A CyPro-managed assurance service
CAF Assessment and Cyber Assurance for Government and Defence
CyPro fronts and manages your assessment against the NCSC Cyber Assessment Framework, while an accredited specialist partner performs the technical work. It is the managed route to CAF, GovAssure, MOD Secure by Design and CHECK-accredited IT Health Check assurance for UK government, defence and CNI suppliers, with indicative fixed-scope pricing published on the page while the rest of the field stays quote-only.
- Partner-delivered, CyPro-managed
- Indicative fixed-scope pricing, published
- NCSC CAF, GovAssure and MOD Secure by Design
- Government, defence and CNI suppliers
CyPro's clients include
What we assess against
Government and defence cyber assurance, managed end to end
Five routes into a single managed service, each with its scope defined and its indicative price printed before you enquire.
The Cyber Assessment Framework, explained
A plain-English guide to the NCSC Cyber Assessment Framework: its four objectives, fourteen principles, the baseline and enhanced profiles, and who has to comply.
GovAssure support
Readiness and independent assurance through all five stages of GovAssure, the Cabinet Office programme that uses the CAF, for central government departments and their arm's length bodies.
MOD Secure by Design
Assurance for MOD suppliers and delivery teams, from Secure by Design activities to the security case and evidence. The defence programme, not the police Secured by Design scheme.
IT Health Check (ITHC)
CHECK-aligned IT Health Checks for PSN, pension dashboards and other public-sector connections, performed by CHECK-accredited testers through our delivery partner.
Assessment pricing, published
Indicative fixed-scope from prices for every engagement, printed on the page while the rest of the field stays quote-only. See what a managed assessment costs before you enquire.
What is a CAF assessment?
A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework: its four objectives and fourteen principles, at either the baseline or enhanced profile set for your sector. Government departments and their arm's length bodies reach it through GovAssure, the Cabinet Office programme built on the CAF, while MOD suppliers meet a related bar through MOD Secure by Design. We run the gap analysis against the profile that applies to you, then hand back a prioritised plan to close the distance, with the indicative cost published up front. The assessment is fronted and managed by CyPro and performed by an accredited delivery partner; see how the engagement runs.
Why this service
A managed assessment, priced in the open
Prices on the page, not behind a quote
Every ranking provider in this market is quote-only. We publish indicative fixed-scope from prices for CAF, GovAssure, MOD Secure by Design and ITHC engagements, so you can size the work before the first call.
Partner-delivered, CyPro-managed
CyPro fronts and manages the engagement end to end; an accredited specialist partner performs the assessment. You get a single managed relationship, with the technical work done by testers who hold the accreditations the framework requires.
Built for government and defence buyers
This is a specialist service for UK government departments and arm's length bodies, MOD suppliers and delivery teams, and CNI operators. The framework you must meet decides the scope, not a generic checklist.
Mapped to your framework obligation
We assess against the exact bar that applies to you: the baseline or enhanced CAF profile for your sector, the GovAssure stage you are at, or the Secure by Design tier for your project. The output is evidence your assessor can use.
A prioritised plan, not just a score
The assessment does not stop at a maturity rating. You receive a ranked plan to close the gap against the profile, written for the people who will do the work, so the finding leads straight to the fix.
CyPro's bench behind the service
The consultants managing your engagement sit beside CyPro's CREST penetration testers and incident responders, so when the assessment surfaces work that needs deeper security expertise, the escalation path is already in place.
Your experts hold
How we work
A straight account of what you are buying
No named-client wall and no borrowed logos on the assessment itself. Here is the model, the frameworks we assess against and the pricing that sets this service apart.
CyPro fronts it, an accredited partner assesses it
We are open about how this works. CyPro manages the engagement, the scoping, the reporting and the relationship; an accredited specialist partner carries out the technical assessment. We do not claim in-house CAF, GovAssure or ITHC delivery, and we never claim an accreditation we do not hold.
The frameworks we assess against
The NCSC Cyber Assessment Framework, GovAssure for central government, MOD Secure by Design for defence suppliers, and IT Health Checks delivered by CHECK and CREST accredited testers. Each name describes the scheme we assess you against, not a CyPro mark.
Fixed-scope pricing, published up front
The entire ranking field runs a quote-only model. We publish indicative from prices instead: CAF assessment from GBP 6,500, GovAssure from GBP 9,500, MOD Secure by Design from GBP 8,500 and ITHC from GBP 4,500, all fixed-scope and partner-delivered.
Before you ask us
Frequently asked questions
What is a CAF assessment?
A CAF assessment measures your organisation against the NCSC Cyber Assessment Framework: its four objectives and fourteen principles, at either the baseline or enhanced profile set for your sector. It is used across government and critical national infrastructure to show whether your cyber security is proportionate to the risk you carry.
We run the gap analysis against the profile that applies to you, then hand back a prioritised plan to close the distance. The assessment is fronted and managed by CyPro and performed by an accredited delivery partner.
What is GovAssure?
GovAssure is the Cabinet Office assurance scheme for central government departments and their arm's length bodies. It uses the NCSC Cyber Assessment Framework as its technical standard and runs across five stages, from scoping and a self-assessment to an independent assurance review.
We support you through readiness and the independent assurance stages, with indicative pricing published rather than held behind a quote.
What is MOD Secure by Design?
MOD Secure by Design is the Ministry of Defence approach that requires cyber security to be built into defence projects from the outset, evidenced through a security case and a set of Secure by Design activities across the project lifecycle. It applies to MOD suppliers and delivery teams.
This is the defence programme. It is distinct from the police Secured by Design scheme for physical security, which is spelled differently and covers a different market. We do not blend the two.
What is an IT Health Check (ITHC)?
An IT Health Check is an assessment of internet-facing and internal systems required for connections such as the Public Services Network and the pension dashboards programme. Buyers require it to be performed by testers holding NCSC CHECK or CREST accreditation.
Our delivery partner's CHECK-accredited testers carry out the ITHC, with CyPro managing the scoping, evidence and reporting around it.
Talk to us about your framework obligation
Find out what a CAF or GovAssure assessment involves for you
The scoping call is free, lasts 45 minutes and is taken by a consultant, not a salesperson. It covers which framework applies to you, the profile or stage you need to meet, and the indicative fixed-scope cost of a managed, partner-delivered assessment.