Northern Ireland already runs independent cyber audits across its water, energy and transport systems. Great Britain's own regulators for energy, oil and most of transport are still only "prospective" partners, months past the date they set themselves to join.
Estimated reading time: 10 minutes
In short. The Cyber Assessment Framework is the National Cyber Security Centre's tool for judging whether organisations running the UK's essential functions, power, water, transport, health, nuclear sites, government itself, are managing their cyber risk properly. The framework says outright that NCSC "has no regulatory responsibilities" and that it is "not the responsibility of NCSC to mandate" anything: enforcement is handed entirely to each sector's own regulator. NCSC's own scheme for independently auditing that self-assessment, launched in October 2024, describes itself as still "initially a Minimum Viable Product." Northern Ireland's regulator already uses it across water, energy, health and transport. Great Britain's regulators for energy, oil and most of transport remain only "prospective" partners, two of them past their own stated target to join. Five documented gaps: three stars.
Picked from the registry's long-queued Tier 2 pool after a direct re-check, per this site's standing rule to verify an "unpickable" claim against the document itself rather than repeat an inherited shorthand: NCSC's Cyber Assessment Framework turned out to be a single, substantial 68-page standard, not the thin collection hub it had been filed under. The escalation criteria in CLAUDE.md pushed it to a Tier 3 treatment: a critical-infrastructure framework covering sectors worth far more than a billion pounds, a live bill reaching report stage in the House of Lords this month, and a document that is, by its own design, "first-of-kind" in naming a standard while explicitly refusing to be the body that enforces it.
A tool that assesses everything and mandates nothing
Version 4.0 of the Cyber Assessment Framework, published 18 April 2024 and reviewed again on 6 August 2025, is NCSC's framework for judging the cyber resilience of "essential functions": the systems behind electricity, gas, water, transport, health and the rest of the UK's critical national infrastructure [1]. It is built around four objectives, managing security risk, protecting against cyber attack, detecting security events and minimising the impact of an incident [2] (pp.7, 23, 51, 63), broken into 14 principles and, in total, "41 individual assessments" an organisation can be marked against [2] (p.5).
The document is careful, on its own second page, to say what it is not. "CAF-based assessments can be carried out either by the responsible organisation itself (self-assessment) or by an independent external entity, possibly a regulator / cyber oversight body or a suitably qualified organisation... It should be noted that NCSC developed the CAF in its role as national technical authority for cyber security, with an expectation that it would be used, amongst other things, as a tool to support effective cyber regulation. NCSC itself has no regulatory responsibilities, and organisations subject to cyber regulation should consult with their regulators to learn whether they should use the CAF" [2] (p.2). A page later, the same point is made about the standard an organisation has to meet: "It is not the responsibility of the NCSC to mandate what represents appropriate and proportionate cyber security and resilience. Any target set for organisations to achieve in terms of CAF results is for the relevant cyber oversight body to define" [2] (p.6).
That is an honest description of how the framework is built, and not, on its own, a defect. But it means the document's own claim to "support effective cyber regulation" [2] (p.2) stands or falls entirely on what the sector regulators it hands the job to actually do with it. That is checkable, and NCSC publishes the evidence itself.
The audit scheme is still, in its own words, a prototype
In October 2024 NCSC launched the mechanism meant to put some rigour behind self-assessment: the Cyber Resilience Audit scheme, which "assures companies delivering independent cyber audits" against the CAF. Its own introduction page states the purpose plainly: "The Cyber Resilience Audit scheme gives consumers confidence in companies that have been assessed as meeting the NCSC standard for delivering independent cyber audits" [3]. The same page is equally plain about its maturity, a year on: "The scheme is initially a Minimum Viable Product; therefore, the initial independent audits will be against Cyber Assessment Framework (CAF)" [3], with the framework expected to broaden later.
Crucially, the scheme does not require anyone to use it. "Scheme Partners may encourage, recommend or require the organisations they oversee to have audits conducted by CRA Assured Service Providers" [3]. Three different verbs, covering three different levels of commitment, and NCSC's own Scheme Partners page shows which "Cyber Oversight Bodies" have actually signed up to any of the three [4].
Belfast is ahead of London
Five bodies are named as current Scheme Partners. The Department for Science, Innovation and Technology is moving GovAssure, the scheme covering central government's own critical systems, onto the CRA model. The Department of Health and Social Care and NHS England have aligned CAF into the Data Security and Protection Toolkit used by NHS trusts, foundation trusts and integrated care boards since September 2024. The Department for Business and Trade covers the chemical sector. The Office for Nuclear Regulation is listed too, though its own entry is the most qualified of the five: it uses its existing Security Assessment Principles and treats CAF adoption as "relevant good practice" rather than a requirement [4].
The fifth current partner is the Department of Finance, Northern Ireland, acting as the NIS Competent Authority for Operators of Essential Services across water, health, energy and transport in Northern Ireland [4]. One devolved administration's regulator already covers all four of its essential sectors under the scheme NCSC built to check CAF self-assessment.
Great Britain's equivalents are listed too, under a separate heading: "Prospective Scheme Partners." Ofgem, the NIS Competent Authority for downstream gas and electricity, is "developing sector-specific requirements" and "exploring incorporation into" its own Assurance Framework, version two [4]. The Department for Energy Security and Net Zero, covering oil, upstream gas and joint authority over electricity and downstream gas, is listed as prospective with no further detail given [4]. The Department for Transport and the Civil Aviation Authority are both listed with the same projected start date: "not before FY 2025/26" [4]. The 2025/26 financial year ended in March 2026. As of this piece, neither appears among the scheme's current partners.
None of this means electricity, oil, gas or transport operators do nothing on cyber security; Ofgem, the Drinking Water Inspectorate and the other sector regulators run their own CAF-based self-assessment regimes under the wider NIS Regulations, independently of NCSC's audit scheme. What the Scheme Partners page documents is narrower and still telling: the specific mechanism NCSC built to put an independently assured audit behind that self-assessment, the thing meant to answer "can we trust what the regulated organisation told us," has not yet reached the sectors where Great Britain keeps the lights, the fuel supply and most of its transport running, two years after NCSC marked both Scotland, England and Wales's transport regulators with the same FY2025/26 target that has already passed.
A live bill the framework does not mention
While that gap sits unresolved, the law around it is moving. The Cyber Security and Resilience (Network and Information Systems) Bill had its first reading in the Commons on 12 November 2025, reached report stage in the Commons on 16 June 2026, and is now at report stage in the House of Lords, with a sitting listed for 26 October 2026 [5] [6]. The Bill, sponsored jointly by the Department for Science, Innovation and Technology in the Commons and Lords, amends the Network and Information Systems Regulations 2018, the legislation CAF-based assessment exists to support [5]. The government's own factsheet summarises what changes: an expanded scope bringing data centres, managed service providers, large load controllers and newly designated "critical suppliers" under regulation, alongside a 24-hour initial incident-notification requirement and new cost-recovery powers for regulators [7]. The enforcement factsheet sets two new penalty bands: up to 10 million pounds or 2 percent of worldwide turnover for standard breaches, and up to 17 million pounds or 4 percent of worldwide turnover, whichever is higher, for the most serious [8]. The canonical Parliament bill page, bills.parliament.uk/bills/4035, returns a 403 to automated fetches. The dates and stage above are drawn directly from Parliament's own Bills API, which serves the same underlying record [5] [6].
The government's own factsheet mentions the CAF only once, in passing, noting that "NCSC has a range of guidance available on its website, including the recent launch of Cyber Assessment Framework version 4.0" [7]; it does not say the Bill makes CAF a statutory baseline, and this piece does not claim that it does. What the Bill does, on its own text, is expand who can be regulated and how hard they can be fined under the regime that CAF-based self-assessment sits inside. The Cyber Assessment Framework document itself, last reviewed six weeks after the Bill's Commons committee stage finished, does not mention the Bill, the NIS Regulations by name, or the words "Network and Information Systems" anywhere across its 68 pages. A document built to help organisations "support effective cyber regulation" [2] (p.2) does not once name the regulation it supports, while that regulation is actively being rewritten around it.
Credit where due
The framework itself is not a weak piece of work. Its four objectives and 14 principles are written as outcomes rather than a tick-box checklist, with explicit "achieved," "partially achieved" and "not achieved" indicators for each of the 41 contributing outcomes, a structure designed to resist the kind of box-ticking compliance exercise that makes a framework look stronger on paper than in practice [2] (pp.4, 7). Its Indicators of Good Practice tables are explicit that they are not an exhaustive checklist and are meant to inform expert judgement, a more honest framing than many compliance documents offer [2] (p.5). The Cyber Resilience Audit scheme, for its part, is transparent about its own immaturity rather than overselling a "Minimum Viable Product" as a finished assurance regime [3], and Northern Ireland's Department of Finance shows the model can be adopted across an entire essential-sector portfolio when a single regulator commits to it [4].
Verdict
The Cyber Assessment Framework does what it says: it gives organisations a detailed, outcome-based way to judge their own cyber resilience, and it says clearly, in its own words, that NCSC will not force anyone to use it properly. That design choice hands the actual enforcement to sector regulators whose own published commitment to independent audit varies from "already covers all four essential sectors" in Belfast to "developing sector-specific requirements" at Ofgem and a missed FY2025/26 target at the Department for Transport and the Civil Aviation Authority. None of that is hidden; NCSC publishes the Scheme Partners list itself. But a framework whose own text has not been updated to mention the live bill rewriting the regulatory regime around it, while the energy, oil and most of the transport sector in Great Britain remain only "prospective" users of its own flagship audit scheme, is not yet the "effective cyber regulation" it was built to support.
This analysis is based on NCSC's Cyber Assessment Framework version 4.0 PDF (published 18 April 2024, reviewed 6 August 2025) and the Cyber Resilience Audit scheme's Introduction and Scheme Partners pages as published on GOV.UK/NCSC at the time of writing, 2 October 2026. If either is revised, or the Cyber Security and Resilience Bill completes its passage, this piece will be updated with a diff; both are tracked in our Daily Register.
The star score counts five documented gaps: the framework's explicit disclaimer of any NCSC enforcement role, the Cyber Resilience Audit scheme's self-description as "initially a Minimum Viable Product" fifteen months after launch, Ofgem's Scheme Partner status still at the "developing requirements" stage, the Department for Transport and Civil Aviation Authority both past their own stated FY2025/26 target to join with no partner status yet shown, and the framework's own text never mentioning the NIS Regulations or the Bill amending them. Five falls in the 4 to 9 band: three stars. The bands are on the ratings page.
Sources
- NCSC, "Cyber Assessment Framework" collection page (reviewed 6 August 2025; checked live 2 October 2026). https://www.ncsc.gov.uk/collection/cyber-assessment-framework
- NCSC, "Cyber Assessment Framework 4.0" (PDF, published 18 April 2024; all page references to this edition). https://www.ncsc.gov.uk/sites/default/files/documents/NCSC-Cyber-Assessment-Framework-4.0.pdf
- NCSC, Cyber Resilience Audit scheme, "Introduction" page. https://www.ncsc.gov.uk/schemes/cyber-resilience-audit/introduction
- NCSC, Cyber Resilience Audit scheme, "Scheme Partners" page (current and prospective Cyber Oversight Bodies). https://www.ncsc.gov.uk/schemes/cyber-resilience-audit/scheme-partners
- UK Parliament Bills API, Cyber Security and Resilience (Network and Information Systems) Bill, bill record. https://bills-api.parliament.uk/api/v1/Bills/4035
- UK Parliament Bills API, same Bill, full stage history. https://bills-api.parliament.uk/api/v1/Bills/4035/Stages
- GOV.UK, Cyber Security and Resilience (NIS) Bill factsheets, "Summary of the Bill". https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/summary-of-the-bill
- GOV.UK, Cyber Security and Resilience (NIS) Bill factsheets, "Enforcement". https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/enforcement