Skip to main content
Image coming soon

HKMA C-RAF Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
HKMA C-RAF · Cyber Resilience Assessment Framework · Evidence & Implementation Kit
Work through the HKMA C-RAF, without decoding the framework yourself.
Every part handed to you as an adopt-ready control, from the inherent risk assessment through the maturity domains to intelligence-led testing, with the evidence an assessor examines.
Cyber-resilience-ready in a weekend, not a quarter.

Here is the honest situation. The HKMA Cyber Resilience Assessment Framework guides authorized institutions through assessing and strengthening cyber resilience: an inherent risk assessment that sets the target maturity, a maturity assessment across domains including governance, identification, protection, detection, response and recovery, situational awareness and third-party risk, and intelligence-led attack simulation testing for higher maturity levels. An institution that runs good security but cannot show its inherent risk rating, its maturity assessment against the target or its testing is exactly where institutions fall short.

This Kit removes the guesswork. It is the C-RAF written as adopt-ready controls you personalize in a weekend, with the evidence an assessor examines.

What you get, the moment you buy

18
Framework parts as adopt-ready controls. Every part, from inherent risk through the maturity domains to intelligence-led testing, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what an assessor examines, plus where institutions fall short, so you close the gap first.
1
Cyber Resilience Control Matrix, pre-built. Every part in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each part and the workbook returns your readiness as a single percentage, and exactly what to fix to reach the target maturity.

Grounded in the HKMA Cyber Resilience Assessment Framework, with the inherent risk assessment, the target maturity, the maturity domains of governance, identification, protection, detection, response and recovery, situational awareness and third-party risk, and intelligence-led testing called out. Editable Word and Excel files.

Your inherent risk sets the bar you have to clear
The C-RAF ties everything to the inherent risk assessment: it sets the target maturity you must reach across the domains, and for higher levels it requires intelligence-led attack simulation. An institution that skips the inherent risk step or never tests has no defensible maturity result. This Kit builds the inherent risk, maturity and testing controls with the evidence an assessor asks for.

What one control looks like

This is adopting the C-RAF assessment, where the framework begins. All 18 are built to this depth.

CRAF-1 Adopt the C-RAF assessment ADOPTION
Put this control in place

Adopt the HKMA Cyber Resilience Assessment Framework within [your organization name] as the basis for assessing and strengthening its cyber resilience, with senior sponsorship and a defined scope of the systems and business in scope, and document it, so that cyber resilience is assessed to a recognised framework and the institution can evidence its adoption of the C-RAF.

Framework note.

The HKMA C-RAF provides a structured assessment of cyber resilience for authorized institutions.

Evidence an assessor examines
  • Adoption of the C-RAF
  • Senior sponsorship
  • The scope of the assessment
Common finding they raise: Cyber resilience is assessed ad hoc with no recognised framework.

Why this is not another template pack

  • The evidence is the point. A maturity claim you cannot evidence will not stand. This tells you what an assessor examines and where institutions fall short, for every part of the framework.
  • Inherent risk, maturity and testing built in. The inherent risk assessment, the maturity domains and intelligence-led testing are written into the controls, the substance the C-RAF requires.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. The C-RAF aligns with your wider cyber and NIST-based program, so this work feeds your broader resilience.

Who buys this

Authorized institutions in Hong Kong and their cyber resilience, risk and compliance leads. Whether it is a first C-RAF assessment or a re-assessment, you save weeks and walk in with the inherent risk, maturity domains and testing structured.

By the end of the weekend you will have
✓  An adopt-ready control for the whole framework
✓  A completed cyber resilience control matrix
✓  The evidence an assessor examines
✓  Your inherent risk and maturity approach in place
✓  A readiness percentage and a fix list
✓  The detection, response and testing gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is this an official C-RAF assessment? No. It is an implementation toolkit grounded in the framework. It gets your controls and evidence in order fast so the assessment goes smoothly.

Does it cover the inherent risk assessment? Yes. The inherent risk assessment and setting the target maturity are built as controls.

Does it cover intelligence-led testing? Yes. Intelligence-led cyber attack simulation testing is built as a control for higher maturity levels.

What if it is not for me? A 30-day money-back guarantee.

Do not claim a maturity level you cannot evidence.
Every part of the C-RAF is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be cyber-resilience-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com