complianceuk-caf-v4-gap-analysiscyber-assessment-frameworkuk-caf-compliancencsc-cafcritical-infrastructure-ukframework-gap-analysis

UK CAF v4 gap analysis: what NCSC assessors check that self-assessment misses

Sienna VanceSienna VanceApril 29, 2026
Share:
UK CAF v4 gap analysis: what NCSC assessors check that self-assessment misses

Key takeaways

  • UK CAF v4 self-assessments score Objective A (Managing Security Risk) against governance documentation. NCSC assessors evaluating the same objective request evidence that risk assessments have demonstrably influenced control selection — not that risk assessments exist and are dated.

  • The Detect pillar (Objective C) is where the largest gap between self-assessed and externally assessed maturity concentrates: organizations score themselves on monitoring capability based on tool deployment, while assessors score on demonstrated detection of the specific threat categories relevant to the organization's CNI sector.

  • CAF v4 supply chain security under Objective A requires evidence that third-party dependencies have been assessed proportionate to their access to OES networks. The evidence standard is independent verification, not completed questionnaires — a distinction that most OES supply chain programs have not operationalized.

  • Incident response evidence under Objective D must demonstrate capability under realistic conditions, not procedural completeness. An IR plan that names roles and timelines satisfies the documentation requirement. Evidence of a tabletop exercise against a scenario relevant to the organization's threat profile satisfies the assessor requirement.

  • CAF v4 Objective B (Protecting Against Cyber Attack) evidence for network security controls must cover OT and IT separately in mixed-environment CNI organizations. Assessors treating these as a single evidence category consistently find that IT-focused evidence masks OT gaps.

TL;DR

UK CAF v4 gap analysis produces different results depending on whether it starts from governance documentation or from operational evidence. Self-assessments that start from documentation find documentation gaps. Assessments that start from what NCSC assessors actually request — demonstrated detection capability, verified supply chain controls, incident response tested against realistic scenarios, OT security evidence separate from IT — find the gaps that matter. The distance between these two starting points is where CNI organizations are most exposed.

The detection capability that existed on paper

A UK water sector operator completed their CAF v4 self-assessment with a score of Achieved for Objective C (Detect). Their SIEM was deployed, log sources were documented, alerting rules were configured, and an on-call analyst rotation covered out-of-hours response. The self-assessment evidence package was substantial and internally consistent. Every indicator of good practice for the Detect pillar had a corresponding policy document or system configuration.

Turning point:

The NCSC assessor asked for evidence of detection in practice: the last five security events that generated an alert, the analyst response timeline for each, and the outcome. Three of the five events had been closed as false positives within 15 minutes without documented investigation rationale. One had been sitting in the queue for 11 days without assignment. The fifth had been escalated correctly. The SIEM was functioning. The analyst process for handling what the SIEM produced was not. The self-assessment had scored the tooling. The assessor scored the capability. These produced different results, and only one of them reflected whether the organization could detect an incident affecting its OT environment.

Why UK CAF v4 self-assessment and NCSC assessment diverge predictably

UK CAF v4 structures assessment around four Objectives — Managing Security Risk, Protecting Against Cyber Attack, Detecting Cyber Security Events, and Minimising the Impact of Incidents — each with contributing outcomes and indicators of good practice. The self-assessment process asks OES and relevant digital service providers to score themselves against these indicators and produce supporting evidence.

The structural problem is that the indicators of good practice describe controls at a level of abstraction that allows documentation to satisfy them without operational reality needing to match. An indicator that an organization has 'defined and documented processes for monitoring' is satisfied by a documented monitoring policy. Whether the monitoring process operates as documented, whether the logs it depends on are actually being ingested, whether alerts are being investigated rather than closed, and whether the analyst team has the sector-specific threat context to distinguish a relevant detection from noise — none of this is captured by the documentation that satisfies the indicator.

NCSC assessors apply a different standard. They review the self-assessment documentation and then request behavioral evidence: incident timelines, alert investigation records, supply chain assessment outputs, tabletop exercise reports. The behavioral evidence reveals whether the documented controls operate as documented. Organizations that have invested in documentation without investing in operational verification of their controls consistently find that the two evidence categories produce different pictures.

This is not a flaw in CAF v4's design. The framework's indicators of good practice are deliberately broad to accommodate the range of OES types across CNI sectors. The gap between self-assessment and external assessment is a property of any framework where self-reported compliance is the primary evidence source. What it means practically is that CAF v4 gap analysis that starts from self-assessment documentation finds documentation gaps. Gap analysis that starts from what an NCSC assessor would request finds operational gaps — the ones that matter when something goes wrong.

Example

An energy sector OES had documented their supply chain security process under Objective A with a tiered supplier questionnaire program covering all direct vendors. The self-assessment scored this as Achieved. During a gap assessment that reviewed the actual questionnaire returns, three suppliers with direct network access to SCADA systems had submitted questionnaires more than 18 months earlier with no subsequent review. One supplier's questionnaire referenced a penetration test report that had not been requested or verified as part of the questionnaire process. The self-assessment score reflected that a supply chain security process existed. The gap assessment found that the process was not producing the assurance it described.

The CAF v4 evidence standard for supply chain security under Objective A Outcome A4 requires that third-party security is managed proportionate to the risk those third parties represent. For an OES with suppliers having direct access to operational technology networks, proportionate management means independent verification of security controls, not questionnaire completion. The distinction between the two is not explicit in the framework's indicator language but is applied consistently by NCSC assessors and is the source of the most common Objective A findings in OES assessments.

What UK CAF v4 gap analysis finds in CNI environments

Assessment base: Vulnox gap analysis and CAF-aligned assessments in UK critical infrastructure, energy, water, and transport sector clients, 2023-2025

Detect pillar scores inflated by tool deployment rather than detection capability

In gap assessments covering the Detect pillar, the pattern is consistent: organizations score themselves based on whether monitoring tools are deployed and log sources are configured. NCSC assessors score based on whether the monitoring produces actionable detection of threats relevant to the organization's CNI sector. The gap between these two scoring bases concentrates in alert handling. SIEMs generating alerts that are closed as false positives without documented investigation rationale, alert queues with events aging beyond any reasonable response window, and monitoring configurations that cover IT infrastructure without equivalent coverage of OT environments all produce a tool-deployment score that significantly exceeds a capability score. The tooling is present. The operational process around the tooling is not.

Implication:

CAF v4 Objective C compliance is assessed on detection capability in practice, not detection infrastructure in principle. An OES that scores Achieved based on SIEM deployment and log source documentation and then receives an NCSC finding on detection process maturity has produced an accurate self-assessment of its infrastructure and an inaccurate self-assessment of its capability. The evidence that distinguishes these is behavioral: alert response records, investigation rationale documentation, escalation timelines against actual events. Producing this evidence requires the operational process to exist, not just the tooling.

Incident response plans that have never been tested against OT-relevant scenarios

OES incident response plans reviewed in gap assessments are typically complete as documents: roles are named, escalation paths are described, regulatory notification timelines are specified, and recovery procedures are outlined. What they consistently lack is evidence of testing against scenarios relevant to the organization's actual threat profile. A water sector operator whose IR plan has been tested against a generic phishing scenario has not tested the controls that matter for its CNI classification — the response to an event affecting SCADA systems, operational technology, or the physical process controls that underpin service delivery. The plan describes the capability. The test evidence would demonstrate it. The test evidence does not exist.

Implication:

CAF v4 Objective D (Minimising the Impact of Incidents) requires evidence of incident response capability. NCSC assessors distinguish between documented capability and demonstrated capability. A plan that has been tabletop-tested against a generic scenario and a plan that has never been tested produce similar self-assessment documentation. The assessor evidence request — tabletop exercise reports, lessons learned records, plan revision history reflecting test outcomes — reveals the difference. An OES that cannot produce test evidence for OT-relevant scenarios has a finding regardless of how complete the plan document is.

Asset management that covers IT inventory and misses OT-connected components

CAF v4 Objective A requires comprehensive asset visibility including all systems relevant to the delivery of essential services. In mixed IT/OT environments, asset inventories produced for CAF compliance consistently cover the IT environment with reasonable completeness and cover the OT environment less reliably. The OT asset gap is not usually a failure of the asset management process — it is a scope boundary that the process inherited from IT asset management tools that were not designed to enumerate OT devices. PLCs, RTUs, historian servers, engineering workstations used only in OT environments, and third-party maintenance terminals that connect periodically are absent from IT asset management platform exports. They are present in the environment and in scope for CAF Objective A.

Implication:

An asset register used to produce CAF v4 Objective A evidence that does not include OT components is an accurate record of the IT environment and an incomplete record of the CNI environment. Risk assessments built on that register make accurate decisions about IT risk and uninformed decisions about OT risk. The downstream effect on Protect and Detect pillar controls is that coverage gaps track the asset register gap — controls are deployed and monitored for the assets in the register, not for the assets in the environment.

The self-assessment score that moves in the wrong direction

Common belief

OES organizations approaching CAF v4 gap analysis expect that their highest-scoring self-assessment areas are their strongest areas. They invest remediation effort in the areas they have scored lowest, and they present their highest-scored Objectives as evidence of mature practice. The assumption is that self-assessment score tracks actual security capability.

What we found

In CAF-aligned gap assessments where we reviewed both self-assessment documentation and behavioral evidence, the Detect Objective showed the largest average gap between self-assessed and externally evaluated scores. Organizations scoring themselves at Achieved or Partially Achieved on Detect based on tool deployment frequently received findings on detection process maturity, alert handling documentation, and OT monitoring coverage that would produce a lower external score. The asset management and governance areas showed smaller gaps — self-assessed scores for Objective A were more predictive of external assessment outcomes than Detect scores.

The finding in gap assessments is that the correlation between self-assessment score and external assessment score is weakest for the Detect and Respond pillars. These are the Objectives where the evidence gap between documentation and operational reality is largest. An organization that has invested in SIEM deployment, alert rule configuration, and monitoring policy documentation will score itself highly on Detect. An assessor reviewing alert investigation records and escalation timelines against actual events will score the same organization lower if the operational process has not kept pace with the tooling investment.

The counterintuitive result is that organizations with the most mature monitoring infrastructure sometimes have the largest gap between self-assessed and externally assessed Detect scores, because mature infrastructure creates confidence that the capability is in place. The SIEM generates thousands of alerts. The team manages the alert volume by closing what looks like noise. The investigation rationale for those closures is not documented because the volume makes documentation feel impractical. The assessor sees a gap between alert volume and documented investigation rationale. The organization sees a well-managed queue.

The implication for gap analysis methodology is that starting from the lowest self-assessment scores is the wrong remediation prioritization. The correct starting point is identifying which Objectives have the largest documentation-to-operational evidence gap, regardless of self-assessment score. For most CNI organizations, that is Detect followed by Respond.

What UK CAF v4 self-assessment consistently misses

OT-specific threat intelligence integration

CAF v4 Detect pillar good practice indicators reference the use of threat intelligence to inform detection. Self-assessments interpret this as subscribing to threat intelligence feeds and integrating them with the SIEM. NCSC assessors interpret it as evidence that the threat intelligence being consumed is relevant to the organization's CNI sector and OT technology stack. Generic threat intelligence covering enterprise IT threats does not satisfy this for a water utility running Siemens SCADA or an energy operator running ABB control systems. OT-specific threat intelligence covering the vulnerability and attack patterns relevant to those specific platforms is what the indicator points to. Most OES organizations are consuming IT-focused feeds and scoring themselves as though the requirement is met.

Regulatory notification capability versus notification intent

CAF v4 Objective D requires that organizations can notify the relevant regulator within the timeframes specified under NIS Regulations. Self-assessments document the notification obligation and the named contact at the regulator. What they do not demonstrate is whether the internal process for identifying a notifiable incident and escalating to the point where notification occurs would operate within the regulatory timeframe. The 72-hour notification window under NIS starts from when the organization became aware of the incident — not when the incident occurred. An organization whose detection-to-awareness gap exceeds 72 hours cannot satisfy the notification requirement regardless of how clearly the notification obligation is documented. The documentation and the capability are different things, and gap analysis that reviews documentation produces a different finding than gap analysis that reconstructs past incident timelines.

Supply chain access path mapping beyond tier-1

CAF v4 Objective A supply chain security requirements are addressed through supplier questionnaire programs covering direct vendor relationships. The evidence standard that NCSC assessors apply for OES organizations is proportionate to the access those suppliers have to networks supporting essential services. Suppliers with direct OT network access warrant independent verification rather than completed questionnaires. Their own upstream dependencies — software component vendors, remote access platform providers, data source aggregators — have indirect access paths through the tier-1 supplier's delivery mechanisms. These paths are not in scope for questionnaire programs that stop at the direct relationship. Mapping the access path rather than the relationship is the standard the assessor applies and the evidence most supply chain programs cannot produce.

Configuration management evidence covering OT system baselines

CAF v4 Protect pillar evidence for network and system protection includes configuration management. In mixed IT/OT environments, configuration baseline documentation covers IT systems with reasonable completeness. OT system configuration baselines — PLC program versions, SCADA application configurations, engineering workstation software states — are rarely documented with the same rigor as IT system baselines, partly because OT configuration management tooling is less mature and partly because OT system changes carry operational risk that makes change management processes slower. The result is configuration evidence that satisfies the Protect pillar for the IT environment and has gaps for the OT environment. Since the OT environment is the part of the CNI organization's infrastructure that adversaries targeting critical infrastructure actually want to reach, the gap is consequential.

What OES organizations say before a CAF v4 gap assessment — and what it means

  • 'We completed the CAF self-assessment last year and our regulator accepted it. We just need to update it for v4.'

    Root cause:

    A regulator accepting a self-assessment confirms that the submission was complete and internally consistent. It does not confirm that the self-assessed scores reflect external assessment outcomes. CAF v4 introduces updated outcome language and evidence expectations compared to previous versions. Updating a v3 self-assessment to v4 by re-mapping existing evidence to new outcome language produces a v4-formatted document. Whether the evidence it contains satisfies v4 assessor expectations is a different question that the update process does not answer.

  • 'Our SIEM covers all critical systems and we have 24/7 SOC coverage. Our Detect scores should be strong.'

    Root cause:

    SIEM coverage and SOC staffing are infrastructure inputs to detection capability. They do not determine detection capability by themselves. The assessor question for Objective C is not whether monitoring infrastructure exists but whether it produces reliable detection of threats relevant to the organization's CNI sector. Alert handling processes, investigation rationale documentation, OT-specific log source coverage, and sector-relevant threat intelligence integration are the evidence categories that determine the external assessment score. Organizations with mature SIEM and SOC infrastructure frequently have gaps in the process layer that the infrastructure investment created confidence to overlook.

  • 'We have supplier questionnaires for all our vendors. Supply chain is covered.'

    Root cause:

    Questionnaire programs cover the direct vendor relationships the procurement team manages. For OES organizations, the CAF v4 supply chain evidence standard is proportionate to supplier access to essential service networks. A supplier with direct OT network access requires independent verification of their security controls — not a completed questionnaire, but evidence that their claimed controls have been verified. The questionnaire is an input to supplier assurance. The verification is the assurance. For the highest-access suppliers in an OES environment, these are not the same thing and the CAF v4 assessor distinguishes between them.

Where UK CAF v4 enforcement is heading

  1. NCSC will introduce behavioral evidence requirements as mandatory components of CAF v4 self-assessment submissions within 3 years, specifically requiring that Detect and Respond Objective scores be supported by incident timeline evidence and exercise records rather than policy documentation alone.

    The gap between self-assessed and externally assessed scores for Detect and Respond is well understood within the NCSC assessment community. As the CAF program matures and the regulator builds a larger dataset of self-assessment versus assessment outcomes, the pattern will drive methodology updates. The most direct intervention is requiring behavioral evidence for the Objectives where self-assessment is least predictive of external outcomes. This is the approach EU NIS2 implementation guidance is moving toward for incident handling evidence, and UK implementation will likely align.

    Confidence: highCAF v4 methodology updates or NIS Regulations guidance published by NCSC or DSIT between 2025 and 2028. If updated guidance does not introduce behavioral evidence requirements for Detect and Respond, this prediction is wrong on the mechanism.
  2. A UK OES organization will face NIS Regulations enforcement action where the primary finding is failure to notify within the 72-hour window, and the post-enforcement review will establish that the notification timeline obligation starts from first internal awareness rather than from incident confirmation — clarifying an ambiguity that most OES notification processes have not addressed.

    NIS Regulations enforcement on notification timelines is an emerging pattern across EU member states. UK enforcement has been slower but the regulatory framework exists and NCSC's increasing focus on incident reporting quality suggests enforcement attention will follow. The ambiguity around what constitutes 'awareness' for notification timeline purposes is real and unevenly addressed across OES organizations. An enforcement action making this explicit will produce immediate changes to detection-to-notification process design across the CNI sector.

    Confidence: mediumICO or sector regulator NIS enforcement decisions published between 2025 and 2027. If no enforcement action addresses notification timeline calculation methodology, this prediction is wrong on the enforcement focus, though the underlying ambiguity remains unresolved.

The honest problem with CAF v4 self-assessment as a compliance mechanism

CAF v4 self-assessment is the right approach for a framework covering the diversity of OES types across UK CNI sectors. A single externally assessed standard applied uniformly to water utilities, energy operators, transport providers, and digital infrastructure organizations would be neither proportionate nor practical. Self-assessment with regulatory acceptance is a reasonable compromise.

The problem is that self-assessment against indicator-of-good-practice language produces scores that are primarily predictive of documentation quality. Organizations that invest in documentation produce high scores. Organizations that invest in operational security but document less carefully produce lower scores for the same underlying capability. The score does not reliably distinguish between these.

For a compliance framework whose purpose is assuring that CNI organizations can withstand and respond to cyber attacks, a mechanism that primarily rewards documentation investment has a structural problem. The CAF's deeper intent — demonstrated capability to detect incidents affecting essential services, verified supply chain controls for OT-access suppliers, incident response tested against realistic OT scenarios — is not consistently captured by the self-assessment mechanism.

NCSC assessors close this gap when they conduct external assessments. The gap remains open for OES organizations that self-assess without external challenge, which is the majority of the CAF population.

Counterargument

The counterargument is that requiring external assessment for all OES organizations at the same rigor as current NCSC assessments would be prohibitively resource-intensive for both the regulator and the regulated organizations, particularly smaller OES entities in sectors like water and transport where the number of regulated entities is large. This is a real constraint. The proportionate response is risk-tiering: mandatory external behavioral evidence review for OES organizations in the highest-consequence sectors, with self-assessment remaining appropriate for lower-consequence entities. The current model applies the same mechanism regardless of consequence, which means the highest-risk gaps are self-assessed on the same basis as the lowest-risk ones.

Running a CAF v4 gap analysis that finds what NCSC assessors find

Commonly skipped:

Step 1 — behavioral evidence review before documentation review. CAF v4 gap analyses typically start from the self-assessment documentation and evaluate whether evidence supports the scored indicators. Starting from alert investigation records, incident timelines, and exercise outputs instead reveals whether the operational capability matches the documented capability. The two starting points find different things, and the behavioral starting point finds the gaps that matter to an NCSC assessor.

  1. 1Security or compliance lead

    Before reviewing self-assessment documentation, pull alert investigation records from the past 90 days from the SIEM or SOC ticketing system. Calculate the ratio of alerts closed without documented investigation rationale to alerts with a documented outcome. For any alert closed as false positive, check whether a rationale exists. Identify the oldest unresolved alert in the queue. These three data points tell you more about Objective C maturity than the monitoring policy document does.

    Expected outcome

    A behavioral evidence baseline for the Detect pillar that reflects operational capability rather than infrastructure deployment, and a specific list of process gaps — undocumented closures, queue aging, OT log source coverage — that documentation review would not have surfaced.

  2. 2Security or OT lead

    Export the asset register used for CAF Objective A evidence and compare it against a network scan of the OT environment. Use a network discovery approach appropriate for OT environments — passive enumeration or active scanning with OT-safe tooling — to enumerate IP-connected devices on OT network segments. Any device in the network scan that is not in the asset register is an Objective A gap and a coverage gap for every downstream control that uses the register as its scope definition.

    Expected outcome

    A reconciled asset inventory that includes OT-connected components, with a gap list of devices absent from the current register and a revised scope for Protect and Detect controls that reflects the actual environment.

  3. 3Compliance or supplier relationship lead

    Identify the three suppliers with the most direct access to OT or essential service networks. For each, review the current assurance evidence: if it consists only of a completed questionnaire, determine what independent verification would look like — a penetration test report, a SOC 2 Type II report, an ISO 27001 certificate with scope covering the relevant services. Request that evidence before the next assessment cycle. For each supplier, also map one level deeper: what upstream dependencies does this supplier have that have delivery access to your environment?

    Expected outcome

    A supply chain assurance file for high-access suppliers that contains independent verification evidence, and a tier-2 dependency map that identifies access paths not currently in scope for the assurance program.

  4. 4Security lead with incident response team

    Run a tabletop exercise against a scenario relevant to the organization's specific CNI sector and OT technology — not a generic phishing or ransomware scenario, but one that involves the operational technology systems that underpin essential service delivery. Document the exercise, the outcomes, and any gaps identified in the response process. This document becomes the behavioral evidence for Objective D that the IR plan alone cannot provide. If no OT-relevant scenario has been used in a previous exercise, that is the finding.

    Expected outcome

    A tabletop exercise record demonstrating tested IR capability against an OT-relevant scenario, with documented lessons learned that provide evidence of continuous improvement in response capability — the evidence category that NCSC assessors request and most OES organizations cannot produce.

One thing to do this week

Go to your SIEM or SOC ticketing system and find the last ten alerts that were closed as false positives. For each one, check whether a documented investigation rationale exists — not a one-word status field, but a record of what was examined and why the conclusion was false positive.

If rationale exists for most of them, your alert investigation process is producing the behavioral evidence that a CAF v4 Objective C assessment would request. If it does not, your Detect self-assessment score reflects your monitoring infrastructure, not your detection capability. Those are different things, and the difference is exactly what an NCSC assessor will look for.

Fixing the rationale documentation is an operational process change, not a technology problem. It takes a process decision and consistent enforcement. Finding the gap takes ten minutes and a query against your ticketing system. One of those is worth doing this week.

Further Reading

Frequently Asked Questions

What does a UK CAF v4 gap analysis find that self-assessment misses?

UK CAF v4 self-assessment scores controls against governance documentation. Gap analysis that starts from behavioral evidence — alert investigation records, incident timelines, supply chain verification files, tabletop exercise reports — finds what documentation review cannot: detection processes that exist on paper but produce closed alerts without investigation rationale, IR plans that have never been tested against OT-relevant scenarios, and supply chain assurance programs that consist of questionnaires rather than verified controls for suppliers with direct OT network access.

Why do CAF v4 Detect pillar self-assessment scores often not reflect actual detection capability?

CAF v4 Detect pillar self-assessments score based on monitoring infrastructure: SIEM deployment, log source configuration, alerting rule coverage. NCSC assessors score based on demonstrated detection capability: whether alerts are investigated with documented rationale, whether alert handling timelines are consistent with the detection requirement, whether OT environments have equivalent monitoring coverage to IT environments, and whether threat intelligence consumed is relevant to the organization's CNI sector. Organizations with mature SIEM deployments frequently score themselves at Achieved and receive assessor findings on detection process maturity.

What evidence does NCSC CAF v4 require for supply chain security under Objective A?

CAF v4 Objective A supply chain security evidence must be proportionate to the access suppliers have to OES networks. For suppliers with direct access to operational technology or essential service systems, NCSC assessors expect independent verification of security controls — penetration test reports, ISO 27001 certificates covering the relevant scope, SOC 2 Type II reports — not completed questionnaires. The questionnaire documents what the supplier claims. Independent verification provides a basis for confidence in those claims. Most OES supply chain programs have the former and not the latter for their highest-access suppliers.

What incident response evidence does CAF v4 Objective D require beyond a documented IR plan?

CAF v4 Objective D requires evidence of incident response capability, not just IR plan completeness. NCSC assessors request tabletop exercise records demonstrating the plan has been tested against scenarios relevant to the organization's actual threat profile and OT environment, lessons learned documentation showing the plan has been refined based on exercise outcomes, and in some cases evidence of response to actual incidents. An IR plan that names roles and timelines satisfies the documentation requirement. Evidence of tested capability against an OT-relevant scenario satisfies the assessor requirement. Most OES organizations have the former.

How should OT assets be included in CAF v4 Objective A asset management evidence?

CAF v4 Objective A requires comprehensive asset visibility for all systems relevant to essential service delivery. In mixed IT/OT environments, asset inventories produced from IT asset management platforms consistently miss OT-connected components: PLCs, RTUs, historian servers, engineering workstations, and third-party maintenance terminals. These devices are in scope for Objective A by the framework's definition. Reconciling the asset register against a network enumeration of OT network segments — using passive enumeration or OT-safe active scanning — is the only reliable way to confirm the register covers the actual environment. Risk assessments and downstream control coverage built on an incomplete register have gaps that track the asset gap.

What is the NIS Regulations notification timeline requirement for UK OES organizations under CAF v4?

NIS Regulations require OES organizations to notify their competent authority of significant incidents within 72 hours of becoming aware. CAF v4 Objective D compliance includes demonstrating that the internal process for identifying a notifiable incident and escalating to notification would operate within this window. Organizations whose detection-to-awareness gap — the time between first indicator and confirmed internal awareness — exceeds 72 hours cannot satisfy the notification requirement regardless of how clearly the obligation is documented. Gap analysis that reconstructs past incident timelines against the detection-to-awareness timeline reveals whether notification capability is real or theoretical.

How often should UK OES organizations conduct CAF v4 gap analysis beyond the self-assessment cycle?

CAF v4 gap analysis should be conducted before each self-assessment submission and after significant changes: new supplier relationships with OT network access, OT system additions or modifications, changes to monitoring infrastructure or SOC processes, and network architecture changes affecting IT/OT segmentation. The annual self-assessment cycle does not align with the rate at which operational environments change. Behavioral evidence review — alert investigation records, incident timelines, supplier verification status — should be reviewed at least quarterly to confirm that operational capability matches the self-assessed scores. Point-in-time self-assessment without ongoing behavioral evidence review produces scores that are accurate at submission and unverified for the rest of the assessment cycle.

Related Articles

GovRAMP Moderate authorization: why the Significant Change Request process catches providers off guard

GovRAMP Moderate authorization: why the Significant Change Request process catches providers off guard

GovRAMP Moderate is the first tier where you need a government sponsor, annual 3PAO reassessment, and a Significant Change Request process that can pause normal product releases for months. Most providers who stall post-authorization were not prepared for what maintaining Moderate status actually costs operationally.

GovRAMP Low+ authorization: the impact level that punishes providers who get the CUI boundary wrong

GovRAMP Low+ authorization: the impact level that punishes providers who get the CUI boundary wrong

GovRAMP Low+ is where providers handling limited Controlled Unclassified Information land — or discover they should not be there. The defining failure is not a missing control. It is a CUI boundary that was drawn before anyone asked what data the government actually sends through the system.

GovRAMP High authorization: why FIPS-validated crypto and personnel security controls catch providers off guard

GovRAMP High authorization: why FIPS-validated crypto and personnel security controls catch providers off guard

GovRAMP High is where cloud providers discover that having strong encryption is not the same as having FIPS 140-2 validated encryption — and that distinction alone has derailed authorizations from vendors who passed every other control family. The architectural constraints at High are qualitatively different from every lower tier.

Ready to Secure Your Digital Assets?

Get a comprehensive vulnerability assessment for your website today.