
The Cyber Assessment Framework has 14 principles across 4 objectives. Here's how penetration testing maps to each.
CAF organises 14 principles into four objectives. Each maps directly to things we test during penetration engagements:
Penetration testing provides evidence for CAF assessments, validation that policies are actually implemented.
| Principle | How Pentesting Maps |
|---|---|
| A1: Governance | Weak governance shows in test results: inconsistent controls, conflicting configurations |
| A2: Risk Management | We find critical assets not in risk registers; scoping reveals gaps |
| A3: Asset Management | Discovery scanning reveals shadow IT, legacy systems, forgotten dev environments |
| A4: Supply Chain | Third-party connections are prime targets, VPN tunnels, API integrations, shared credentials |
| B1: Service Protection | Test if policies are implemented, default credentials on production systems? |
| B2: Identity & Access | ~40% of findings: over-privileged accounts, weak passwords, missing MFA, Kerberoasting |
| B3: Data Security | Test data access controls, look for exposed databases, verify encryption |
| B4: System Security | Patch management, secure configuration, unnecessary services, primary entry vectors |
| B5: Resilient Networks | Test segmentation and firewall rules: can we pivot from workstation to critical servers? |
| B6: Staff Awareness | Phishing simulations, social engineering, click rates, credential harvesting success |
| C1: Security Monitoring | Purple team tests detection capability, do SOC alerts fire when we compromise systems? |
| C2: Proactive Discovery | Red team engagements test threat hunting, do defenders notice persistence? |
| D1: Response Planning | Tabletop exercises, simulated incidents, can teams contain breaches? |
| D2: Lessons Learned | Track findings year-over-year, organisations that improve fix and verify |
Roughly 40% of our findings relate to B2. Over-privileged service accounts, weak password policies, stale admin accounts, missing MFA. Kerberoasting, AS-REP roasting, password spraying, all exploit B2 weaknesses.
CAF assessments need evidence. Penetration test reports provide:
CAF uses four maturity levels. Testing supports progression:
Most organisations target Level 2 or 3. Achieving these sustainably requires testing that goes beyond annual checkbox exercises. Testing that validates controls work under real attack conditions.
We structure penetration testing engagements to provide evidence directly applicable to CAF assessments. Findings map to specific principles, making it straightforward to demonstrate security posture to assessors.
One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.