Skip to main content
Image coming soon

UK NCSC CAF Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
UK NCSC CAF · Cyber Assessment Framework · Evidence & Implementation Kit
Meet the NCSC Cyber Assessment Framework, without decoding the outcomes yourself.
Every CAF objective handed to you as an adopt-ready control, from managing security risk and protecting against attack through detecting events to minimising impact, with the evidence an assessor examines.
Assessed against the CAF in a weekend, not a quarter.

Here is the honest situation. The NCSC Cyber Assessment Framework sets outcomes across four objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of incidents. It is how operators of essential functions and many regulated organizations show their cyber posture. The hard part is turning fourteen outcome-based principles into concrete controls and the evidence behind them. An organization with good security that cannot map itself to the CAF outcomes is exactly where organizations fall short.

This Kit removes the guesswork. It is the CAF objectives and principles written as adopt-ready controls you personalize in a weekend, with the evidence an assessor examines.

What you get, the moment you buy

18
Objectives as adopt-ready controls. Every CAF objective, from managing risk and protection through detection to minimising impact, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what an assessor examines, plus where organizations fall short, so you close the gap first.
1
CAF Control Matrix, pre-built. Every outcome in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each outcome and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the NCSC Cyber Assessment Framework and its four objectives, with governance and risk management, identity and access, data and system security, monitoring, detection, and response and recovery called out. Editable Word and Excel files.

The CAF is outcome-based, so evidence is everything
The CAF does not hand you a checklist, it asks whether you achieve security outcomes. That is harder to answer without concrete controls and the evidence behind them. This Kit turns the four objectives into controls with the evidence an assessor asks for, so you can show the outcome, not just claim it.

What one control looks like

This is setting governance for cyber security, where Objective A begins. All 18 are built to this depth.

CAF-A1 Set governance for cyber security OBJECTIVE A
Put this control in place

Establish governance at [your organization name] for the security of its networks and information systems, with board-level ownership, defined roles and resourced decision-making, and document it, so security is directed and the organization can evidence its governance against the Cyber Assessment Framework.

Framework note.

CAF Objective A expects appropriate organizational structures, policies and processes to govern security risk.

Evidence an assessor examines
  • Cyber security governance and roles
  • Board-level ownership
  • Records of the arrangements
Common finding they raise: There is no clear governance for the security of essential systems.

Why this is not another template pack

  • The evidence is the point. An outcome you cannot evidence is not achieved. This tells you what an assessor examines and where organizations fall short, for every CAF outcome.
  • All four objectives built in. Managing risk, protecting, detecting and minimising impact are written into the controls, the substance the CAF expects.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. The CAF sits on your wider security program, so this work feeds your NIS and regulator reporting and your governance.

Who buys this

Operators of essential functions, regulated organizations and their security and risk leads. Whether it is a first CAF self-assessment or a readiness pass, you save weeks and walk in with the four objectives structured and evidenced.

By the end of the weekend you will have
✓  An adopt-ready control for all 18 outcomes
✓  A completed CAF control matrix
✓  The evidence an assessor examines
✓  Your risk, protection and detection in place
✓  A readiness percentage and a fix list
✓  The response and recovery gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is this an official NCSC tool? No. It is an independent implementation toolkit grounded in the published CAF objectives and principles, to get your controls and evidence in order fast.

Does it cover all four objectives? Yes. Managing security risk, protecting against attack, detecting events and minimising impact are all built as controls.

Does it help me self-assess? Yes. The Gap and Readiness assessment scores you against the outcomes and ranks the fixes.

What if it is not for me? A 30-day money-back guarantee.

Do not face a CAF assessment with outcomes you cannot show.
Every CAF outcome is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be CAF-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com