ComplianceBack to Blog

Cyber Security and Resilience Bill: CAF Readiness Guide

The Cyber Security and Resilience Bill (CSRB) leaves most technical detail to secondary legislation, so what should in-scope organisations do now? Start with the NCSC Cyber Assessment Framework (CAF v4.0). This guide walks through the CAF's four objectives and 14 principles, how to run a baseline self-assessment, and how each part maps to the Bill's incident reporting, supply chain and risk management duties.

Precursor Security
2 September 2026
7 min read
1,300 words

Precursor Security

Precursor Security is a UK-based penetration testing and offensive security testing company with 24/7 security operations centres. We are CREST certified in both penetration testing and security operations, providing comprehensive cyber security services to help organisations achieve regulatory compliance and enhance their security posture.

Share:

How to Prepare for the Cyber Security and Resilience Bill Using the NCSC Cyber Assessment Framework

The Cyber Security and Resilience Bill (CSRB) does not, on its own, hand you a checklist. Like the Network and Information Systems (NIS) Regulations it updates, the Bill sets out duties and enforcement powers, then leaves most of the technical detail to secondary legislation and codes of practice that will follow Royal Assent. That creates a practical problem for the organisations it brings into scope: what, concretely, are you supposed to be doing now, while the substantive duties are still being written?

For most in-scope organisations the answer is already published, and it is not part of the Bill at all. It is the NCSC's Cyber Assessment Framework (CAF) - the outcome-based framework the government uses to judge whether an operator of essential services is genuinely resilient. If you want a head start on CSRB compliance that will not be wasted whatever the final regulations say, the CAF is where to start.

Why the Cyber Security and Resilience Bill points to the CAF

The Cyber Security and Resilience Bill widens the existing NIS regime rather than replacing its architecture. Operators of essential services, qualifying managed service providers, in-scope data centres and designated critical suppliers all inherit a version of the same core obligation: take appropriate and proportionate measures to manage the risks to the security of your network and information systems, and report significant incidents.

"Appropriate and proportionate" is deliberately outcome-based language, and the CAF is the government's chosen way of assessing it. The public sector already works this way: through the GovAssure programme, government departments assess themselves against the CAF, and the framework is the reference point NCSC and sector regulators use when they judge cyber resilience. Nothing in the direction of travel suggests the regulators charged with the CSRB - Ofcom is confirmed as the sole regulator for data centres, alongside the existing sector regulators - will abandon that shared language. Preparing against the CAF is therefore the lowest-regret move available while the detailed changes are finalised.

What the Cyber Assessment Framework actually is

The CAF is structured around four top-level security objectives, broken down into 14 principles:

  • Objective A - Managing security risk: governance (A1), risk management (A2), asset management (A3) and supply chain (A4). Knowing what you run, why it matters and who else can reach it.
  • Objective B - Protecting against cyber attack: service protection policies and processes (B1), identity and access control (B2), data security (B3), system security (B4), resilient networks and systems (B5) and staff awareness and training (B6).
  • Objective C - Detecting cyber security events: security monitoring (C1) and proactive security event discovery (C2).
  • Objective D - Minimising the impact of incidents: response and recovery planning (D1) and lessons learned (D2).

Each principle is assessed against a set of Indicators of Good Practice (IGPs), and each outcome is rated Achieved, Partially Achieved or Not Achieved rather than scored as a percentage. It is a maturity picture, not a tick-box audit - which is exactly why it maps onto the Bill's "appropriate and proportionate" test better than a certificate does.

The current version, CAF v4.0, was published by the NCSC in August 2025 and is the most significant revision since the framework was introduced in 2018. It adds over 100 new indicators of good practice and sharpens several areas that matter directly for CSRB duties: a stronger focus on understanding attacker methods and motivations, a new emphasis on securing the software used to deliver essential services, expanded coverage of security monitoring and threat hunting, and improved treatment of AI-related risk throughout. If you assessed against an earlier version, treat v4.0 as a fresh baseline, not a minor update.

A CAF-based readiness roadmap

You do not need to wait for the regulations to start. Work through these steps in order.

  1. Confirm whether you are in scope, and against which duties. Scope, thresholds and sector determine which obligations apply. Start with what the Bill is and the who is affected guidance, then decide whether you are being brought in as an operator of essential services, a relevant digital service provider, a managed service provider or a critical supplier - the emphasis differs.
  2. Run a baseline CAF self-assessment. Rate every one of the 14 principles Achieved, Partially Achieved or Not Achieved against the v4.0 indicators, honestly. The goal at this stage is an accurate map of where you are, not a flattering one.
  3. Prioritise by duty, not by objective order. The Bill's hardest new edges are incident detection and reporting, so weight Objectives C and D first if that is where your gaps sit. A strong governance story (Objective A) that cannot actually detect an incident will not satisfy a reporting duty.
  4. Fix the gaps that carry statutory consequences first. A Not Achieved outcome under security monitoring is a compliance risk the moment a reporting duty commences; a partially achieved governance indicator is a slower-burn issue. Sequence remediation accordingly.
  5. Gather evidence as you go. Regulators assessing CAF outcomes want demonstrable practice, not policy documents alone - logs, exercise records, tested runbooks. Build the evidence trail now so an inspection is a retrieval exercise, not a scramble.
  6. Cost it and put it in front of the board. Closing CAF gaps has a real budget line, and so does regulator charging under the regime - our cost recovery explainer sets out how that works. Fund it across the next two financial years rather than discovering the number the week a duty commences.

Where the CAF maps to specific CSRB duties

The value of the CAF is that its principles line up with the Bill's headline obligations:

  • Incident reporting. The Bill's 24-hour initial notification and 72-hour full-report expectation depend entirely on Objective C. You cannot report within 24 hours what your monitoring did not detect. The related near-miss reporting duty, which goes beyond both the current NIS Regulations and the EU's NIS2, leans even harder on C1 and C2.
  • Supply chain. Principle A4 is the CAF's answer to the Bill's expanded focus on managed service providers and critical suppliers. If you rely on third parties for essential services, A4 is where you demonstrate you have assessed and managed that dependency - and it is the groundwork you will need if the Government's proposed vendor-related direction powers over risky suppliers are enacted.
  • Risk management and governance. Objective A is the framework's expression of the "appropriate and proportionate measures" duty at the heart of the Bill.
  • Response and recovery. Objective D is where you show you can minimise disruption and learn from it - the resilience half of the Bill's name.

Common gaps to fix now

Across in-scope sectors, the same weak spots recur. Security monitoring that covers the corporate network but not operational technology or cloud-hosted services. Asset inventories that are months out of date, so you cannot say what is exposed. Incident response plans that have never been exercised end to end against a realistic scenario. Supply chain assurance that stops at a signed questionnaire. Each of these is a Partially Achieved or Not Achieved outcome waiting to become a compliance finding once the duties bite.

None of this depends on the final wording of the regulations, which is the point. The Bill completed its Commons stages and passed to the Lords in June 2026; Lords Committee Stage began on 1 September 2026, Royal Assent is expected in late 2026, and the substantive duties are then expected to be phased in through secondary legislation, following the DSIT implementation consultation, towards 2028. That timeline reads as generous until you measure it against how long it takes to stand up continuous monitoring or re-architect a supply chain assurance process. Starting from the CAF now converts that window into preparation time. For the full picture of the obligations, see our definitive analysis of the Bill and track its progress.

This article draws on the NCSC's Cyber Assessment Framework guidance and the CAF v4.0 release (published August 2025, ncsc.gov.uk), corroborated by independent CAF v4.0 analyses from Bridewell, Huntsman Security and others; the CAF's four objectives and 14 principles are set out in NCSC and security.gov.uk guidance. The Bill's stage (Lords Committee Stage, which began on 1 September 2026) is confirmed on the UK Parliament page for HL Bill 32 (bills.parliament.uk/bills/4035). Position as of 2 September 2026.

Tags:
CSRBcyber securityUK legislationcomplianceCyber Assessment FrameworkCAFCAF v4.0NCSCGovAssureincident reportingnear-miss reportingsupply chainNISHL Bill 32managed service providersoperators of essential services
Last updated: 2 September 2026
Share:

You Might Also Like

Explore more insights and guidance on the Cyber Security and Resilience Bill.

Precursor Security
3 Jul 2026

UK Cyber Breaches Survey 2026: The Cyber Security and Resilience Bill Compliance Gap

DSIT's Cyber Security Breaches Survey 2025/2026 put 43% of UK businesses on the wrong end of a breach. The more revealing numbers sit beneath that headline: only 40% told anyone outside the organisation, and only 25% hold a formal incident response plan. Here is what that gap means once the Cyber Security and Resilience Bill (CSRB) makes 24/72-hour reporting a legal duty.

CSRBcyber security+12 more
Read Article
Precursor Security
28 Jul 2026

The Cyber Security and Resilience Bill Skills Gap: Can UK Firms Resource the New Duties?

A new think-tank report warns the Cyber Security and Resilience Bill (CSRB) risks becoming a "paper tiger" unless the UK's cyber skills shortage is addressed. With 49% of businesses and 58% of government bodies reporting a basic skills gap, the people needed to run 24/72-hour reporting and ongoing risk management may not be there. Here is what in-scope organisations should do about it before the duties commence.

CSRBcyber security+14 more
Read Article
Precursor Security
22 Jul 2026

Lords Complete Cyber Security and Resilience Bill Second Reading: Key Themes and Committee Stage on 1 September

The Lords gave the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, cross-party support at Second Reading on 14 July 2026 without calling a division - but they put five pointed themes on the record, from the public sector exemption to the Bill's total silence on AI. Committee Stage begins on 1 September, and those themes are the working agenda. Here is what each one means for in-scope organisations.

CSRBcyber security+19 more
Read Article