A module-native Cyber Assessment Framework - IGP rows, contributing-outcome judgements and evidence inheritance, assembled into a GovAssure-ready evidence pack.
CAF is not a checklist. It is a set of judgements you have to defend.
Under GovAssure, the NCSC Cyber Assessment Framework became the spine of UK government cyber assurance. The hard part is not understanding the framework - it is sustaining consistent contributing-outcome judgements, reusable evidence and clear ownership of gaps across a whole organisation and its supply chain. Rebuilt in a spreadsheet every cycle, that position rarely survives contact with an assessor.
E2ERisk is CAF v4.0 native. Indicators of good practice, contributing-outcome judgements, evidence inheritance and improvement actions live in one model, scoped to your profile - so evidence captured once is reused across outcomes, every judgement carries its rationale and owner, and the Stage 1-4 GovAssure pack assembles from live evidence instead of a frantic document hunt.
Most tools treat the CAF as a content pack bolted onto a generic, US-centric GRC engine. E2ERisk is built the other way round: CAF v4.0 is first-class, modelled at indicator-of-good-practice depth - the level a GovAssure assessor actually expects to see, not a loose mapping that falls apart under questioning.
All four objectives, 14 principles, IGP rows and contributing-outcome judgements built in.
Achieved / Partially / Not-achieved per contributing outcome, each with rationale and evidence.
Reuse evidence across principles and assessments - capture once, satisfy many.
Stage 1-4 evidence assembly with a CO-by-CO accept / concern / reject workflow.
Gaps become tracked actions with owners and dates - closure with an audit trail.
Baseline or Enhanced profile applied per system, scoping the assessment automatically.
A GovAssure assessment is dozens of contributing-outcome judgements that have to hang together. Seeing the whole profile on one screen - achieved, partially achieved and not-yet-achieved across all four objectives - is what turns a sprawling spreadsheet into a position you can actually reason about and defend.
The framework itself is published and well understood; the difficulty is operational. Tracked by hand, judgements drift between assessors, evidence scatters across SharePoint and email, and each GovAssure cycle starts from a blank page rather than last year's verified position.
The assessment follows the GovAssure sequence: scope the systems and profile, self-assess at indicator level, attach evidence once, record a judgement and rationale per contributing outcome, and turn gaps into owned actions - so the Stage 1-4 pack is assembled continuously rather than in a pre-deadline scramble.
A generic GRC tool maps a US control set loosely onto the CAF; a spreadsheet transcribes it by hand. Neither gives you the indicator-level depth an assessor expects. The comparison below shows what native CAF v4.0 support changes.
| Capability | E2ERisk | Spreadsheet tracker | Generic US GRC tool |
|---|---|---|---|
| NCSC CAF v4.0 content | Native - all 14 principles | Manually transcribed | US control set, mapped loosely |
| IGP-level depth | Indicators of Good Practice built in | Free-text cells | Generic maturity levels |
| Contributing-outcome judgements | Achieved / Partial / Not, with rationale | Colour-coded cells | Pass/fail scoring |
| Evidence inheritance | Capture once, satisfy many outcomes | Re-attached every time | Per-control upload |
| GovAssure pack | Stage 1-4 assembled for you | Hand-built each round | Export to PDF only |
| Profile-aware scoping | Baseline / Enhanced per system | Not supported | Not CAF-aware |
The result is a CAF position that holds up under scrutiny: every contributing-outcome judgement carries its rationale and evidence, and the next cycle becomes a review of what changed, not a rebuild.
CAF does not sit in isolation. A single contributing outcome - access control, say - is also an ISO 27001 control, a Cyber Essentials requirement and a NIST function, so the judgement and evidence you record once become evidence against each of them.
The point of native CAF support is what it lets you hold: all four objectives, fourteen principles and thirty-nine contributing outcomes assessed in one model, with the evidence behind each, ready to assemble into a Stage 1-4 GovAssure pack on demand.
Three things come out of the module, each in the form a lead department and an assessor recognise: the CAF profile report, the GovAssure evidence pack, and the improvement plan that turns every gap into owned, dated action.
Objective-by-objective status with rationale and evidence per contributing outcome.
Stage 1-4 assembly with an accept / concern / reject workflow for assessors.
Every gap as a tracked action with an owner, a due date and a closure trail.
One body of CAF evidence, mapped to every regime a UK public-sector organisation answers to - so the work you do for GovAssure also answers NIS, ISO 27001 and the rest without being re-collected.
Assemble a defensible CAF evidence pack continuously - not in a three-week scramble before the deadline.