
OUTCOME-BASED ASSURANCE, APPLIED WHERE IT ACTUALLY HELPS.
Who this is for
We are direct about this, because CAF is frequently misapplied in this region.
The NCSC Cyber Assessment Framework has no regulatory force in the GCC. NCSC holds no regulatory responsibility, and CAF's authority derives from the UK regulators that adopt it. If you are a GCC entity with no UK or EU nexus, your obligations are to NCA ECC-2:2024, the UAE Information Assurance Standard v2, SAMA, or your sectoral regulator — and CAF is not a substitute for any of them.
This service is for four situations:
UK and EU firms delivering into the Middle East. Your methodology is CAF-based; your CAF-fluent architects are UK-based. Every regional engagement carries mobilisation cost and a time-zone gap.
MEA subsidiaries of UK or EU parents. Group-level CAF, NIS2 or DORA obligations cascading to Gulf operating entities.
Organisations with UK critical national infrastructure exposure. Where a UK regulator's expectations reach your operations.
Organisations that want a better assessment instrument. CAF's outcome-based structure produces materially better findings than control-checklist scoring — and we use it as our internal assessment engine while reporting against whichever framework you are accountable to. This is the largest use case in our regional practice.
What CAF v4.0 is
Version 4.0 was released on 4 August 2025. Its top-level structure was unchanged from v3.2: four objectives, fourteen principles, thirty-nine contributing outcomes, assessed against Indicators of Good Practice.
Four objectives: A — Managing security risk · B — Protecting against cyber attack · C — Detecting cyber security events · D — Minimising the impact of incidents
What changed in v4.0 was the content, substantially. The NCSC highlighted four major updates:
Deeper understanding of attacker methods and motivations. Assessment is pushed toward considering attacker capability and intent explicitly, rather than assessing controls in the abstract. A control is not adequate because it exists — it is adequate relative to a specific adversary.
Secure software development and maintenance. New and expanded coverage, reflecting where a large share of consequential compromise now originates.
Stronger security monitoring and threat hunting. A substantial refresh, with much greater emphasis on behavioural monitoring and proactive hunting. Signature-based detection no longer demonstrates the outcome.
Broader AI-related cyber risk coverage. Strengthened across the framework.
The AI gap — and why it matters here
That last change opened a gap that matters in the Gulf more than in the UK.
Look at the regional frameworks. NCA ECC-2:2024. The UAE Information Assurance Standard v2. SAMA's Cyber Security Framework. All credible instruments. None was drafted with generative AI or autonomous agents as a primary consideration.
Meanwhile, GCC governments are pursuing sovereign AI capability at a scale and pace few regions match.
So there is a structural lag. Organisations across the Gulf are deploying AI systems faster than the frameworks that govern them can be revised — not through carelessness, but because framework revision runs in years while AI deployment runs in months.
Which means that for AI systems in this region right now, "we are compliant" and "we have assessed this risk" are different statements.
Three things we recommend in the interim:
Use CAF v4.0's AI treatment as reference material. It carries no regulatory force here, but it is public, credible, and written by a national technical authority.
Adopt ISO/IEC 42001 as your management-system anchor. It is auditable and gives your board something concrete.
Threat-model your AI systems specifically, using the OWASP Top 10 for LLM Applications and MITRE ATLAS. Your existing STRIDE process will not surface prompt injection or training-data poisoning, because it was not designed to.
OUR APPROACH
-
Establish scope and essential functions. CAF assesses the security of essential functions, not the whole organisation. Getting the essential-function definition wrong invalidates the assessment. This is where most CAF exercises go wrong at the start.
-
Build a threat-informed baseline. In line with v4.0's emphasis, we establish which threat actors are relevant, their realistic capability and intent, and assess controls against that — not against a generic adversary.
-
Assess against contributing outcomes, referenced to Indicators of Good Practice. Achieved, partially achieved, or not achieved, with the evidence and the IGP commentary that supports the judgement.
-
Address the v4.0 content changes explicitly. Secure software development. Threat hunting and behavioural monitoring. AI-related cyber risk. Most CAF assessments in this region will not cover these, because they were built on v3.2 habits.
-
Map to your actual regulatory obligations. Where your accountability is to NCA, the UAE Cyber Security Council, SAMA or a sectoral regulator, we report against those frameworks natively — using CAF's outcome logic as the assessment engine underneath.
-
Produce a dependency-ordered roadmap. Sequenced by what gates what, not by what is easiest to close first.
ENGAGEMENTS
CAF-01 CAF v4.0 Assessment
Typical duration: 15-25 days
Full assessment across four objectives and thirty-nine contributing outcomes, referenced to IGPs
CAF-02 CAF Readiness Review
Typical duration: 8-15 days
Gap assessment ahead of a formal or regulator-facing CAF assessment
CAF-03 v3.2 to v4.0 Transition Review
Typical duration: 6-12 days
Delta assessment against the four v4.0 content changes, for organisations previously assessed to v3.2
CAF-04 CAF Methodology Adoption
Typical duration: 10-18 days
Implementing CAF's outcome-based approach as your internal assessment method, reporting against your own regulators
CAF-05 Essential Function Scoping
Typical duration: 3-6 days
Standalone essential-function definition and scoping workshop
CAF-06 AI Risk Assessment (CAF-informed)
Typical duration: 10-18 days
AI system risk assessment using CAF v4.0's AI treatment, ISO/IEC 42001, OWASP LLM Top 10 and MITRE ATLAS
FRAMEWORKS AND MAPPING
Primary: NCSC CAF v4.0 (four objectives, fourteen principles, thirty-nine contributing outcomes)
Mapped to: NCA ECC-2:2024 · UAE Information Assurance Standard v2 · SAMA Cyber Security Framework · NIST CSF 2.0
Related: NIS2 · DORA for financial entities with EU exposure · ISO/IEC 42001 · MITRE ATT&CK · MITRE ATLAS
We publish the crosswalk mapping CAF v4.0 to NCA ECC-2:2024, the UAE Information Assurance Standard v2 and NIST CSF 2.0 — free and ungated.
