How UK CISOs Should Prepare for the Cyber Assessment Framework | INFORMD Executive Briefing

How UK CISOs Should Prepare for the Cyber Assessment Framework

UK CISOs should map controls to the NCSC’s Cyber Assessment Framework now, before the Cyber Security and Resilience Bill makes it statutory. The framework already underpins how regulators judge cyber governance in essential and digital services.

The Cyber Security and Resilience Bill entered the House of Lords on 25 June 2026 after clearing all Commons stages, with Royal Assent expected later this year and phased implementation running through to 2028. Once enacted, it places the National Cyber Security Centre’s Cyber Assessment Framework (CAF) on a statutory footing as the baseline standard for Operators of Essential Services, Relevant Digital Service Providers, managed service providers and newly designated Critical Suppliers. For CISOs, the compliance clock is already running, even though the legislation is not yet law.

What Does the Bill Actually Change for Security Leaders?

Today, CAF compliance is largely voluntary outside a narrow set of NIS-regulated sectors such as energy, water, transport and digital infrastructure. The Bill widens that net substantially. It brings managed service providers into direct scope for the first time, gives regulators the power to designate “Critical Suppliers” whose failure could disrupt an essential service, and extends coverage to data centres and large load controllers supporting the grid. Firms that have never had a statutory cyber duty — including many technology vendors and outsourcers serving regulated clients — will need to demonstrate CAF alignment or risk losing contracts with in-scope customers, regardless of whether they are directly regulated themselves.

Executive Action:

  • Confirm whether your organisation, or a critical supplier you depend on, falls within the Bill’s expanded scope.
  • Ask procurement to flag contracts where a counterparty may soon need to evidence CAF compliance.
  • Brief the audit or risk committee that the compliance deadline is regulatory, not optional, once Royal Assent lands.

What Are the Four CAF Objectives CISOs Must Map Against?

According to the NCSC, the Cyber Assessment Framework reached version 4.0 in August 2025 and remains structured around four outcomes-based objectives, each underpinned by a set of security principles rather than prescriptive controls. Objective A covers managing security risk — governance, asset management and supply chain risk. Objective B covers protecting against cyber attack — identity and access control, data security, resilient networks and staff awareness. Objective C covers detecting cyber security events — monitoring and proactive discovery. Objective D covers minimising the impact of incidents — response planning, recovery capability and lessons learned. Assessors score each principle against indicators of good practice, so CISOs need evidence, not just policy documents.

Executive Action:

  • Run a gap assessment against all four CAF objectives, not just the technical controls under Objective B.
  • Assign a named owner for each objective, since governance and supply chain risk under Objective A are frequently under-resourced.
  • Build an evidence pack now — auditors will expect documented indicators of good practice, not assurances.

Why Is Board-Level Ownership the Weak Link?

According to the 2025/2026 Cyber Security Breaches Survey, only 31% of UK businesses have explicit board-level responsibility for cyber risk — the single gap the CAF’s governance-first design is built to close. The framework treats cyber risk as a business risk owned at board level, not a technical problem delegated wholesale to IT. Regulators assessing CAF compliance under the new Bill will expect to see board minutes, risk appetite statements and management assurance reporting that reference cyber security explicitly, alongside the technical evidence. A CISO who cannot show the board is engaged on CAF outcomes will struggle to demonstrate Objective A compliance, however strong the technical controls are underneath.

Executive Action:

  • Put CAF readiness on the board or risk committee agenda before Royal Assent, not after.
  • Ensure risk appetite statements name cyber security explicitly rather than folding it into generic operational risk.
  • Use INFORMD’s AI and technology governance self-assessment to benchmark current board engagement against CAF’s governance expectations.

How Should CISOs Sequence Their CAF Readiness Programme?

With phased implementation running to 2028, there is time to sequence readiness properly rather than rushing a compliance exercise. The priority order should be: confirm scope and supply chain exposure first, since designation as a Critical Supplier can arrive via a customer’s regulator rather than your own; complete an honest gap assessment against all 14 CAF principles second; and only then invest in technical remediation, sequenced against the objectives where evidence gaps are largest. Firms that jump straight to tooling before establishing governance ownership typically fail Objective A on their first assessment, even with strong technical scores elsewhere.

Executive Action:

  • Sequence governance and evidence-gathering ahead of technical spend to avoid failing Objective A despite strong controls elsewhere.
  • Track the Bill’s progress through the Lords and revisit scope annually as Critical Supplier designations are issued.
  • Review INFORMD’s related briefing on the Cyber Security and Resilience Bill for the board-level obligations that sit alongside this technical roadmap.

INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).

What is the NCSC Cyber Assessment Framework?

The Cyber Assessment Framework (CAF) is the National Cyber Security Centre’s outcomes-based framework for assessing cyber resilience. It has four objectives — managing risk, protecting against attack, detecting events and minimising impact — each measured against defined indicators of good practice rather than fixed technical checklists.

Who will the Cyber Security and Resilience Bill apply to?

The Bill extends statutory CAF-based duties to Operators of Essential Services, Relevant Digital Service Providers, managed service providers, newly designated Critical Suppliers, data centres and large load controllers — a significantly wider scope than the current NIS regulations.

When will the Cyber Security and Resilience Bill become law?

The Bill entered the House of Lords on 25 June 2026 after completing all Commons stages. Royal Assent is expected later in 2026, with the new duties phased in through to 2028, giving organisations a window to prepare.

Why does CAF readiness start with the board, not IT?

Objective A of the CAF assesses governance and risk ownership. With only 31% of UK businesses giving boards explicit cyber responsibility, regulators expect documented board engagement — risk appetite statements, minutes and assurance reporting — alongside technical controls.

Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk (/resources/).

Similar Posts