organisation adopt CAF v4.0 and how do you choose an assessor?
Adopt the Cyber Assessment Framework version 4.0 when you operate essential services, are preparing for GovAssure, or when a UK regulator requests CAF evidence. For smaller organisations, adopt when you need formal evidence for supply chain or insurance requirements.
Decision rules
Choose a CAF assessment now if your organisation is an operator of essential services under UK regulation, if the Financial Conduct Authority (FCA) or Information Commissioner's Office (ICO) asks for mapped outcomes, or if you are bidding for regulated contracts that require GovAssure readiness. The ncsc caf 4.0 changelog shows updated evidence expectations, so late-stage adopters face more work collecting logs and configuration artefacts (NCSC, Cyber Assessment Framework 4). Using the ncsc caf 4.0 approach early reduces rework when auditors ask for traceable artefacts.
Practical next steps
First, define scope: pick the CAF outcomes and the systems to be assessed. Second, run an evidence gap analysis and catalogue artefacts (logs, patch records, IAM policies). Third, shortlist assessors and request fixed-scope pricing and a sample evidence checklist. Fourth, schedule the assessment and reserve time for evidence remediation.
How to choose an assessor
Pick an assessor with demonstrable UK sector experience, clear evidence-handling procedures, and transparent fixed-scope pricing. Confirm the assessor understands how ncsc caf 4.0 maps to ISO 27001 and can provide a sample evidence checklist tied to CAF outcomes. Ask for references in your sector, and check whether the assessor will handle sensitive logs under a proper data processing agreement with secure transfer methods. If you need gubernatorial assurance for public contracts, confirm the assessor’s GovAssure experience.
Finally, budget for evidence remediation: expect assessor time plus internal staff hours for artefact collation, especially where AI or automation generated logs must be proven, a point highlighted in industry incident studies (IBM, 2025), and in breach trend analysis (Verizon, 2025).
Frequently asked questions
Does CAF v4.0 replace ISO 27001 or NIST for my organisation?
Key fact: CAF v4.0 is an assessment framework focused on outcomes for essential services, not a replacement for ISO 27001 or NIST. ISO 27001 remains a management system standard, NIST provides control-level guidance, and many organisations map ISO 27001 or NIST controls to CAF outcomes for regulator-facing assurance and certification needs.
Is CAF v4.0 mandatory for all UK organisations?
Key fact: CAF v4.0 is not mandatory for all UK organisations; it is aimed at operators of essential services under the NIS Regulations, critical national infrastructure and bodies assessed via GovAssure. Other organisations may use CAF voluntarily to improve cyber defences, but being out of scope does not remove obligations under UK GDPR or sector regulators such as the FCA or ICO.
How long does a CAF assessment typically take to complete?
Key fact: Assessment duration varies widely, from a few weeks for narrowly scoped reviews to several months for large cross-sector programmes. Time depends on evidence readiness, systems in scope, and stakeholder availability. Ask assessors for a written timeline based on your defined scope and an evidence checklist to get an accurate quote.
Can an organisation prepare for CAF v4.0 without hiring an assessor?
Key fact: Organisations can self-assess against CAF v4.0 contributing outcomes and informed guidance practices to prepare evidence and prioritise gaps, but independent assessment is required for GovAssure and regulator assurance. At CyPro, we help scope self-assessments and compile evidence while an accredited partner performs the formal, independent judgement.
What new evidence will assessors ask for under CAF v4.0 due to AI coverage?
Key fact: Assessors will request AI-specific evidence, including AI risk governance, model inventories, model provenance, data handling controls, testing results, monitoring outputs and supplier assurances for third-party models. Organisations should map AI systems to CAF contributing outcomes and document mitigations, logging and validation before formal assessment to avoid last-minute surprises.