NCSC Cyber Assessment Framework v4.0
Framework
The yardstick UK regulators apply to essential services, including energy.
CAF is outcome-based rather than prescriptive. It asks whether you achieve an outcome, not whether
you bought a particular product. Four objectives, A to D, covering managing security risk,
protecting against cyber attack, detecting events, and minimising the impact of incidents.
Version 4.0 landed in August 2025 and moved the bar in four places, a deeper expectation around
understanding attacker methods and motivations, secure software development and maintenance for
software used in essential services, stronger security monitoring and threat detection, and
explicit coverage of AI-related risk. Operators who assessed against v3.2 and have not re-baselined
are carrying an unquantified gap.
Structure
4 objectives, 14 principles, contributing outcomes assessed as achieved, partially achieved or not achieved
Current version
v4.0, published August 2025
Hardest outcome for OT
B1.a asset management, which is where M1 earns its place
UK Cyber Security & Resilience Bill
Legislation, in progress
The update to the UK NIS Regulations 2018, currently before the House of Lords.
Announced in the July 2024 State Opening, introduced on 12 November 2025, second reading
6 January 2026, committee stage through February, third reading in the Commons 16 June 2026, and
now in Lords committee. It is not law yet, but the direction is settled enough to plan against.
The scope widens. Data centres, managed service providers, large load controllers and critical
suppliers to regulated entities come into the net, alongside the existing sectors. Reporting duties
increase, including compulsory ransomware reporting, and regulators gain stronger enforcement
powers. Daily fines in the order of £100,000 for continued failure have been signalled by
government.
For an offshore wind operator the practical question is not whether you are in scope, you almost
certainly are, but whether your critical suppliers know that they now might be too.
Stage
House of Lords committee, from 1 September 2026
New in scope
Data centres, MSPs, large load controllers, critical suppliers
Enforcement
Signalled daily fines up to £100,000, plus wider regulator powers
NIS2 Directive & UK NIS Regulations
Regulation
Legal duties for essential and important entities, on both sides of the Channel.
NIS2 (EU 2022/2555) has applied since October 2024, though national transposition has been uneven
and several member states arrived late. If you operate assets in Dutch, German, Danish, Belgian or
Polish waters, the obligation sits with the local entity under local implementing law, which is
rarely a straight copy of the directive.
The reporting clock is the part that catches operators out. An early warning within 24 hours of
becoming aware of a significant incident, a fuller notification within 72 hours, and a final report
within one month. Twenty four hours is not long if nobody has agreed in advance who declares an
incident and who talks to the regulator.
Reporting
24h early warning, 72h notification, 1 month final report
Penalties
Up to €10M or 2% of global turnover for essential entities
Management liability
Named accountability at management-body level, a change from NIS1
IEC 62443 Series
Standard
The engineering standard for industrial automation and control system security.
A standard, not a framework. Where CAF asks whether you have understood your estate, 62443 tells
you how to partition it and how to specify a control so a vendor can build and verify it. The parts
that matter most in an operating offshore wind estate are 62443-2-1 for the security management
system, 62443-3-2 for zone and conduit risk assessment and target security levels, and 62443-3-3
for the system requirements that follow from an SL target.
62443-3-2 is increasingly written into FEED and O&M contracts, which means the zone and conduit
model stops being a consultancy artefact and becomes a contractual deliverable that has to be
maintained. M3 holds it as living data for exactly that reason.
Zone & conduit
62443-3-2, tolerable risk and target security level per zone
System requirements
62443-3-3, SL 1 to SL 4 with foundational requirements
Product side
62443-4-1 and 4-2, what to demand of an OEM
NIST Cybersecurity Framework 2.0
Framework
The common language, and the one your US parent or investor will ask for.
CSF 2.0 added Govern to the original five functions, so the set is now Govern, Identify, Protect,
Detect, Respond and Recover. It is not a UK regulatory requirement, but it is the framework most
international owners, insurers and lenders are fluent in, and it is frequently the language a board
paper has to be written in.
Modus treats CSF as an output view rather than a separate programme. The controls are the same
controls, presented against CSF categories for the audience that wants them that way.
Functions
Govern, Identify, Protect, Detect, Respond, Recover
Released
Version 2.0, February 2024
Typical use
Investor, insurer and group-level reporting
MITRE ATT&CK for ICS
Capability
Adversary behaviour, in the language of industrial control systems.
A knowledge base of the tactics and techniques observed against ICS environments, not a compliance
checklist. Its value in Modus is specificity. Rather than a generic threat statement, techniques are
mapped against the assets, conduits and access routes in your register that would actually carry
them.
That turns the threat model into a prioritised work list, and it gives detection engineering
something concrete to aim at. CAF v4.0's stronger expectation around understanding attacker methods
is most readily evidenced this way.
Scope
ICS-specific tactics and techniques, distinct from Enterprise ATT&CK
Use in Modus
Technique-to-asset mapping, coverage and gap analysis
Not to be confused with
CVE and KEV, which describe vulnerabilities, not behaviour
CISA Known Exploited Vulnerabilities
Capability, live feed
The short list of vulnerabilities that are being exploited in the wild.
Thousands of CVEs are published every month and almost none of them are relevant to your estate.
The KEV catalogue narrows the field to what is confirmed as actively exploited, which is a far more
useful prioritisation signal than a CVSS score on its own.
Modus matches advisories against the asset register by vendor, product and firmware version, then
flags KEV entries separately. A KEV on a device sitting behind a well-controlled conduit is a
different conversation from the same KEV on an asset reachable through an OEM remote access route,
and Modus can tell the difference because it knows the architecture.
Match on
Vendor, product, firmware version, from M1
Context added
Zone, conduit and reachability, from M2 to M4
Reality check
Most OT assets cannot be patched on demand, so compensating controls are the answer Modus tracks
Ofgem CAF & The OFTO Regime
Sector profile
How CAF is actually applied to GB energy, and what changes hands at OFTO transfer.
Ofgem applies CAF as the competent authority for the GB energy sector, with sector-specific
expectations and its own assessment cycle. Generators, transmission owners and OFTOs are all in
scope, with the boundary between them a recurring source of argument about who owns which control.
OFTO transfer is where an undocumented OT estate becomes expensive. Due diligence increasingly
includes OT cyber evidence, and a transmission asset handed over without a credible asset register
or zone model creates a liability that gets priced in. Building the register during construction is
considerably cheaper than reconstructing it at transfer.
Competent authority
Ofgem, for the GB energy sector
Boundary risk
Generator, TO and OFTO control ownership at the interface
Transfer evidence
Asset register, zone model, access records, incident history