The NCSC Cyber Assessment Framework asks whether your organisation achieves outcomes — not whether you bought a tool. Boards like CAF because it sounds like English. Suppliers like CAF because they can print the letters on a slide. The test is whether the evidence is real.
What a pentest can support
CAF objectives around identifying attack surface, protecting critical functions, detecting incidents (sometimes), and minimising impact of a compromise. A good pentest produces: an asset map you did not have, proven access-control failures, and a prioritised fix list.
What a pentest cannot be
It is not a CAF assessment. It is not an audit of your governance, training, supply chain or incident-response playbooks. If a report claims “CAF compliant” after five days on a web app, throw it away.
How VAPT.UK maps findings
Each finding can carry an optional CAF objective identifier where the mapping is honest (for example, a broken tenant isolation finding supports evidence against protecting data in your service). Where we did not test an objective, the report says “not covered.” That sentence is the one a capable reviewer looks for.
For operators of essential services
If you are in scope for NIS / the UK’s equivalent duties, CAF is probably already in your language. Bring the profile you are assessed against to the scoping call. We will tell you which parts a pentest can feed and which parts need your GRC team.
Need this as an engagement, not an article?
UK hours. GBP quote. Written CMA 1990 authorisation.
Request a pentest