NCSC CAF 4.0 · AI-POWERED · 41 OUTCOMES

CAF
assessment
reinvented.

CAFtrack is an AI agent trained on the NCSC CAF 4.0 framework. It analyses your security documentation against all 41 contributing outcomes, identifies compliance gaps, asks targeted clarifying questions, and generates a structured self-assessment report.

41
CAF 4.0 outcomes
4
Principles assessed
<2h
Time to report
AI
Agent trained on CAF 4.0
41

All four CAF 4.0 principles

Every contributing outcome across all principles fully assessed by an AI agent trained on the NCSC CAF 4.0 framework, with targeted clarifying questions where evidence is missing.

A
Managing Security Risk
9 contributing outcomes
B
Protecting Against Cyber Attack
20 contributing outcomes
C
Detecting Cyber Security Events
7 contributing outcomes
D
Minimising the Impact of Incidents
5 contributing outcomes
ASSESSMENT TOOL
Upload. Assess. Report.

Drop in your security documents. The AI assessor works through all 41 CAF 4.0 contributing outcomes.

CAF 4.0 Assessor BETA
Early-access beta. Please do not upload real security documents use example content only. Not approved for formal CAF submissions.
Drop documents here or click to browse
.txt · .md · .pdf policies, risk registers, audits
I understand this is an MVP not for regulatory or formal use, and I will not upload real organisational documents.
CAF Assessor
Assessment Report
Outcome Tracker
AWAITING ASSESSMENT
0 / 41 assessed
Achieved
Partial
Not achieved
Unclear
EXAMPLE DOCUMENT CONTENT
Information Security Policy v1.0
Organisation: Example Infrastructure Ltd

Governance: The CISO has board-level accountability for
cyber security. Roles and responsibilities are documented
and communicated to all staff. Policy is reviewed annually.

Risk: Cyber risks are identified and assessed quarterly.
An asset register is maintained and reviewed regularly.
Third-party suppliers are assessed before onboarding.

Access: Multi-factor authentication is enforced for all
privileged accounts. Access rights are reviewed every
quarter and removed promptly when staff leave.

Data: Data is encrypted at rest and in transit. A data
classification policy is in place and staff are trained
on handling sensitive information.

Incident: An incident response plan exists and is tested
annually via a tabletop exercise. Incidents are reported
to the ICO within 72 hours where required.

Monitoring: A SIEM platform monitors network activity
24/7. Logs are retained for 12 months and protected
from tampering.

Save as .txt and upload to test the assessment flow.

PROCESS
Three steps to a full
CAF 4.0 assessment.
01

Upload your documents

Drop in your security policies, risk registers, audit reports, and incident procedures. Supported formats include PDF and plain text.

02

AI analyses the evidence

The AI agent maps your documentation to each of the 41 CAF 4.0 contributing outcomes. Trained specifically on the NCSC CAF 4.0 framework, it asks targeted questions where evidence is missing or ambiguous.

03

Receive your CAF report

A structured report showing Achieved, Partially Achieved, Not Achieved, or Insufficient Evidence for every outcome with reasoning, ready to print or share.

CAPABILITIES
Built for
real assessments.

Not a checklist. An intelligent assessor that reads your evidence, reasons over it, and asks exactly the right questions when something is missing.

Evidence-based reasoning

Reads your actual documents and maps specific content to CAF outcomes genuine comprehension, not keyword matching.

Targeted clarifying questions

When evidence is absent or ambiguous, CAFtrack asks precise, outcome-specific questions rather than defaulting to fail.

Full 41-outcome coverage

Every contributing outcome across all four CAF 4.0 principles governance, protection, detection, and response.

Powered by leading AI

Built on state-of-the-art large language models, CAFtrack uses the same AI technology trusted by organisations worldwide to reason over complex documents.

Hours, not weeks

Compress the evidence review phase from weeks of consultant time down to hours.

Printable report

A structured per-outcome report with verdicts and reasoning, ready to present to your Competent Authority.

WHO IT'S FOR
Built for UK cyber
professionals.

Cybersecurity Analysts

Assess your security posture against CAF 4.0 and surface gaps before a formal Competent Authority review.

IT Managers

Understand where your systems and processes stand against CAF requirements without needing an external consultant.

Compliance Officers

Map existing policies and controls to CAF contributing outcomes and track your compliance position over time.

Risk Professionals

Integrate CAF outcomes into your risk register and evidence your risk treatment approach to regulators.

BETA STATUS
We're in
early access.

CAFtrack is currently an early-access product. We're validating the AI-assisted assessment approach with security professionals before building the full production platform.

Your feedback shapes what we build next.

⚠ BETA LIMITATIONSThis beta is for evaluation with example content only. Do not upload real organisational security documents. CAFtrack is not approved for formal CAF submissions or regulatory use at this stage.
  • Full 41-outcome CAF 4.0 assessment flow
  • Document upload and AI evidence analysis
  • Targeted clarifying questions per outcome
  • Structured pass/partial/fail report
  • AI agent trained on the NCSC CAF 4.0 framework
  • Multi-user workspace (coming soon)
  • Evidence tagging and audit trail (coming soon)
  • Competent Authority export format (coming soon)
  • UK-hosted secure deployment (coming soon)

Stay in the loop.

Register your interest and be first to know when CAFtrack launches for production use. No spam just updates when it matters.

No spam. Unsubscribe at any time.

You're on the list we'll be in touch when CAFtrack is ready.

Start your CAF 4.0
assessment today.

Free. No account required. Results in under two hours.