Frameworks · UK & Europe
NCSC Cyber Assessment Framework compliance, run as a living system
The UK's Cyber Assessment Framework sets out cyber security outcomes across four objectives, each assessed against indicators of good practice rather than a binary control checklist. It underpins oversight of essential services and is widely adopted for critical functions.
Who it applies to
Operators of essential services, relevant digital service providers, and organisations adopting the framework for critical functions and supply-chain assurance.
What it demands
Managing security risk
Governance, risk management, asset management and supply-chain assurance.
Protecting against attack
Service protection policies, identity and access, data and system security, resilient networks and staff awareness.
Detecting events
Security monitoring and proactive discovery of anomalous activity.
Minimising impact
Response and recovery planning, and lessons learned feeding back into the programme.
How Compli-Once runs it
- 1
Outcomes and their indicators modelled as assessable items, so profiles are computed rather than authored in a document.
- 2
Achieved, partially achieved and not achieved states roll up per objective, each drilling to its evidence.
- 3
Crosswalked to ISO 27001 and NIST SP 800-53 so an existing programme starts from measured coverage.
What you already satisfy
NCSC Cyber Assessment Framework overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.
Implement once, satisfy many
In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.
Illustrative, computed live per tenant in the platform.
Frequently asked questions
What is the Cyber Assessment Framework?
It is the UK's outcome-based cyber assessment framework, structured into four objectives and assessed against indicators of good practice rather than a binary checklist.
How are outcome states reported?
Each contributing outcome carries an achieved, partially achieved or not achieved state computed from control evidence, rolling up by objective for reporting.
Does it work with ISO 27001?
Yes. Indicators are crosswalked to ISO 27001 and NIST, so existing implementations are counted before any new work is planned.
Can profiles be tracked over time?
Yes. Assessment history is retained, so improvement between reporting periods is evidenced rather than asserted.
