Framework
Full specification

CAF 4.0

Oh no! No description found. But not to worry. Read from Tasks below how to advance this topic.

NCSC's Cyber Assessment Framework (CAF) 4.0 is a UK framework designed to help organizations providing essential services assess and improve their cyber resilience through a structured, outcome-focused approach.

The NCSC Cyber Assessment Framework (CAF) 4.0 is an outcome-based model developed by the UK's National Cyber Security Centre (NCSC) to help organizations, particularly those providing essential services and critical national infrastructure, assess and improve their cyber resilience. It offers a systematic approach to evaluating how effectively cyber risks to essential functions are managed based on predefined Indicators of Good Practice (IGPs). The CAF is designed to help organizations define and achieve security objectives appropriate to their risks and operational context. CAF 4.0 includes updates such as a section focused on understanding attacker methods, ensuring secure software development, enhancing threat detection, and strengthening coverage of AI-related cyber risks.
No items found.
Tasks
45
Scope
Want to see how Cyberday helps users address
CAF 4.0
compliance?
Here's what
CAF 4.0
requires and how to comply.

Below you'll find all of the requirements of this framework. In Cyberday, we map all requirement to global tasks, making multi-compliance management easy. Do it once, and see the progress across all frameworks!

Requirements
C1.c: Generating alerts
C1.f: Operational threat awareness
C1.a: Logging and monitoring
C1.d: Alert contextualisation
A3: Asset management
A2.a: Internal processes for risk management
A4.b: Secure software development and support
A4.a: Supplier risk management
A1.b: Roles and responsibilities
D2.a: Post incident analysis
D2.b: Learning from incidents
D1.c: Testing response plans
D1.b: Response and recovery capability
D1.a: Response plan
B6.a: Cyber security culture
B4.c: Secure management
CAF 4.0
learning hub

Explore our comprehensive resources and improve your security with the themes of this framework.

How Cyberday helps with
CAF 4.0

Discover specific ways our platform streamlines your ISO 27001 compliance process, from automated controls to audit preparation.

Explore use case
Free
CAF 4.0
assessment

Take our comprehensive assessment to identify gaps in your current implementation and get personalized recommendations.

Start assessment
Read more about
CAF 4.0

Dive deeper with our articles, case studies, and expert insights on framework implementation.

Read article
Guide to compliance

Get a concise overview of all requirements, controls, and implementation steps in our quick guide.

Get the guide
Framework comparison

See how the overlap and differences with any other framework to optimize your compliance strategy.

Compare framework
Join a live
CAF 4.0
webinar

Participate in expert-led sessions covering implementation strategies, common pitfalls, and best practices for compliance.

Register for webinar
Join our live webinars

Participate in expert-led sessions covering implementation strategies, common pitfalls, and best practices for compliance.

Register for webinar
What are frameworks?

Understand the basics of cyber security frameworks with our comprehensive guide.

Read the article

The ISMS component hierachy

When building an ISMS, it's important to understand the different levels of information hierarchy. Here's how Cyberday is structured.

Framework

Sets the overall compliance standard or regulation your organization needs to follow.

Requirements

Break down the framework into specific obligations that must be met.

Tasks

Concrete actions and activities your team carries out to satisfy each requirement.

Policies

Documented rules and practices that are created and maintained as a result of completing tasks.

Never duplicate effort. Do it once - improve compliance across frameworks.

Reach multi-framework compliance in the simplest possible way
Security frameworks tend to share the same core requirements - like risk management, backup, malware, personnel awareness or access management.
Cyberday maps all frameworks’ requirements into shared tasks - one single plan that improves all frameworks’ compliance.
Do it once - we automatically apply it to all current and future frameworks.