Decoding NCIIPC's Conformity Assessment Framework.
OT/ICS
India Regulation
.jpg)
Key Takeaways
- What CAF actually is: NCIIPC's framework, developed with the Quality Council of India, covering people, processes, technology and governance across Critical Sector Entities.
- The 5 schemes in one place: Cybersecurity Management System certification, the inspection scheme for IT and ICS, CyberPros personnel certification, accreditation for consultancy organisations, and accreditation for training bodies.
- Whether CAF is mandatory, and what it maps to: ISO 27000, IEC 62443, NIST and CIS, set against the IT Act 2000, NCIIPC directives and CEA guidelines.
- Preparation split by who you are: a Critical Sector Entity, a consultancy organisation, a training body, or an individual practitioner.
What's inside
India's critical sectors already carry several overlapping cybersecurity mandates. CAF does something different. Rather than adding controls, it builds the assurance layer underneath them: who certifies a management system, who inspects an ICS, who is competent to consult, and who is accredited to train.
This whitepaper reads the framework scheme by scheme and says plainly what each covers and who it binds. The last section splits preparation by role, because a distribution licensee and a consultancy organisation are looking at completely different parts of the same framework.
What the 22 pages cover
Look inside
.webp)











