United Kingdom7 min read

External Attack Surface Management in the UK: CAF v4.0, Cyber Essentials and the Web Check Gap

The United Kingdom is the one market where the national cyber authority has effectively handed this category to the commercial market, in writing, twice.

The NCSC published a buyer's guide

On 18 September 2025 the NCSC published an External Attack Surface Management buyer's guide, describing EASM products as providing "automated discovery of your external attack surface" and "a view of the attack surface as seen from an attacker's perspective".

When a national technical authority writes a procurement guide for a product category, the category has stopped being optional in practice.

Then it retired its own tooling

On 31 March 2026 the NCSC retired Web Check and Mail Check. Its stated reasoning is the significant part: EASM products perform "effectively the same function", and under Active Cyber Defence 2.0 "the NCSC will only deliver solutions where the cyber security market is unable to".

Thousands of UK public sector bodies were using those free services for external checking. That capability has not been replaced by government. Early Warning remains free, but it is a different service. If you relied on Web Check, you currently have a gap that the NCSC has explicitly said the market should fill.

What the CAF requires

The Cyber Assessment Framework is at version 4.0, current since 6 August 2025, which added Basic and Enhanced Profiles and renamed objective C2 to Threat Hunting. Anyone still working to v3.2 is a version behind.

Two outcomes carry the weight:

A3.a Asset Management, at achieved: "All assets relevant to the secure operation of essential function(s) are identified and inventoried, and kept up-to-date."

B4.d Vulnerability Management, at achieved: "You maintain a current understanding of the exposure of your essential function(s) to publicly-known vulnerabilities", and "externally exposed vulnerabilities are mitigated (e.g. by patching) promptly." The not-achieved statement is blunt: "You do not mitigate externally exposed vulnerabilities promptly."

GovAssure continues under the Government Cyber Action Plan published 6 January 2026, which superseded the 2022 to 2030 strategy. Its first-year findings recorded widespread low maturity in fundamental controls, naming asset management specifically, with 28 percent legacy technology.

Cyber Essentials, and the patch clock people get wrong

Cyber Essentials Requirements for IT Infrastructure moved to v3.3 in April 2026, effective for accounts created from 27 April 2026, with the question set named Danzell. If your documentation references v3.2 Willow, it is superseded.

Scope catches anything that can accept inbound internet connections, make outbound ones, or control that flow, and the standard states plainly that "cloud services cannot be excluded from scope". Firewalls must block unauthenticated inbound connections by default, and internet-exposed administrative interfaces require documented business need plus either multi-factor authentication or an IP allow-list.

Patching is within 14 days where the vendor rates it critical or high, or the CVSS v3 base score is 7 or above, or the vendor provides no severity rating.

Here is the distinction that trips people. Fourteen days is the Cyber Essentials figure. The NCSC's own vulnerability management guidance, reviewed 1 May 2026, is stricter: five days for internet-facing services, seven for operating systems and applications, fourteen for internal. For actively exploited vulnerabilities it drops to under 24, 48 and 72 hours respectively. Quoting 14 days as "the NCSC recommendation" for everything is wrong.

Cyber Essentials Plus is assessed against Test Specification v3.2 from April 2025. Test case 1.1 requires the assessor to "identify all of the IP addresses currently in use by the Applicant", including IaaS, and scan all of them across the recommended TCP and UDP ports. A single failure fails the whole assessment. Since 2026, missing MFA on cloud services is an automatic fail, as are the new questions on 14-day patching.

If you cannot produce a complete list of your IP addresses, you cannot pass Cyber Essentials Plus. That is the requirement stated as directly as it can be.

The Cyber Security and Resilience Bill is not law yet

This matters because a lot of marketing implies otherwise. The Bill is not an Act and has not received Royal Assent. As at July 2026 it completed all Commons stages on 16 June 2026, had its Lords second reading on 14 July 2026, and Lords Committee stage begins 1 September 2026.

When it passes, it will extend the regime to data centres, managed service providers and designated critical suppliers, with 24-hour initial and 72-hour full incident reporting. Around 1,214 UK managed service providers are potentially in scope.

Worth knowing: the words "asset" and "vulnerability" do not appear in the Bill. The detail will arrive through secondary regulations and the statutory code of practice, with DSIT indicating phased commencement and consultation during 2026.

So the Bill is a reason to prepare, not a current obligation. Anyone selling you compliance with the Cyber Security and Resilience Act is selling you something that does not exist yet.

Where that leaves you

The UK case does not rest on pending legislation. It rests on CAF B4.d requiring current understanding of external exposure, Cyber Essentials Plus requiring a complete IP inventory to pass, and the NCSC having withdrawn the free tooling that used to cover the gap while publishing a guide on how to buy the commercial equivalent.

Other regions