The implementation of the EU Security of Networks and Information Systems (NIS) Directive in May 2018 requires Competent Authorities (CAs) to have the ability to assess the cyber security of Operators of Essential Services (OES).
In support of the UK NIS Directive implementation, the NCSC is committed to working with lead government departments, regulators and industry to develop a systematic method of assessing the extent to which an organisation is adequately managing cyber security risks in relation to the delivery of essential services.
This assessment method, otherwise known as the Cyber Assessment Framework (CAF), is intended to meet both NIS Directive requirements and wider CNI needs.
Source: NCSC