IT Audit Factory — evidence-first audit & compliance operations
Free • Professional • MSP
Frameworks & Controls

NCSC Cyber Assessment Framework 4.0

41 contributing outcomes across 14 principles with published Not Achieved, Partially Achieved where present, and Achieved indicator guidance

All available frameworks

What the app checks

Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.

Explicit requirement-to-test mappings

RequirementCollector / testWhat it checks or supports
A3.aWINDOWS / WIN-INVENTORY-COVERAGE-001Supporting observation only. Independently verify target-level time limits, population, enforcement, approved exceptions or CAF essential-function context and expert conclusion. No maturity or CAF achievement rating from a scan.
B2.aENTRA / ENTRA-MFA-REG-001Supporting observation only. Independently verify target-level time limits, population, enforcement, approved exceptions or CAF essential-function context and expert conclusion. No maturity or CAF achievement rating from a scan.
B2.cADSEC / AD-PRIV-001Supporting observation only. Independently verify target-level time limits, population, enforcement, approved exceptions or CAF essential-function context and expert conclusion. No maturity or CAF achievement rating from a scan.
B2.dENTRA / ENTRA-GUEST-001Supporting observation only. Independently verify target-level time limits, population, enforcement, approved exceptions or CAF essential-function context and expert conclusion. No maturity or CAF achievement rating from a scan.
B3.bCERTTLS / CERTTLS-POSTURE-001Supporting observation only. Independently verify target-level time limits, population, enforcement, approved exceptions or CAF essential-function context and expert conclusion. No maturity or CAF achievement rating from a scan.
B3.cSTORAGE / STOR-AT-REST-ENCRYPTION-001Supporting observation only. Independently verify target-level time limits, population, enforcement, approved exceptions or CAF essential-function context and expert conclusion. No maturity or CAF achievement rating from a scan.
B4.aWINDOWS / WIN-FW-001Supporting observation only. Independently verify target-level time limits, population, enforcement, approved exceptions or CAF essential-function context and expert conclusion. No maturity or CAF achievement rating from a scan.
B4.bWINDOWS / WIN-SMB1-001Supporting observation only. Independently verify target-level time limits, population, enforcement, approved exceptions or CAF essential-function context and expert conclusion. No maturity or CAF achievement rating from a scan.
B4.dVULN / VULN-IMPORT-001Supporting observation only. Independently verify target-level time limits, population, enforcement, approved exceptions or CAF essential-function context and expert conclusion. No maturity or CAF achievement rating from a scan.
B5.cBACKUP / VEEAM-REPO-001Supporting observation only. Independently verify target-level time limits, population, enforcement, approved exceptions or CAF essential-function context and expert conclusion. No maturity or CAF achievement rating from a scan.

What requires manual review

Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.

Evidence preparation with expert judgement and sector context; generic ITAF review status is not an official CAF achievement rating. Record the CAF conclusion and rationale in the observed result. Contains public sector information from NCSC CAF 4.0, Crown copyright 2025, licensed under the Open Government Licence v3.0: https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/. Text reformatted; ITAF evidence actions and mappings added. No NCSC endorsement.

Where it is available

This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.

Coverage shown here comes from the application’s C32 requirement and mapping catalogs.