The UK Cyber Assessment Framework (CAF) is the UK National Cyber Security Centre's official framework for assessing cyber resilience, used to enforce the UK NIS Regulations 2018 across operators of essential services and relevant digital service providers. It's built around 4 objectives, 14 principles, and Indicators of Good Practice (IGPs), assessed against a target CAF Profile (Basic or Enhanced), with mandatory incident notification to your competent authority within 72 hours of becoming aware of a qualifying incident. Non-compliance can carry fines of up to £17 million.