The UK’s National Cyber Security Centre is updating its Cyber Assessment Framework, providing extra guidance for critical national infrastructure.
The Cyber Assessment Framework was last updated in April 2024 and is now used by nearly all cyber regulators, as well as GovAssure, the cybersecurity assurance scheme for the UK’s critical national infrastructure (CNI).
The CAF mainly serves to provide CNI across sectors with a comprehensive framework for assessing their security and resilience needs and outcomes to protect against threats.
Despite successful update of the CAF, the threat risk to the UK’s CNI has only increased, and keeping pace with complicated attack methodology is essential to closing the gap between escalating cyber threats and security defence posture.
The NCSC has therefore updated the CAF in an attempt to ensure that the framework remains relevant as CNI organisations try to protect themselves from rising threats.
Version 4.0 of the framework will have four major changes.
First, it will feature a new section dedicated to building a deeper understanding of attacker methods and motivations in an effort to inform better cyber risk decisions.
Recommended reading
- UK Cybersecurity Budgets Set to Surge Over 30% in 2025
- Report: Cybersecurity Fears Grow for Critical National Infrastructure
- Cyber Leaders Reveal Compliance and Boardroom Struggles
The update will also have a new section focused on ensuring the secure development and maintenance of software used in essential services.
The existing section on security monitory and threat hunting will be updated to improve cyber threat detection.
The CAF will also have improved coverage of AI cyber risks.
The NCSC says that it has consulted with cyber regulators and oversight bodies on the updates to th framework, which mainly serves critical national infrastructure such as energy, healthcare, transport, digital infrastructure and government sectors.
“We are already looking ahead to future iterations of the CAF, ensuring that it keeps pace with the regulatory proposals within the Cyber Security and Resilience Bill, which will be laid before parliament later this year,” the NCSC said.





