Forefront IT Security Services
BlogCompliance
Compliance

NCSC CAF: Mapping Penetration Testing to the 14 Principles

December 2025Forefront IT Security Services2 min read

The Cyber Assessment Framework has 14 principles across 4 objectives. Here's how penetration testing maps to each.

  • 14 Principles across 4 objectives
  • 40% of findings relate to B2 (Identity & Access)
  • 4 Maturity levels for assessment

The Four Objectives

CAF organises 14 principles into four objectives. Each maps directly to things we test during penetration engagements:

  • A: Managing Security Risk (Principles A1-A4). Governance, risk management, asset management, supply chain
  • B: Protecting Against Cyber Attack (Principles B1-B6). Service protection, identity/access, data security, system security, network security
  • C: Detecting Cyber Security Events (Principles C1-C2). Security monitoring, anomaly detection
  • D: Minimising Impact (Principles D1-D2). Response planning, recovery, lessons learned

Penetration testing provides evidence for CAF assessments, validation that policies are actually implemented.

Principle-by-Principle Pentest Mapping

PrincipleHow Pentesting Maps
A1: GovernanceWeak governance shows in test results: inconsistent controls, conflicting configurations
A2: Risk ManagementWe find critical assets not in risk registers; scoping reveals gaps
A3: Asset ManagementDiscovery scanning reveals shadow IT, legacy systems, forgotten dev environments
A4: Supply ChainThird-party connections are prime targets, VPN tunnels, API integrations, shared credentials
B1: Service ProtectionTest if policies are implemented, default credentials on production systems?
B2: Identity & Access~40% of findings: over-privileged accounts, weak passwords, missing MFA, Kerberoasting
B3: Data SecurityTest data access controls, look for exposed databases, verify encryption
B4: System SecurityPatch management, secure configuration, unnecessary services, primary entry vectors
B5: Resilient NetworksTest segmentation and firewall rules: can we pivot from workstation to critical servers?
B6: Staff AwarenessPhishing simulations, social engineering, click rates, credential harvesting success
C1: Security MonitoringPurple team tests detection capability, do SOC alerts fire when we compromise systems?
C2: Proactive DiscoveryRed team engagements test threat hunting, do defenders notice persistence?
D1: Response PlanningTabletop exercises, simulated incidents, can teams contain breaches?
D2: Lessons LearnedTrack findings year-over-year, organisations that improve fix and verify

B2 (Identity & Access) is Where Most Fail

Roughly 40% of our findings relate to B2. Over-privileged service accounts, weak password policies, stale admin accounts, missing MFA. Kerberoasting, AS-REP roasting, password spraying, all exploit B2 weaknesses.

Evidence for Assessment

CAF assessments need evidence. Penetration test reports provide:

  • Control Validation Proof that policies are actually implemented
  • Gap Identification Issues assessors might miss
  • Detection Evidence Logs showing what triggered alerts (and what didn't)
  • Remediation Tracking Before/after comparisons showing improvement

Maturity Level Considerations

CAF uses four maturity levels. Testing supports progression:

  • Level 1: Partial Basic testing identifies fundamental gaps
  • Level 2: Risk-Informed Regular testing validates controls align with identified risks
  • Level 3: Repeatable Continuous testing demonstrates consistent security posture
  • Level 4: Adaptive Advanced testing (red team, purple team) validates response and adaptation

Most organisations target Level 2 or 3. Achieving these sustainably requires testing that goes beyond annual checkbox exercises. Testing that validates controls work under real attack conditions.

CAF-Aligned Testing

We structure penetration testing engagements to provide evidence directly applicable to CAF assessments. Findings map to specific principles, making it straightforward to demonstrate security posture to assessors.

Security Front Door

Find the right level of security for your business.

One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.

Forefront
UK Penetration Testing & Red Team Operations
Loading...