Assess your CAF 4.0 compliance status

The NCSC Cyber Assessment Framework 4.0 is an outcome-based model for essential service providers to systematically assess cyber resilience, with updated coverage of attacker methods, secure software development, and AI-related risks. Take the CAF 4.0 assessment to see how your organization scores against these outcomes.

Assess your compliance in just 15 minutes
CAF 4.0
The NCSC Cyber Assessment Framework (CAF) 4.0 is an outcome-based model developed by the UK's National Cyber Security Centre (NCSC) to help organizations, particularly those providing essential services and critical national infrastructure, assess and improve their cyber resilience. It offers a systematic approach to evaluating how effectively cyber risks to essential functions are managed based on predefined Indicators of Good Practice (IGPs). The CAF is designed to help organizations define and achieve security objectives appropriate to their risks and operational context. CAF 4.0 includes updates such as a section focused on understanding attacker methods, ensuring secure software development, enhancing threat detection, and strengthening coverage of AI-related cyber risks.

Why choose the Cyberday assessment?

Comprehensive yet simple

Gain insights into your organization's compliance status towards the most popular information security frameworks worldwide, in just a few clicks.

Instant results

Receive a detailed, easy-to-understand report that highlights your strengths and areas for improvement.

Free to use

Complete the assessment and download your compliance report at no cost.

Seamless integration

Move from assessment to full-scale ISMS implementation with just one click, ensuring continuous compliance monitoring.

Step 1

Start the assessment

Choose the framework that is most relevant for you and start assessing. You'll see a suggested list of measures, which you can categorize according to your current operations.

Step 2

Get your initial report

You'll automatically see your compliance score updating and can click "Preview results" at any time to see a more detailed summary of your assessment results. This report can be printed for internal discussion about current security level.

Step 3

Transition to ISMS

Aftey your assessment, you can choose to transition to a free Cyberday ISMS account to actually start implenenting and monitoring your security actions. You can utilize our tools for e.g. control deployment, risk management, internal auditing and improvement management to get better every day.

Step 4

Review your full framework compliance report

Access a detailed compliance report tailored to your selected framework. Dive into the structure, review gaps, and explore actionable insights that help you achieve full compliance.