NCSC CAF Copilot
Specialist AI guidance for the UK Cyber Assessment Framework
What the NCSC CAF Copilot Can Do
CAF 4.0 structure: 4 objectives and 14 principles
Contributing-outcome titles and evidence-list drafting from your notes
Preparation against supplied CAF requirements (IGP wording is not in the knowledge pack)
UK NIS Regulations 2018 context: appropriate measures, not a CAF certificate
Risk management and security governance document drafting
Cross-mapping between CAF outcome titles and ISO 27001 controls
About NCSC CAF Copilot
NCSC CAF Copilot helps UK teams work the Cyber Assessment Framework as a structure: 4 objectives, 14 principles, and 41 contributing-outcome titles. It drafts from requirements you supply. It does not score Indicators of Good Practice or issue a CAF assessment.
Who it's for
ISO 27001
Maps cleanly to CAF outcome titles. Many operators use ISO 27001 as the implementation backbone.
Cyber Essentials
The earlier five-theme baseline, often a procurement gate before CAF-shaped evidence.
UK NIS Regulations 2018
The UK law. CAF is the assessment framework used with it, not an EU NIS 2 transposition.
Cross-framework mappings
Working across NCSC CAF and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.
Browse free mappingsFrequently Asked Questions
What is the NCSC CAF Copilot?
The NCSC CAF Copilot is an AI assistant that helps UK organisations navigate the NCSC Cyber Assessment Framework structure (objectives, principles, contributing-outcome titles). UK NIS Regulations 2018 require appropriate and proportionate measures. Competent authorities use CAF in that context. The Copilot does not score IGPs or run a GovAssure assessment.
Who uses the CAF?
Operators of essential services and relevant digital service providers under the UK NIS Regulations 2018, and organisations whose contract or GovAssure process asks for CAF evidence. CAF is an assessment framework, not a certification scheme.
How does CAF relate to ISO 27001?
CAF is outcome-based while ISO 27001 is control-based. Organisations with ISO 27001 often have a head start documenting CAF outcomes. The Copilot maps ISO 27001 controls to CAF's 41 contributing-outcome titles. It does not claim that ISO 27001 equals CAF compliance.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
