Skip to main content

What do you think of this service? Your feedback will help us to improve it.

Author: AnnaB

Last updated: 2025-10-31

GovAssure detailed contributing outcome summary guidance

Specific guidance on how to write a summary for each contributing outcome in NCSC's Cyber Assessment Framework (CAF).

Please note: the content on this page is currently being updated. Guidance will be available for all 39 contributing outcomes soon.

You will need to write a summary of up to 1,500 words for every contributing outcome.

At stage 4, your reviewer will use the summary to understand how your IGP responses and evidence support your contributing outcome status.

Make your summary clear and evidence-based. This will help your reviewer to confirm your compliance without needing to ask for clarification. It will also help them to make a decision if they are considering downgrading or upgrading your contributing outcome status.

In your contributing outcome summary, you should:

  1. Be specific to your organisational context.
  2. Confirm the processes and controls in place.
  3. Explain how processes and controls are managed and who is responsible.
  4. Explain how often your organisation reviews processes.
  5. Describe how key controls and processes support the contributing outcome.
  6. Explain how you implement these controls.
  7. Include references to your supporting evidence.
  8. Make sure that you reference your responses to IGPs, including where you have commented on alternative controls or exemptions.
  9. Include any gaps or limitations that your organisation faces with cyber security measures.

Note: It is important that you write a summary even if your status is ‘not achieved’. This will allow the reviewer to provide more targeted recommendations in their final report.

CAF Objective A – Managing security risk

CAF Objective B – Protecting against cyber attacks

CAF Objective C – Detecting cyber security events

CAF Objective D – Minimising the impact of cyber security incidents

Sign up to UK Government Security

Subscribe to our newsletters to receive notifications when changes to strategy, policy, standards, and guidance are published on the website.

Sign up now