Cyber governance, risk and resilience without the licence fee

A growing suite of free, open source tools that help UK public sector bodies, suppliers and charities assess, evidence and improve their cyber security posture — from NCSC CAF v4.0 self-assessment through to business continuity planning and penetration test scoping.

8Live tools, all free to use
38CAF v4.0 IGPs covered
1,046NIST SP 800-53 controls mapped
£0Cost — no account required

The tools

Each tool runs independently in your browser at its own address. Pick the one that matches the job in front of you, or work through them in sequence to build a complete assurance picture.

Colleagues reviewing documents together around a meeting table

CAF v4.0 Self-Assessment

caf.govassure.uk

Assess your organisation against the full NCSC Cyber Assessment Framework v4.0 — all 4 objectives, 14 principles and 38 Indicators of Good Practice.

  • Achieved / Partially achieved / Not achieved scoring
  • Progress saved automatically to your browser
  • Export and re-import as JSON for review or handover
A delivery team working together around a table

Secure by Design SoA Generator

sbd.govassure.uk

Produce a Statement of Applicability for your service. Declare the data, stakeholders and technologies in scope, and the tool works out which controls apply and why.

  • Every control mapped to Secure by Design, CAF v4.0 and NIST SP 800-53 Rev. 5
  • 130-control curated baseline, or browse the full 1,046-control library
  • Inherent and residual risk capture, plus a traceable scope-to-control map
  • Export to Word, PDF or a CSV risk register
A team working across several laptops on a shared table

API Security Controls Matrix

api.govassure.uk

The seven NCSC API security pillars mapped against every UK classification tier, from OFFICIAL through to TOP SECRET, so you can see exactly which controls apply.

  • Based on NCSC Securing HTTP-based APIs (April 2025)
  • Cross-referenced to GSCP 2023, CAF v4.0 and GPG 13
  • Settles “what controls does this API actually need?” at design time
Three colleagues in discussion at a desk

Governance Review Tool

governance.govassure.uk

Prepare submissions for governance board reviews. Work through the questions for each board, set a RAG status, then export the whole pack as a document.

  • Technical Design Authority, Architecture Review Board and Solution Architecture Board
  • 12 questions per board with RAG confidence ratings
  • Export to Word or PDF; save and reload progress as JSON
A person working at a laptop in an office

Cyber Essentials Readiness

ce.govassure.uk

Work through 29 questions across the five Cyber Essentials control areas before you pay for certification, so you find the gaps before an assessor does.

  • Firewalls, secure configuration, user access control, malware protection, patching
  • Shows where you are ready and where remediation is needed
  • Preparation only — certification comes from an IASME-accredited body
Two colleagues reviewing information on a laptop screen

Supplier Risk Tracker & Domain Checker

tracker.govassure.uk

Keep a live register of your third parties and check the external security posture of the domains they operate.

  • Track supplier dependencies and Cyber Essentials compliance
  • Surface concentration risk where too much rests on one supplier
  • Built-in domain security checker for email and DNS hygiene
People walking between office buildings in a UK city

BCP Generator

bcp.govassure.uk

Answer a nine-step guided wizard about your organisation and get a tailored, professional business continuity plan written for you. About 20–30 minutes.

  • Covers cyber attack, IT failure, supply chain, premises, weather and more
  • AI drafts the narrative; download the finished plan as a Word document
  • Aligned to Cabinet Office BCM guidance, NCSC and BS 65000:2022
Aerial view of a UK city during the day

Penetration Test Scoping

scope.govassure.uk

Define targets, constraints and authorisation for a test engagement, then export a signed-off scope and rules of engagement document.

  • In-scope and explicitly out-of-scope assets, IP ranges and environments
  • Testing windows, permitted techniques, stop conditions and escalation contacts
  • OWASP, PTES, NIST SP 800-115, CREST, CHECK and TIBER-EU methodologies

Built for the people doing the work

Governance, risk and compliance tooling is usually sold by the seat and priced for organisations that already have a security budget. GovAssure exists for everyone else.

  • Free and open source — no licence, no seats, no sales call.
  • Private by design — most tools store everything in your browser and send nothing to a server.
  • Aligned to UK frameworks — NCSC CAF v4.0, Cyber Essentials, GSCP 2023, GPG 13 and BS 65000:2022.
  • Portable evidence — export to Word, PDF or JSON so the output is yours to keep and hand over.
  • Practical, not theoretical — built from real assurance, audit and continuity engagements.
Aerial view of a UK city and river

Who these tools are for

If you are accountable for cyber security outcomes but do not have an enterprise GRC platform behind you, these tools are built for your situation.

  • Central government departments and ALBs
  • Local authorities
  • NHS trusts and health bodies
  • Emergency services
  • Education and academy trusts
  • Housing associations
  • Charities and the third sector
  • Public sector suppliers
  • SMEs entering public procurement
  • Consultants and virtual CISOs
  • Internal audit and assurance teams

Not sure where to start? Smaller organisations usually begin with Cyber Essentials readiness and a business continuity plan. Public sector bodies in scope for assurance reporting tend to start with the CAF v4.0 self-assessment, then use the governance review tool to take the gaps to a board. If you are standing up a new service, begin with the Secure by Design SoA generator.

A UK city skyline seen across water

About GovAssure

GovAssure is an independent, community-run project. The tools are built and maintained by Jon Silvester, a cyber security architect working in and around UK public sector assurance, and shared openly so that other teams do not have to rebuild the same spreadsheets.

Feedback, corrections and contributions are welcome — particularly from practitioners who are using these frameworks in anger.

Connect on LinkedIn