Disclosure Log

National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF) (FOI/7932)

Message from Nottinghamshire County Council - 29 May 2026


Dear Requester,
Request FOI/7932
Further to your request received on I confirm that the Council has now considered your request under the Freedom of Information Act 2000.
1. Adoption Status
  • Has the Council formally adopted the Cyber Assessment Framework (CAF) as its primary cyber security assurance model No
  • If yes, on what date was the framework adopted, and what is the current progress of its implementation (e.g., pilot stage, partial rollout, or fully implemented) Partial Rollout
  • If the Council has not adopted the CAF, is there a formal plan or timeline to do so in the 2026/27 financial year (or beyond) Already in progress
2. Alternative Frameworks
  • If the Council has decided not to adopt the CAF, please state the primary reason for this decision (e.g., lack of resources, preference for other standards, or awaiting further central government guidance). N/A
  • Please list any other cyber security or risk management frameworks currently in use by the Council outside of PSN (e.g., ISO 27001, Cyber Essentials/Cyber Essentials Plus, NIST). PSN, Cyber Essentials
3. Manpower and Personnel
  • How many Full-Time Equivalent (FTE) staff members are currently allocated to the implementation, assessment, or ongoing maintenance of the CAF X1
  • Has the Council recruited new staff specifically to handle the requirements of the CAF, or has the workload been absorbed by existing IT/security teams No
  • Have external consultants or third-party service providers been contracted to assist with the CAF assessment No
  • How are you planning to select systems to be prioritised during the CAF implementation Already Chosen
4. Financial Cost
  • What is the total estimated cost to date of adopting/implementing the CAF framework within the Council (Please include costs for staff time, software/tools, and external consultancy). Staff Time only estimated at approx. £2183.85 (15 days).
  • What is the projected annual budget for maintaining compliance with the CAF over the next three financial years Annual budget has not been determined.
5. Governance
  • Which department or senior leadership role (e.g., SIRO, CISO, or Head of IT) is ultimately responsible for the Council’s CAF compliance and reporting Head of Service Delivery, Governance and Standards


We hope you find this information useful.
The Council publishes Access to Information requests and responses on its online Disclosure Log. Only requests deemed to be in the public interest will be included and any request included within this log will be de-personalised accordingly.
To view the Council’s Disclosure Log, please visit our website.
If you have any queries about this email, please do not hesitate to contact us, quoting the reference number listed at the top of this letter in all communications.
If you are unhappy with the Council’s response to your request and wish to make a complaint or to request a review of the information provided, please write to us or complete the on-line complaint form that can be found on our website.
If after going through the Council’s Internal Review process you are still not satisfied, you can contact the Information Commissioner direct.
 
Information Commissioner
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Helpline:
 
Email:
Website:
0303 123 1113
01625 545 745

[email protected]
www.ico.org.uk
 
Yours sincerely


Freedom of Information
Complaints and Information Team
Chief Executives Department
Nottinghamshire County Council
The Council is committed to protecting your privacy and ensuring all personal information is kept confidential and safe. For more details see our general and service specific privacy notices at: https://www.nottinghamshire.gov.uk/global-content/privacy