Sorry, you need to enable JavaScript to visit this website.
Skip to main content

About CDCAT®

46
%
of organizations don’t know they’ve been breached
69
%
of organizations don’t have a formal plan
43
%
of UK businesses have been attacked
85
%
of CEOs say cybersecurity is critical for growth

CDCAT® Overview

Image
Three professionals working together at a computer, smiling and reviewing lines of code displayed on a large screen.

Benefits of CDCAT®

For Individuals

  • Strengthen Analytical Thinking in Cyber Defence.
  • Learn to interpret assessment data and performance indicators to make informed decisions about cyber risk and resilience. 
  • Build confidence in applying cyber frameworks.
  • Gain hands-on experience in applying mapped controls from multiple standards, helping you confidently contribute to audit preparation and strategic planning. 
  • Understand how specific controls, processes and practices can be adopted by an organisation and how they interconnect to create a cyber security strategy.
  • Understand how standards, framework, guidance or report has been mapped to a variety of control groups.
  • Develop skills which help you develop a best practice cyber defence strategy.
  • Explore up to date security standards.

For Organizations

  • Clear visibility of cyber maturity which allows you to gain a detailed understanding of your organisation’s current cyber defence posture across people, processes, and technology.
  • Identification of Vulnerabilities - Pinpoint specific weaknesses before they are exploited — enabling proactive remediation and risk reduction.
  • Actionable Insights and KPIs- Receive tailored reports with performance indicators and prioritised recommendations to guide strategic decisions.
  • Compliance Readiness - Ensure alignment with key standards like ISO 27001, NIST, PCI-DSS, and Cyber Essentials — supporting audit preparation and regulatory compliance.
  • Cost and Time Efficiency - Save thousands in audit costs and reduce assessment time from weeks to days with automated, consultant-led evaluations.
  • Strategic Planning Support - Use assessment outcomes to inform cybersecurity investment, workforce planning, and board-level reporting.
  • Repeatable and Scalable - Apply the same framework across departments, regions, or business units — ensuring consistency and comparability.

    Documentation

    Document thumbnail
    pdf - 264 KB - 17 June 2025
    Document thumbnail
    pdf - 256.32 KB - 17 June 2025

    Videos

    Videos

    Understand and manage your cyber security with CDCAT

    | 3 minutes 9 seconds

    FAQs

    CDCAT® (Cyber Defence Capability Assessment Tool) is a scientifically developed framework that evaluates your organisation’s cyber defence maturity across people, processes, and technology. It helps identify vulnerabilities, benchmark performance, and guide strategic improvements. 

    CDCAT® provides a structured assessment aligned with global standards (e.g. ISO 27001, NIST, Cyber Essentials), helping organisations understand gaps, reduce risk, and build long-term resilience. 

    Yes, CDCAT® is scalable and cost-effective, starting at £1,250. It’s designed to support organisations of all sizes—from small businesses to multinational corporations.

    CDCAT® maps controls from widely recognised standards including ISO 27001, PCI-DSS, NIST, Cyber Essentials, and more—making it ideal for multi-framework environments.

    A typical CDCAT® Classic Assessment takes around 1 week, significantly faster than traditional audits which can take 6 weeks or more.

    You’ll receive a tailored report with performance indicators, a high-level action plan, and detailed insights using the TEPIMOIL framework—helping you prioritise and plan effectively. 

    The TEPIMOIL framework is used as a checklist by the UK Ministry of Defence to prevent new equipment from being delivered without the necessary support systems. The principle of "Interoperability" is also considered an overarching theme that links the Defence Lines of Development (DLoDs) together.  The acronym stands for:  

    • Training: Ensuring that personnel are properly prepared and have the necessary skills.
    • Equipment: Providing the right platforms, weapons, and tools.
    • Personnel: Having enough people with the right skills and motivation.
    • Information: Delivering and managing the information needed for command and control.
    • Management: Understand whether policies and decisions are supporting enhanced security appropriately.
    • Organisation: Creating the right structures and chains of command.
    • Infrastructure: Supplying the physical bases, facilities, and support systems.
    • Logistics: Managing the supply, maintenance, and support of the capability.  

    Organisations often use a mix of tools, platforms, and vendors. Interoperability ensures these systems can communicate and work together to detect, respond to, and prevent threats effectively. Interoperability also facilitates easier mapping to regulatory frameworks (e.g. ISO 27001, NIST) by enabling consistent data collection and reporting across systems.

    Absolutely. CDCAT® streamlines audit readiness by mapping controls, identifying gaps, and providing consultant-led guidance to prepare for external reviews.

    Yes. CDCAT® is developed using science licensed by the UK Ministry of Defence and is used by organisations including the City of London Police and critical national infrastructure providers.

    Get in touch

    If you have a query about this certification or want to know more about training send us a message via this contact form. We would love to hear from you!

    Get in touch

    Have you found what you need on this page?