How to Prepare for the Cyber Security and Resilience Bill Using the NCSC Cyber Assessment Framework
The Cyber Security and Resilience Bill (CSRB) does not, on its own, hand you a checklist. Like the Network and Information Systems (NIS) Regulations it updates, the Bill sets out duties and enforcement powers, then leaves most of the technical detail to secondary legislation and codes of practice that will follow Royal Assent. That creates a practical problem for the organisations it brings into scope: what, concretely, are you supposed to be doing now, while the substantive duties are still being written?
For most in-scope organisations the answer is already published, and it is not part of the Bill at all. It is the NCSC's Cyber Assessment Framework (CAF) - the outcome-based framework the government uses to judge whether an operator of essential services is genuinely resilient. If you want a head start on CSRB compliance that will not be wasted whatever the final regulations say, the CAF is where to start.
Why the Cyber Security and Resilience Bill points to the CAF
The Cyber Security and Resilience Bill widens the existing NIS regime rather than replacing its architecture. Operators of essential services, qualifying managed service providers, in-scope data centres and designated critical suppliers all inherit a version of the same core obligation: take appropriate and proportionate measures to manage the risks to the security of your network and information systems, and report significant incidents.
"Appropriate and proportionate" is deliberately outcome-based language, and the CAF is the government's chosen way of assessing it. The public sector already works this way: through the GovAssure programme, government departments assess themselves against the CAF, and the framework is the reference point NCSC and sector regulators use when they judge cyber resilience. Nothing in the direction of travel suggests the regulators charged with the CSRB - Ofcom is confirmed as the sole regulator for data centres, alongside the existing sector regulators - will abandon that shared language. Preparing against the CAF is therefore the lowest-regret move available while the detailed changes are finalised.
What the Cyber Assessment Framework actually is
The CAF is structured around four top-level security objectives, broken down into 14 principles:
- Objective A - Managing security risk: governance (A1), risk management (A2), asset management (A3) and supply chain (A4). Knowing what you run, why it matters and who else can reach it.
- Objective B - Protecting against cyber attack: service protection policies and processes (B1), identity and access control (B2), data security (B3), system security (B4), resilient networks and systems (B5) and staff awareness and training (B6).
- Objective C - Detecting cyber security events: security monitoring (C1) and proactive security event discovery (C2).
- Objective D - Minimising the impact of incidents: response and recovery planning (D1) and lessons learned (D2).
Each principle is assessed against a set of Indicators of Good Practice (IGPs), and each outcome is rated Achieved, Partially Achieved or Not Achieved rather than scored as a percentage. It is a maturity picture, not a tick-box audit - which is exactly why it maps onto the Bill's "appropriate and proportionate" test better than a certificate does.
The current version, CAF v4.0, was published by the NCSC in August 2025 and is the most significant revision since the framework was introduced in 2018. It adds over 100 new indicators of good practice and sharpens several areas that matter directly for CSRB duties: a stronger focus on understanding attacker methods and motivations, a new emphasis on securing the software used to deliver essential services, expanded coverage of security monitoring and threat hunting, and improved treatment of AI-related risk throughout. If you assessed against an earlier version, treat v4.0 as a fresh baseline, not a minor update.
A CAF-based readiness roadmap
You do not need to wait for the regulations to start. Work through these steps in order.
- Confirm whether you are in scope, and against which duties. Scope, thresholds and sector determine which obligations apply. Start with what the Bill is and the who is affected guidance, then decide whether you are being brought in as an operator of essential services, a relevant digital service provider, a managed service provider or a critical supplier - the emphasis differs.
- Run a baseline CAF self-assessment. Rate every one of the 14 principles Achieved, Partially Achieved or Not Achieved against the v4.0 indicators, honestly. The goal at this stage is an accurate map of where you are, not a flattering one.
- Prioritise by duty, not by objective order. The Bill's hardest new edges are incident detection and reporting, so weight Objectives C and D first if that is where your gaps sit. A strong governance story (Objective A) that cannot actually detect an incident will not satisfy a reporting duty.
- Fix the gaps that carry statutory consequences first. A Not Achieved outcome under security monitoring is a compliance risk the moment a reporting duty commences; a partially achieved governance indicator is a slower-burn issue. Sequence remediation accordingly.
- Gather evidence as you go. Regulators assessing CAF outcomes want demonstrable practice, not policy documents alone - logs, exercise records, tested runbooks. Build the evidence trail now so an inspection is a retrieval exercise, not a scramble.
- Cost it and put it in front of the board. Closing CAF gaps has a real budget line, and so does regulator charging under the regime - our cost recovery explainer sets out how that works. Fund it across the next two financial years rather than discovering the number the week a duty commences.
Where the CAF maps to specific CSRB duties
The value of the CAF is that its principles line up with the Bill's headline obligations:
- Incident reporting. The Bill's 24-hour initial notification and 72-hour full-report expectation depend entirely on Objective C. You cannot report within 24 hours what your monitoring did not detect. The related near-miss reporting duty, which goes beyond both the current NIS Regulations and the EU's NIS2, leans even harder on C1 and C2.
- Supply chain. Principle A4 is the CAF's answer to the Bill's expanded focus on managed service providers and critical suppliers. If you rely on third parties for essential services, A4 is where you demonstrate you have assessed and managed that dependency - and it is the groundwork you will need if the Government's proposed vendor-related direction powers over risky suppliers are enacted.
- Risk management and governance. Objective A is the framework's expression of the "appropriate and proportionate measures" duty at the heart of the Bill.
- Response and recovery. Objective D is where you show you can minimise disruption and learn from it - the resilience half of the Bill's name.
Common gaps to fix now
Across in-scope sectors, the same weak spots recur. Security monitoring that covers the corporate network but not operational technology or cloud-hosted services. Asset inventories that are months out of date, so you cannot say what is exposed. Incident response plans that have never been exercised end to end against a realistic scenario. Supply chain assurance that stops at a signed questionnaire. Each of these is a Partially Achieved or Not Achieved outcome waiting to become a compliance finding once the duties bite.
None of this depends on the final wording of the regulations, which is the point. The Bill completed its Commons stages and passed to the Lords in June 2026; Lords Committee Stage began on 1 September 2026, Royal Assent is expected in late 2026, and the substantive duties are then expected to be phased in through secondary legislation, following the DSIT implementation consultation, towards 2028. That timeline reads as generous until you measure it against how long it takes to stand up continuous monitoring or re-architect a supply chain assurance process. Starting from the CAF now converts that window into preparation time. For the full picture of the obligations, see our definitive analysis of the Bill and track its progress.
This article draws on the NCSC's Cyber Assessment Framework guidance and the CAF v4.0 release (published August 2025, ncsc.gov.uk), corroborated by independent CAF v4.0 analyses from Bridewell, Huntsman Security and others; the CAF's four objectives and 14 principles are set out in NCSC and security.gov.uk guidance. The Bill's stage (Lords Committee Stage, which began on 1 September 2026) is confirmed on the UK Parliament page for HL Bill 32 (bills.parliament.uk/bills/4035). Position as of 2 September 2026.