Security HubGovAssure and the CAF: Selling to UK Government

GovAssure and the CAF: Selling to UK Government

Netru Compliance8 min read

GovAssure is how UK central government now assures its own cyber security, and it has replaced the cyber element of the Departmental Security Health Check. It matters to suppliers for a reason that is easy to miss: departments assessed against a framework will push that framework into their supply chain, because their assessment depends partly on you.

What GovAssure is

It is a process run across central government departments and selected arm's length bodies, assessing their critical systems against the National Cyber Security Centre's Cyber Assessment Framework. It replaced the cyber portion of the Departmental Security Health Check and moved government away from the older Minimum Cyber Security Standards.

The significance is the shift from a checklist to an outcomes framework. Minimum standards asked whether specific controls existed. The CAF asks whether security outcomes are being achieved, which is harder to satisfy on paper and more informative when satisfied.

The five stages

Stage one establishes organisational context: what the department does, what matters most, and what would be most damaging to lose.

Stage two identifies the in-scope systems and assigns a target CAF profile to each. Not every system is held to the same standard, and the profile assigned determines what achievement looks like for that system.

Stage three is the self-assessment against the CAF for those systems, recorded in the WebCAF service.

Stage four is an independent assurance review of that self-assessment. This is the stage with the most significant recent change: from April 2026 it can only be delivered by a provider on the NCSC Cyber Resilience Audit scheme. Anyone planning this work needs to check their assessor is on that scheme rather than assuming any competent auditor qualifies.

Stage five produces a targeted improvement plan for the gaps the review found.

What the CAF actually is

Worth understanding on its own, because it now appears well beyond government. The framework has four objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of cyber security incidents.

Under those sit fourteen principles, and under those a set of contributing outcomes, thirty-nine in the base framework. Each outcome is supported by indicators of good practice, and each is assessed as achieved, partially achieved or not achieved.

The design point is that it describes outcomes rather than controls. It does not tell you to deploy a particular technology; it asks whether you can detect an intrusion, and leaves how to you. That makes it more durable than a control list and considerably harder to satisfy by procurement alone.

It is also becoming the common language of UK public sector assurance. The NHS Data Security and Protection Toolkit moved onto a CAF-aligned basis for its largest organisations in September 2024, and the CAF is used in the NIS regulations for operators of essential services. Learning it once now pays across health, government and critical national infrastructure.

Why this reaches suppliers

Departments cannot achieve CAF outcomes for systems they do not run. If a supplier hosts the service, the department's assessment of that system depends on what the supplier can evidence, so the questions arrive in procurement and in contract.

Assurance evidence is increasingly a procurement prerequisite rather than a nice-to-have, and the practical form it takes is a question set derived from the CAF outcomes relevant to the system you provide. Being able to answer at outcome level, with evidence, is what wins these.

This is why a certificate alone is a weak answer. ISO 27001 tells a department that you run a management system. It does not tell them whether outcome C1 is achieved for the specific service they are buying. The gap between those two things is where most supplier responses fall down.

If you are outside the UK

The CAF is a UK framework and will be unfamiliar even to organisations with mature security programmes, because it is not an international standard and does not map cleanly onto one. The underlying practices are recognisable. The structure, the vocabulary and the achieved or partially achieved rating scale are not.

Nothing prevents an overseas supplier from evidencing CAF outcomes. What tends to slow it down is that the evidence is expected in a particular shape, and a response written in the language of SOC 2 criteria or ISO Annex A controls does not answer the question that was asked.

The efficient approach is to map your existing control evidence onto the CAF outcomes once, properly, and keep that mapping current. It is reusable across every UK public sector opportunity you pursue, and across NHS work as well now that the toolkit is CAF-aligned.

How we help

Mostly by translation. Organisations with ISO 27001 or SOC 2 already do most of what the CAF asks about, and the work is expressing that in outcome terms, finding where the evidence genuinely does not exist, and being honest about which outcomes are partially achieved rather than claiming otherwise and being corrected at review.

For suppliers, the durable asset is a CAF-mapped evidence pack that answers at outcome level and can be reused across bids. For departments and arm's length bodies, the useful work is a pre-assessment before stage three, so the independent review at stage four finds what you expected it to find.

Related services

Talk to an engineer

We respond to every enquiry within one business day, and return a scoped proposal with fixed pricing within 48 hours.

Book a discovery call