LOADING…
Platform  /  CAF Assessment  ·  Module
NCSC CAF · GovAssure

NCSC CAF & GovAssure,done properly.

A module-native Cyber Assessment Framework - IGP rows, contributing-outcome judgements and evidence inheritance, assembled into a GovAssure-ready evidence pack.

14 principles4 objectivesStage 1-4 GovAssure
The challenge

The framework is published. Defending it is the hard part.

CAF is not a checklist. It is a set of judgements you have to defend.

Under GovAssure, the NCSC Cyber Assessment Framework became the spine of UK government cyber assurance. The hard part is not understanding the framework - it is sustaining consistent contributing-outcome judgements, reusable evidence and clear ownership of gaps across a whole organisation and its supply chain. Rebuilt in a spreadsheet every cycle, that position rarely survives contact with an assessor.

E2ERisk is CAF v4.0 native. Indicators of good practice, contributing-outcome judgements, evidence inheritance and improvement actions live in one model, scoped to your profile - so evidence captured once is reused across outcomes, every judgement carries its rationale and owner, and the Stage 1-4 GovAssure pack assembles from live evidence instead of a frantic document hunt.

Why it's different

Built for the framework you're audited against.

Most tools treat the CAF as a content pack bolted onto a generic, US-centric GRC engine. E2ERisk is built the other way round: CAF v4.0 is first-class, modelled at indicator-of-good-practice depth - the level a GovAssure assessor actually expects to see, not a loose mapping that falls apart under questioning.

CAF v4.0 native

All four objectives, 14 principles, IGP rows and contributing-outcome judgements built in.

CO judgements

Achieved / Partially / Not-achieved per contributing outcome, each with rationale and evidence.

Evidence inheritance

Reuse evidence across principles and assessments - capture once, satisfy many.

GovAssure pack

Stage 1-4 evidence assembly with a CO-by-CO accept / concern / reject workflow.

Improvement tracking

Gaps become tracked actions with owners and dates - closure with an audit trail.

Profile-aware scoping

Baseline or Enhanced profile applied per system, scoping the assessment automatically.

See it work

Your CAF profile, at a glance.

A GovAssure assessment is dozens of contributing-outcome judgements that have to hang together. Seeing the whole profile on one screen - achieved, partially achieved and not-yet-achieved across all four objectives - is what turns a sprawling spreadsheet into a position you can actually reason about and defend.

 caf-assessment · GovAssure profileLive
A · Managing risk
A1 Governance
A2 Risk management
A3 Asset management
A4 Supply chain
B · Protecting
B1 Policies
B2 Identity & access
B3 Data security
B4 System security
C · Detecting
C1 Security monitoring
C2 Threat awareness
D · Minimising impact
D1 Response planning
D2 Lessons learned
AchievedPartially achievedNot yet achieved
The problem

CAF in a spreadsheet doesn't survive contact with GovAssure.

The framework itself is published and well understood; the difficulty is operational. Tracked by hand, judgements drift between assessors, evidence scatters across SharePoint and email, and each GovAssure cycle starts from a blank page rather than last year's verified position.

Without E2ERisk
Each principle tracked by hand, row by row in Excel
Evidence scattered across SharePoint, email and screenshots
IGPs interpreted differently by every assessor
The GovAssure submission rebuilt from scratch each cycle
No line of sight from a gap to who is fixing it
With E2ERisk
All 4 objectives, 14 principles and 39 contributing outcomes, native
Evidence captured once and inherited across every outcome
IGP-level guidance built in, so judgements stay consistent
A GovAssure Stage 1-4 evidence pack assembled automatically
Every gap becomes a tracked action with an owner and a date
How it works

From scoping to a GovAssure-ready pack.

The assessment follows the GovAssure sequence: scope the systems and profile, self-assess at indicator level, attach evidence once, record a judgement and rationale per contributing outcome, and turn gaps into owned actions - so the Stage 1-4 pack is assembled continuously rather than in a pre-deadline scramble.

01
Scope
Baseline or Enhanced profile
Systems in scope set
02
Self-assess
IGP rows per outcome
Achieved / Partial / Not
03
Evidence
Attach once
Inherit across outcomes
04
CO judgement
Rationale per outcome
Reviewer sign-off
05
Improve
Gaps → tracked actions
Owners & dates
06
GovAssure
Stage 1-4 pack
Assessor workflow
Why it's better

Built for the framework you’re actually audited against.

A generic GRC tool maps a US control set loosely onto the CAF; a spreadsheet transcribes it by hand. Neither gives you the indicator-level depth an assessor expects. The comparison below shows what native CAF v4.0 support changes.

CapabilityE2ERiskSpreadsheet trackerGeneric US GRC tool
NCSC CAF v4.0 contentNative - all 14 principlesManually transcribedUS control set, mapped loosely
IGP-level depthIndicators of Good Practice built inFree-text cellsGeneric maturity levels
Contributing-outcome judgementsAchieved / Partial / Not, with rationaleColour-coded cellsPass/fail scoring
Evidence inheritanceCapture once, satisfy many outcomesRe-attached every timePer-control upload
GovAssure packStage 1-4 assembled for youHand-built each roundExport to PDF only
Profile-aware scopingBaseline / Enhanced per systemNot supportedNot CAF-aware

The result is a CAF position that holds up under scrutiny: every contributing-outcome judgement carries its rationale and evidence, and the next cycle becomes a review of what changed, not a rebuild.

Framework depth

Assess one outcome, satisfy many frameworks.

CAF does not sit in isolation. A single contributing outcome - access control, say - is also an ISO 27001 control, a Cyber Essentials requirement and a NIST function, so the judgement and evidence you record once become evidence against each of them.

CAF B2.a
Identity and access control - only authorised users and devices can access networks and systems.
This contributing outcome maps to
NCSC CAF B2.aIdentity & access management
ISO 27001:2022A.5.15, A.5.16, A.8.2 - access control
Cyber EssentialsUser access control
NIST CSF 2.0PR.AA - identity, authentication & access
Outcomes

The whole framework, on one screen.

The point of native CAF support is what it lets you hold: all four objectives, fourteen principles and thirty-nine contributing outcomes assessed in one model, with the evidence behind each, ready to assemble into a Stage 1-4 GovAssure pack on demand.

4
CAF objectives
14
principles
39
contributing outcomes
Stage 1-4
GovAssure ready
What you get

Deliverables your lead government department expects.

Three things come out of the module, each in the form a lead department and an assessor recognise: the CAF profile report, the GovAssure evidence pack, and the improvement plan that turns every gap into owned, dated action.

CAF profile report

Objective-by-objective status with rationale and evidence per contributing outcome.

GovAssure evidence pack

Stage 1-4 assembly with an accept / concern / reject workflow for assessors.

Improvement plan

Every gap as a tracked action with an owner, a due date and a closure trail.

Native to your frameworks

Map once. Report against everything.

One body of CAF evidence, mapped to every regime a UK public-sector organisation answers to - so the work you do for GovAssure also answers NIS, ISO 27001 and the rest without being re-collected.

NCSC CAF v4.0GovAssureNIS RegulationsNIS2ISO 27001:2022NIST CSF 2.0
CAF Assessment

Walk into GovAssure ready.

Assemble a defensible CAF evidence pack continuously - not in a three-week scramble before the deadline.

See Supplier Assurance