GovAssure news and updates
News and updates from the GovAssure team.
GovAssure news
You can now find GovAssure news in the Government Cyber Unit Cyber Bytes newsletter.
Targeted Improvement Plans (TIPs)
The deadline for submitting 2025-26 TIPs on WebCAF for organisations that had an Independent Assurance Review has now passed.
For organisations that had a Peer Review, the deadline is 30 September.
The GovAssure team will be in touch with organisations following the review of TIPs.
We are also preparing to carry out a light-touch follow-up activity on TIPs from the first two years of GovAssure. We will shortly be in touch directly with relevant organisations.
GovAssure 2026-27
Timeline
The timeline for GovAssure 2026-27 is:
- Stages 1 and 2 | Scoping | September – October 2026
- Stage 3 | Self-assessment | November 2026 – January 2027
- Stage 4 | Independent Assurance Review or Peer Review | February – March 2027
- Stage 5 | Targeted Improvement Plan | April – May 2027
If your organisation works directly with a GovAssure cyber adviser, they will get in touch with you from 21 September onwards to discuss your approach to participating in this year’s GovAssure cycle and to support you with the scoping process.
Arm’s length body participation
Lead Government Departments (LGDs) should share the following information with the GovAssure team by no later than 21 September:
- which of your ALBs will be going through GovAssure
- name, role and contact emails for each ALB’s GovAssure Lead
You can either share this directly with your cyber adviser, or email govassure@dsit.gov.uk.
The guidance on supporting arm’s length bodies provides further information on your role as the LGD, including:
- deciding which of your ALBs are in scope for GovAssure
- acting as the point of contact for ALBs throughout the process
- supporting your ALBs through the 5 stages of GovAssure
- sharing relevant information about the progress of your ALBs with the GovAssure team
CAF 4.0 transition and updates to the Government CAF profiles
We are working on transitioning GovAssure and WebCAF to CAF 4.0 for 2026-27.
The Government CAF profiles are being updated to align with CAF v4.0 and reflect the current threat landscape. There are two profiles:
- Basic (replacing Baseline)
- Enhanced
The new profiles will be available in the week commencing 21 September, along with supporting information.
The profiles are going through a rigorous modelling and validation process involving in-depth engagement with internal teams, NCSC and other government organisations.
Alignment with NCSC’s CRA scheme for Independent Assurance Reviews
NCSC’s Cyber Resilience Audit scheme gives organisations confidence in companies that have been assured as meeting the NCSC standard for delivering Independent Assurance Reviews.
For 2026-27, all GovAssure Independent Assurance Reviews must be delivered by Assured Service Providers registered on the CRA scheme.
The GovAssure team has worked closely with the Government Commercial Agency (GCA – formerly Crown Commercial Services) to reflect this change in the Cyber Security Services 3 dynamic purchasing system (DPS) and supporting documentation.
Organisations should select ‘Cyber Resilience Audit’ under ‘NCSC Assured Services’ in the DPS to find eligible suppliers.