Selling into Government: Where Penetration Testing Sits in Your CAF Evidence

Selling into Government: Where Penetration Testing Sits in Your CAF Evidence

By EJN Labs · 31 Jul 2026 · 8 min read

The NCSC Cyber Assessment Framework does not name penetration testing as a mandatory control. It is a risk-based assurance framework, and government buyers assessed under it expect suppliers to show objective evidence that vulnerabilities are found and fixed. A recent penetration test report from a CREST-accredited firm is the strongest single item in that evidence pack. Typical UK rates run £1,200 to £1,400 per tester day.

What CAF security assurance means for suppliers

CAF security assurance is the process by which UK government departments and regulators measure an organisation against the NCSC Cyber Assessment Framework. Suppliers are judged on outcomes, since each principle is assessed against contributing outcomes rather than a checklist of named products or tests.

The CAF sets out four objectives and fourteen principles covering risk management, protection, detection and response.

If you sell software, hosting, managed services or data processing into government, the CAF affects you even though you are not the one being formally assessed. Departments reviewed under GovAssure, and operators of essential services regulated under the NIS Regulations, have to account for the risk their suppliers introduce. That accountability flows down the supply chain as security questionnaires and contract schedules. When a procurement team asks how you manage vulnerabilities, they are asking a CAF-shaped question, and a penetration test report is the answer they hope to see.

The contractual driver: how CAF requirements reach your contract

The CAF is issued by the NCSC and is mandatory in effect wherever a regulator or organisation has adopted it. Central government departments use it through GovAssure, and several sector regulators use CAF-derived profiles. None of those assessments stops at the buyer’s own perimeter: Objective A includes supply chain risk management, which obliges the assessed organisation to manage the security of the suppliers it depends on.

In practice that reaches a supplier in three ways:

  • Pre-contract security questionnaires asking for your vulnerability management process, your last penetration test date and a summary of findings and remediation.
  • Contract clauses requiring independent testing at defined intervals, often annually, and after significant change.
  • Ongoing assurance requests, where the buyer’s own CAF assessment or GovAssure review prompts them to refresh the evidence they hold about you.

Being honest about the framework matters here. No CAF principle says “the supplier must commission a penetration test”. The framework demands achieved outcomes with objective evidence behind them, and independent testing is the verification method buyers trust most, which is why it appears in almost every government-facing security schedule we see.

Where penetration testing sits in the CAF evidence pack

The most direct fit is contributing outcome B4.d, vulnerability management, which sits under the system security principle. An organisation achieving that outcome can show that it identifies, triages and mitigates vulnerabilities in a timely way, and that its confidence in this is grounded in evidence rather than assertion. A penetration test provides exactly that: an independent, dated record of what an attacker could reach, what was exploitable and what was fixed.

Testing also supports outcomes beyond B4.d: findings about exposed services strengthen the protection objective, and retest evidence demonstrates that remediation actually happens. For a supplier assembling an evidence pack, the pieces that carry the most weight are:

  • A recent penetration test report covering the service sold to government, including your external infrastructure and any APIs the buyer’s systems or users touch.
  • A remediation log mapping each finding to a fix, an owner and a date.
  • A retest letter or updated report confirming that high and critical findings were closed.
  • Supporting certifications such as Cyber Essentials Plus and ISO 27001, which government buyers commonly expect as a baseline alongside testing.

If your service runs on AWS, Azure or GCP, expect the buyer to ask how the cloud control plane was assessed. A cloud penetration test covering identity, storage exposure and segmentation answers that directly. Our penetration testing checklist walks through the preparation steps.

How a CAF-aligned engagement runs

An engagement built for government evidence follows the same technical process as any high quality test, with extra care over scoping and reporting so the output maps to what the buyer will ask for.

  • Scoping. We define the boundary of the service sold to government: internet-facing hosts, web applications, APIs, cloud accounts and administrative access paths. Anything the buyer’s data flows through belongs in scope.
  • Testing. UK-based testers work through the agreed scope using manual techniques backed by tooling, focusing on exploitable weaknesses rather than raw scanner output.
  • Reporting. Each finding carries a severity, an evidence trail and a specific remediation step, written so a procurement reviewer can follow the summary while your engineers act on the detail.
  • Retest. Once fixes land, we verify them and issue confirmation you can hand to the buyer.

Timing matters. If a bid deadline or renewal is approaching, commission the test early enough to remediate and retest before you submit evidence. A report full of open critical findings is not the pack you want to send a government buyer.

What it costs and how scope drives the price

Penetration testing in the UK is priced on tester days, with day rates typically between £1,200 and £1,400. The scope of the service you sell to government sets the day count, so a lean SaaS product costs far less to evidence than a multi-component managed service.

ScopeTypical effortTypical cost
External infrastructure serving the government contract3 to 5 days£3,600 to £7,000
Web application and API test of the delivered service5 to 8 days£6,000 to £11,200
Full evidence pack: external, application, API and cloud configuration8 to 12 days£9,600 to £16,800

These are typical UK ranges rather than a quotation; the exact figure depends on the applications, API endpoints, hosts and cloud accounts in scope. Our guide to penetration testing costs in the UK breaks the pricing model down further, and you can get an exact figure through our quote form.

How EJN Labs approaches CAF evidence for suppliers

EJN Labs is a CREST-accredited penetration testing firm holding Cyber Essentials Plus, ISO 27001 and ISO 9001, so we build the same kind of evidence pack for our own certifications that government buyers ask our clients for. All testing is carried out by UK-based testers, which matters to public sector buyers who ask where their data and credentials are handled.

When we scope a supplier engagement, we start from the contract rather than the network diagram. We ask what the security schedule and questionnaire actually require, then shape the test boundary so the report answers those questions directly: which assets serve the government contract, what an internet-based attacker can reach, and whether vulnerability management is working in practice. That keeps the day count honest, because you pay to evidence the service you sell, not your entire estate. The same discipline applies whether the buyer is central government or a regulated sector such as financial services. Full details of our methodology are on our CREST penetration testing page.

Frequently Asked Questions

Does the NCSC CAF require penetration testing?

No, no CAF principle names penetration testing as a mandatory control. The framework is outcome-based, requiring organisations to manage vulnerabilities effectively and to hold objective evidence that they do, and an independent penetration test is in practice the most credible way to produce that evidence.

That applies particularly to contributing outcome B4.d on vulnerability management, which is why buyers assessed under the CAF routinely require testing from their suppliers.

What evidence do government buyers ask suppliers for?

A recent penetration test report, a remediation log, retest confirmation for high and critical issues, and baseline certifications such as Cyber Essentials Plus and ISO 27001 form the common set. The report should cover the contracted service, and the log should show findings were fixed.

Some buyers also ask for your vulnerability management policy and patching timescales. Keeping this pack current avoids scrambling when a questionnaire or GovAssure-driven request arrives mid-contract.

What does a CAF-aligned penetration test cost?

Expect £3,600 to £7,000 for an external infrastructure test of the systems serving the contract, based on 3 to 5 days at UK day rates of £1,200 to £1,400. A web application and API test typically takes 5 to 8 days, £6,000 to £11,200.

A full evidence pack covering external, application, API and cloud configuration runs 8 to 12 days, £9,600 to £16,800. Exact pricing comes from scoping.

How often should we retest to keep evidence current?

Retest annually, which is the norm in government-facing contracts and stated explicitly in many security schedules, and after significant change to the service, such as a major release, a new integration or a cloud migration. A report that predates the current architecture carries little assurance value.

Retesting of individual fixes should happen as remediation completes rather than waiting for the next annual cycle.

Do we need a CREST-accredited firm for government work?

Yes, in practice. CREST accreditation is the standard buyers ask for because it independently verifies the testing firm’s methodology, personnel and data handling. Many government security schedules name CREST explicitly, and even where they do not, a CREST-accredited firm’s report is accepted without argument.

For most commercial suppliers, choosing an accredited UK firm removes a whole category of procurement friction before it starts.

Build the evidence pack before the buyer asks for it

If you are bidding for or delivering a government contract, the strongest position is holding a current test report, a closed remediation log and retest confirmation before the questionnaire lands. Tell us what you sell into government and we will scope a test that produces exactly the evidence your buyer’s CAF assessment needs. Get a CREST penetration testing quote and we will come back with a fixed scope and price.

Leave a Reply

Your email address will not be published. Required fields are marked *