The NCSC Cyber Assessment Framework — the CAF — was written for operators of nationally important systems, not schools. So why are multi-academy trusts increasingly being asked about it? This guide explains what the CAF actually is, its four objectives in plain English, and how to approach it sensibly without a security team.
What is the NCSC CAF?
The Cyber Assessment Framework is published by the National Cyber Security Centre (part of GCHQ). It is an outcome-based framework: rather than a tick-box list of controls, it describes what good cyber resilience looks like and asks you to show how you achieve it. It is organised into four objectives, broken into fourteen principles, each assessed against "indicators of good practice".
It was designed for critical national infrastructure and, more recently, central government (through the GovAssure programme). Schools are not formally in scope — but the CAF has become a common language for cyber resilience across the public sector, which is why trust boards, auditors and insurers increasingly reference it.
Why are schools and MATs being asked about it?
- Trusts are maturing. As a MAT grows, "we have antivirus" stops being a good enough answer to a governor's question. The CAF gives a grown-up structure to the conversation.
- It aligns with the DfE standards. The DfE Digital & Technology Standards draw on the same NCSC thinking, so CAF work and DfE work reinforce each other.
- Insurers and auditors like it. A recognised framework is easier to evidence against than an ad-hoc description of "what we do".
The four objectives, in plain English
Objective A — Managing security risk
Do you understand and govern your cyber risk? This covers leadership and governance, risk management, knowing what assets and data you hold, and managing the risk from your suppliers (including your IT provider and cloud platforms).
Objective B — Protecting against cyber attack
The controls most people picture: identity and access management (including MFA), data security, keeping systems patched and configured well, resilient networks, and — crucially — staff awareness and training. This is the largest objective.
Objective C — Detecting cyber security events
If something goes wrong, would you notice? This is about monitoring your systems and being able to spot the signs of an attack — the area schools most often have a blind spot in.
Objective D — Minimising the impact of incidents
When (not if) an incident happens, can you respond and recover? This covers having a tested response plan, the ability to restore from backups, and learning lessons afterwards.
How to approach the CAF without a security team
- Start with a baseline, not perfection. Honestly rate each principle Achieved / Partial / Not. The map itself is the value.
- Reuse what you already have. Cyber Essentials, your DfE standards work and your incident plan all map onto CAF principles — you are not starting from zero.
- Prioritise by risk. Fix "Not achieved" items that protect your most important data and services first.
- Make it a rhythm. Re-assess on a schedule and report the trend to governors, so cyber resilience becomes routine oversight.
Making the CAF manageable
The CAF is genuinely useful — but for a busy school it can feel abstract. Ceidwad brings the same objectives into a single readiness view, cross-maps them to the DfE standards and Cyber Essentials so you evidence once, and turns the gaps into a plain-English, prioritised action list your governors can follow. Recognised structure, without the security team.