Tom OwlesTom Owles· Risk & Security Solutions Lead

Organisations in scope for the NIS CAF should already be well into the work of meeting it. A difficult question is how much of the framework you can evidence with the platforms you already own, and which of the remaining gaps are genuinely yours to close.

This guide sets out the four objectives and what each one asks for, how far software takes you against all 234 'Achieved' criteria, and where the remainder has to be closed by your own people, decisions and specialist controls.



What is CAF v4.0?

The Cyber Assessment Framework, commonly referred to as the NIS CAF, is the National Cyber Security Centre's framework for assessing the cyber and technology resilience of the UK's essential services. It is outcome-based: rather than prescribing specific controls, it defines the outcomes you need to achieve and leaves the detail of how you get there to you.


Version 4.0, published in August 2025, is the most significant revision since the framework was introduced in 2018. It organises the NIS CAF around four top-level objectives, 41 contributing outcomes and 234 individual criteria at the 'Achieved' tier — the level a mature organisation is expected to reach — each supported by principles and indicators of good practice.


Every one of those 234 criteria can be scored one of three ways, and this is the basis we used throughout our assessment:


  1. Fully met - the product or control satisfies the criterion out of the box, across the whole estate, assuming the process runs as intended.
  2. Supported - the product materially helps evidence, orchestrate or manage the criterion, but real control also lives in a process or another system.
  3. Not met - the product alone doesn't move the needle without other tooling, or organisational change, doing the work.

Scoring at this granularity, rather than giving each outcome a single verdict, is what makes the resulting numbers defensible. It also means the honest answer to “are we covered” is rarely a flat yes or no.


The four CAF objectives

The NIS CAF groups its 41 contributing outcomes under four objectives. Between them they cover the full lifecycle of managing cyber risk to an essential function, from board-level governance through to learning from an incident after the fact.

Ref Objective What it covers
A Managing security risk Governance, roles and responsibilities, risk management process, assurance, asset management and supply chain.
B Protecting against attack Policy and process, identity and access, data security, system security and resilience preparation. The largest and most technical objective.
C Detecting cyber security events Logging, monitoring, alerting and threat hunting across the estate.
D Minimising impact Response planning, recovery capability, testing, and using incidents to drive improvement.


How ServiceNow meets those objectives

Out of the box, and before Veza or Armis, ServiceNow fully meets or supports 67% of the 234 'Achieved' criteria, most of it through four products: IRM, SecOps, ITOM and BCM. That is a strong foundation. It does a great deal in some areas and comparatively little in two that a workflow platform was never built to answer alone: knowing every identity's real access, and seeing every device on the estate.

Veza and Armis, both acquired by ServiceNow within the last year, exist to close precisely those two gaps. Veza establishes identity and data-access truth - who, human or machine, genuinely has access to what, reviewed and certified rather than assumed. Armis brings sight of every device, including the unmanaged, OT and IoT assets ServiceNow's own discovery cannot reach. Together they lift coverage of the NIS CAF from 67% to 76%, and cut the number of 'Not Met' criteria from 77 to 55.


Ref Objective ServiceNow alone With Veza and Armis
A Managing security risk
80% 84% (+4 pts)
B Protecting against attack
53% 67% (14pts)
C Detecting cyber security events
67% 79% (12pts)
D Minimising impact
93% 93% (no change)


Ref Objective ServiceNow alone With Veza and Armis
Overall All 234 'Achieved' criteria 67% 76% (+9pts)

Objective B moves the most, from 53% to 67%, because that is exactly where identity, privilege, data access and device visibility sit. Objective D barely shifts, because ServiceNow's business continuity and incident response tooling was already strong there without any help.


How Pulsar can support you

As a Premier ServiceNow partner with a Validated Practice in Risk, Resilience & Sustainability, we take you from an honest baseline to a working platform, sequenced so you are never committing to a long programme before you have seen value. Each phase is priced and scoped to how you want to buy - fixed price where the scope is clear, time and materials where it needs to flex.


1. Introductory workshop
2. Readiness Assessment
3. Roadmap session
4. Launch Pad delivery
90 minutes, no cost Fixed price Fixed price Modular, fixed price
We walk this assessment through against your estate and talk through what matters most to you.
Run against your environment: where you sit today, your biggest gaps and a CAF view.
A prioritised, sequenced plan, quick wins first, mapped to your regulatory timeline.
Built in bite-sized phases, each a self-contained package with a known scope and timescale.


A typical path through the wider programme runs as follows: baseline your estate against the NIS CAF and agree priorities; stand up risk, control and incident response in ServiceNow; add Armis for asset visibility and Veza for identity; build out business continuity and continuous monitoring; then move to managed run, so evidence stays current and coverage keeps improving. Every phase stands on its own, and you can pause or re-sequence at any point.

Our recent whitepaper sets out the full criterion-by-criterion assessment and can be downloaded here. And if you would like to see where your own estate sits against the NIS CAF, the introductory workshop is the easiest place to start - 90 minutes, no cost, walked through against your environment.

NIS CAF: common questions

Who does the NIS CAF apply to?

- The NIS CAF applies to organisations responsible for the UK's essential functions: operators of essential services, relevant digital service providers, managed service providers and designated critical suppliers. Government departments and public sector bodies are assessed against it too, through GovAssure. If a regulator or a prime contractor has asked how you measure up, the NIS CAF is almost certainly the yardstick they mean.

Is the NIS CAF mandatory?

- The framework itself is not a law; it is the assessment tool regulators and oversight bodies use to judge whether your cyber resilience obligations are being met. For organisations in scope of the NIS Regulations, or assessed under GovAssure, demonstrating your position against the NIS CAF is in practice unavoidable - which is why most organisations treat it as mandatory regardless of how it is formally worded.

How much of the NIS CAF can software cover?

- In our criterion-by-criterion assessment of all 234 'Achieved' criteria, ServiceNow fully meets or supports 67% out of the box, rising to 76% with Veza and Armis added. The remaining 55 criteria are not a product shortfall: 23 are inherent to your organisation - accountability, culture, skilled people, secure-by-design decisions - and 32 need adjacent specialist tooling such as SIEM, EDR, PAM or cryptographic controls. No single vendor can close the NIS CAF on its own.

Facing something similar?

Talk to the practitioners behind this work — we'll tell you honestly what we'd do.