On 6 August 2025, the National Cyber Security Centre (NCSC) unveiled CAF 4.0, the latest version of its Cyber Assessment Framework. This update builds on CAF 3.2 and introduces significant changes to enhance cyber security best practices.
This update puts greater emphasis on measuring the effectiveness of cyber practices and controls, rather than simply confirming their presence. This means organisations are expected to be able to evidence that the practices they have in place are impacting on cybersecurity and resilience in the real world. The NCSC have also re-highlighted that the CAF 4.0 is an outcome-based assessment; therefore, the Indicators of Good Practice listed in the CAF should not be used as a checklist to ascertain a compliance state.
Updated Structure and Language in CAF 4.0
As with previous updates, minor linguistic updates have been made to make the content of the assessment framework easier to interpret and assess against. Overlaps and ambiguities that were present in version 3.2 have been removed, resulting in clearer guidance, more consistent terminology, and a more logical flow between principles and contributing outcomes.
A Threat-Focused Approach to Risk Management
There is an increased emphasis on proportionate and strategic risk responses. Now, organisations are expected to consider and anticipate potential risks from technological developments that could be used to adversely impact network and information systems. Examples of this are the growing use of AI powered tools and Large Language Models that many organisations are now adopting.
Understanding Threat
While previous versions of the framework referred to the use of threat intelligence within Principle A2, with more focused guidance in Principle C2, a newly developed Contributing Outcome (A2.b Understanding Threat) is intended to encourage organisations to fully understand their threat landscape and use this information to inform their risks. This should allow for organisations to make better decisions when it comes to risk management.
Understanding Users’ and Systems’ Behaviour, and Threat Intelligence (within Security Monitoring)
Threat Hunting has been introduced as a new Contributing Outcome, replacing the previous which focused on proactive system discovery. This update arrives alongside a newly introduced C1.f, which centres on analysing user and system behaviour, as well as integrating threat intelligence. Together, these revisions mark a significant shift in what is expected of organisations. The focus has shifted from simply consuming threat intelligence to actively leveraging it to detect, understand, and respond to emerging risks within the organisation’s wider threat landscape.
In earlier iterations of the CAF, organisations were expected to monitor for unusual system behaviour that might suggest malicious intent. With the release of version 4.0, the bar has been raised. Organisations must now show a deeper grasp of threat hunting methodologies and demonstrate the ability to deploy these capabilities effectively.
Supply Chain Considerations
Secure Software Development and Support
Virtually all organisations depend on software, whether developed in-house or sourced externally, which inherently carries the risk of exploitable vulnerabilities. These weaknesses may emerge during initial deployment or evolve over the software’s operational lifespan. This is particularly applicable to legacy OT technology present within some CNI organisations, and CAF has always aimed to highlight this issue. However, the new update goes one step further by introducing an entirely new Contributing Outcome that emphasises the security of supported software, including development and testing environments within the production stages. There is a further requirement for the organisation to demonstrate the use of a software development framework such as NIST Secure Software Development Framework and Microsoft Secure Development Lifecycle.
So, what does this mean?
Although CAF 4.0 has now been published, it is ultimately up to each Operator of Essential Services (OES’s) Competent Authority to determine when they will be expected to meet the requirements of the updated framework. When this happens, OESs will need to update their supporting documentation to reflect the changes in the new version. Whilst it is generally true that OESs should align to the latest frameworks and guidance, it is always recommended to consult with the Competent Authorities to understand what their expectations are.
It’s also worth noting that the forthcoming Cyber Security and Resilience Bill will bring new sectors into the scope of UK NIS regulations. As a result, managed service providers, data centre operators, and others will likely have to gear up to adhere to CAF 4.0 in future.
Want to find out what this means for you? Get in touch for a conversation with an expert.