Skip to content
NCSC CAF + GovAssure · UK

Walk into a GovAssure assessment with the file already on the table.

The NCSC Cyber Assessment Framework is the gateway cyber rulebook for UK government, Critical National Infrastructure and the suppliers behind them. Have the evidence the assessor expects.

What you get

Three outcomes for a CAF assessment.

The CAF evidence pack

One PDF and CSV covering every CAF objective the assessor walks through.

An honest verdict map

Each contributing outcome shows Achieved, Partially Achieved or Not Achieved — with the signal behind it.

The remediation list

Gaps surfaced as a short list, sorted by the impact on your GovAssure score.

How it works

Connect. Assess. Ship.

1. Connect

Read-only OAuth into your cloud and SaaS.

2. Assess

Each contributing outcome mapped to your evidence. Two reviewers sign off.

3. Ship

One-click CAF evidence pack with the audit trail attached.

Who it’s for

UK government, CNI operators, and their suppliers.

Departments and arm’s-length bodies inside the GovAssure scheme. CNI operators in scope of NIS Regulations. Suppliers behind both.

Deep detail

Every CAF objective, mapped — in our docs.

The full CAF walkthrough — the four objectives, the fourteen principles and every contributing outcome — lives on docs.secruna.com.

Want to see your CAF gap?
Talk to us for 30 minutes.

A 30-minute call tells you which outcomes are Achieved today and which are not.