How this links to the Cyber Security and Resilience Bill
The Bill does not name the CAF, but it is the yardstick regulators already use to judge the "appropriate and proportionate measures" duty in regulation 10. Clause 19 requires regulators’ guidance to cover those measures, and clause 36 lets the Secretary of State issue a statutory code of practice. The CAF is the most likely basis for both.
- Regulators assess operators of essential services against CAF outcomes under the existing NIS Regulations.
- Clause 19 obliges designated competent authorities to issue guidance on security measures and to have regard to any code of practice.
- DESNZ consulted from 23 June to 1 September 2026 on a Tier 1 CAF profile for large load controllers, with Ofgem providing assurance.
- Objectives C and D (detection, response and recovery) underpin the 24-hour and 72-hour reporting duties.
How is the CAF structured?
The CAF sets four objectives, each broken into principles and assessed against indicators of good practice. The result is a maturity picture rather than a pass mark, which fits the outcome-based security duties in the NIS Regulations.
- Objective A, managing security risk: governance, risk management, asset management, supply chain.
- Objective B, protecting against cyber attack: policies, identity and access, data security, system security, resilient networks, staff training.
- Objective C, detecting cyber security events: security monitoring and proactive event discovery.
- Objective D, minimising the impact of incidents: response and recovery planning, lessons learned.
What changed in CAF v4.0?
The NCSC published CAF v4.0 on 6 August 2025, the largest revision since 2018. It adds more than 100 new indicators of good practice, a section on understanding attacker methods and motivations, a section on secure software development, and stronger coverage of monitoring, threat hunting and AI-related risk.
Earlier self-assessments should be treated as a starting point, not a current baseline. The new monitoring and threat hunting indicators matter most for the Bill, because the initial notification is due within 24 hours of first awareness. An organisation that cannot detect an incident promptly cannot report it on time.
What is the Tier 1 CAF profile for load controllers?
Clause 6 brings large load controllers, those with 300 MW or more of potential electrical control, into the NIS Regulations. DESNZ, working with Ofgem and the NCSC, drafted a Tier 1 CAF profile setting the outcomes they would be expected to meet.
The consultation ran from 23 June to 1 September 2026, and the Government is analysing responses. The final profile, and the transition period before Ofgem assures compliance against it, are not settled. It is the first sector-specific CAF profile tied directly to a category the Bill creates, and a sign of how regulators may tailor the CAF for other new entrants.
Worked example (illustrative)
Illustrative: a managed service provider preparing for scope
A mid-sized MSP expects to be a relevant managed service provider. It runs a CAF v4.0 self-assessment and finds that monitoring of customer environments is Partially Achieved. Because the 24-hour clock starts at awareness, it prioritises Objective C before refreshing governance documents.
Common misconceptions
Myth: The CAF is a certification you can pass.
Reality: It is an assessment framework. There is no CAF certificate; outcomes are rated and evidenced, and regulators judge them.
Where it appears in the Bill
- Clause 19Regulator guidance must cover measures under regulation 10(1) and (2).
- Clause 36Secretary of State may issue a code of practice on compliance measures.
- Clause 6Designation of large load controllers, the subject of the Tier 1 profile.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Is the CAF mandatory under the Cyber Security and Resilience Bill?
The Bill does not name the CAF. The legal duty is to take appropriate and proportionate measures. In practice, regulators use the CAF to judge that duty, and guidance or a code of practice under the Bill is likely to draw on it. Treat it as the expected standard of evidence rather than an optional extra.
Which CAF version should I use?
Use CAF v4.0, published by the NCSC on 6 August 2025. It adds more than 100 new indicators of good practice and new sections on threat understanding and secure software. Check with your sector regulator whether it applies a specific profile, such as the Tier 1 profile proposed for large load controllers.
How does the CAF relate to Cyber Essentials?
Cyber Essentials certifies five baseline technical controls. The CAF assesses whole-organisation outcomes from governance to recovery. Cyber Essentials evidence can support parts of CAF Objective B, but it does not show that monitoring, incident response or supply chain risk meet the standard regulators expect under the NIS Regulations.