Skip to main content

What do you think of this service? Your feedback will help us to improve it.

Author: Government Security Group

Last updated: 7 September 2026

GovAssure news and updates

News and updates from the GovAssure team. 

GovAssure news 

You can now find GovAssure news in the Government Cyber Unit Cyber Bytes newsletter.  

Sign up for Cyber Bytes

Read past issues

Targeted Improvement Plans (TIPs) 

The deadline for submitting 2025-26 TIPs on WebCAF for organisations that had an Independent Assurance Review has now passed.  

For organisations that had a Peer Review, the deadline is 30 September.  

The GovAssure team will be in touch with organisations following the review of TIPs.  

We are also preparing to carry out a light-touch follow-up activity on TIPs from the first two years of GovAssure. We will shortly be in touch directly with relevant organisations. 

GovAssure 2026-27 

Timeline  

The timeline for GovAssure 2026-27 is: 

  • Stages 1 and 2  |  Scoping  |  September – October 2026  
  • Stage 3  |  Self-assessment  |  November 2026 – January 2027  
  • Stage 4  |  Independent Assurance Review or Peer Review  |  February – March 2027  
  • Stage 5  |  Targeted Improvement Plan  |  April – May 2027  

If your organisation works directly with a GovAssure cyber adviser, they will get in touch with you from 21 September onwards to discuss your approach to participating in this year’s GovAssure cycle and to support you with the scoping process.  

Arm’s length body participation 

Lead Government Departments (LGDs) should share the following information with the GovAssure team by no later than 21 September:  

  • which of your ALBs will be going through GovAssure 
  • name, role and contact emails for each ALB’s GovAssure Lead 

You can either share this directly with your cyber adviser, or email govassure@dsit.gov.uk.  

The guidance on supporting arm’s length bodies provides further information on your role as the LGD, including:  

  • deciding which of your ALBs are in scope for GovAssure 
  • acting as the point of contact for ALBs throughout the process 
  • supporting your ALBs through the 5 stages of GovAssure 
  • sharing relevant information about the progress of your ALBs with the GovAssure team 

CAF 4.0 transition and updates to the Government CAF profiles  

We are working on transitioning GovAssure and WebCAF to CAF 4.0 for 2026-27.   

The Government CAF profiles are being updated to align with CAF v4.0 and reflect the current threat landscape. There are two profiles:

  • Basic (replacing Baseline)
  • Enhanced

The new profiles will be available in the week commencing  21 September, along with supporting information. 

The profiles are going through a rigorous modelling and validation process involving in-depth engagement with internal teams, NCSC and other government organisations. 

Alignment with NCSC’s CRA scheme for Independent Assurance Reviews  

NCSC’s Cyber Resilience Audit scheme gives organisations confidence in companies that have been assured as meeting the NCSC standard for delivering Independent Assurance Reviews.  

For 2026-27, all GovAssure Independent Assurance Reviews must be delivered by Assured Service Providers registered on the CRA scheme.  

The GovAssure team has worked closely with the Government Commercial Agency (GCA – formerly Crown Commercial Services) to reflect this change in the Cyber Security Services 3 dynamic purchasing system (DPS) and supporting documentation.   

Organisations should select ‘Cyber Resilience Audit’ under ‘NCSC Assured Services’ in the DPS to find eligible suppliers.   

Sign up for the Government Security Profession newsletter

Subscribe to our monthly email newsletter for the latest news, learning opportunities, vacancies and events.

Sign up now (Opens in a new tab)