Frameworks · UK & Europe

NCSC Cyber Assessment Framework compliance, run as a living system

The UK's Cyber Assessment Framework sets out cyber security outcomes across four objectives, each assessed against indicators of good practice rather than a binary control checklist. It underpins oversight of essential services and is widely adopted for critical functions.

Who it applies to

Operators of essential services, relevant digital service providers, and organisations adopting the framework for critical functions and supply-chain assurance.

What it demands

Managing security risk

Governance, risk management, asset management and supply-chain assurance.

Protecting against attack

Service protection policies, identity and access, data and system security, resilient networks and staff awareness.

Detecting events

Security monitoring and proactive discovery of anomalous activity.

Minimising impact

Response and recovery planning, and lessons learned feeding back into the programme.

How Compli-Once runs it

  • 1

    Outcomes and their indicators modelled as assessable items, so profiles are computed rather than authored in a document.

  • 2

    Achieved, partially achieved and not achieved states roll up per objective, each drilling to its evidence.

  • 3

    Crosswalked to ISO 27001 and NIST SP 800-53 so an existing programme starts from measured coverage.

What you already satisfy

NCSC Cyber Assessment Framework overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.

Implement once, satisfy many

Access control
ISO 27001 A.5.15SOC 2 CC6.1SEBI CSCRF PR.AARBI CSF Access Mgmt
Incident response
ISO 27001 A.5.24SOC 2 CC7.3SEBI CSCRF 6-hour report
Change management
ISO 27001 A.8.32SOC 2 CC8.1PCI DSS v4 6.5

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.

Illustrative, computed live per tenant in the platform.

Frequently asked questions

What is the Cyber Assessment Framework?

It is the UK's outcome-based cyber assessment framework, structured into four objectives and assessed against indicators of good practice rather than a binary checklist.

How are outcome states reported?

Each contributing outcome carries an achieved, partially achieved or not achieved state computed from control evidence, rolling up by objective for reporting.

Does it work with ISO 27001?

Yes. Indicators are crosswalked to ISO 27001 and NIST, so existing implementations are counted before any new work is planned.

Can profiles be tracked over time?

Yes. Assessment history is retained, so improvement between reporting periods is evidenced rather than asserted.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.