Here is the honest situation. The NCSC Cyber Assessment Framework sets outcomes across four objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of incidents. It is how operators of essential functions and many regulated organizations show their cyber posture. The hard part is turning fourteen outcome-based principles into concrete controls and the evidence behind them. An organization with good security that cannot map itself to the CAF outcomes is exactly where organizations fall short.
This Kit removes the guesswork. It is the CAF objectives and principles written as adopt-ready controls you personalize in a weekend, with the evidence an assessor examines.
What you get, the moment you buy
Grounded in the NCSC Cyber Assessment Framework and its four objectives, with governance and risk management, identity and access, data and system security, monitoring, detection, and response and recovery called out. Editable Word and Excel files.
What one control looks like
This is setting governance for cyber security, where Objective A begins. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. An outcome you cannot evidence is not achieved. This tells you what an assessor examines and where organizations fall short, for every CAF outcome.
- All four objectives built in. Managing risk, protecting, detecting and minimising impact are written into the controls, the substance the CAF expects.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. The CAF sits on your wider security program, so this work feeds your NIS and regulator reporting and your governance.
Who buys this
Operators of essential functions, regulated organizations and their security and risk leads. Whether it is a first CAF self-assessment or a readiness pass, you save weeks and walk in with the four objectives structured and evidenced.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this an official NCSC tool? No. It is an independent implementation toolkit grounded in the published CAF objectives and principles, to get your controls and evidence in order fast.
Does it cover all four objectives? Yes. Managing security risk, protecting against attack, detecting events and minimising impact are all built as controls.
Does it help me self-assess? Yes. The Gap and Readiness assessment scores you against the outcomes and ranks the fixes.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com