UK CYBER RESILIENCE · 2026

EVIDENCE INTELLIGENCE FOR CYBER ASSURANCE

Could you evidence your
cyber resilience today?

Cyber assurance, made clearer.

Could you evidence your
cyber resilience today?

SIFTR turns organisational evidence into traceable cyber assurance findings — showing what your evidence supports, where gaps may exist, and where human review is needed.

SIFTR turns organisational evidence into traceable cyber assurance findings.

Controlled scope · Evidence traceability · Human judgement retained

Controlled scope · Evidence traceability · Human judgement

CAF OUTCOME · A2.a — Policy and process

HUMAN REVIEW REQUIRED

EVIDENCE REFERENCES · 02 CONNECTED

Information Security Policy.pdf

PAGE 14 · §4.2

SOURCE DOCUMENT EXTRACT

“The policy is reviewed annually by the Information Security Steering Group.”

POTENTIAL EVIDENCE GAP — No evidence of review effectiveness was identified in the supplied material.

THE EVIDENCE PROBLEM

Your cyber evidence exists. Finding out what it demonstrates is the hard part.

Your cyber evidence exists. Finding out what it demonstrates is the hard part.

POLICY

RISK REGISTER

PEN TEST

STANDARD

GOVERNANCE

SUPPLIER

INCIDENT

TECHNICAL CONTROL

EVIDENCE → OUTCOMES → GAPS → ACTIONS

SIFTR organises the initial evidence picture. Professionals investigate, challenge and judge it.

From documents to defensible evidence.

From documents to defensible evidence.

SIFTR · EVIDENCE WORKSPACE
TRACEABLE · REVIEWABLE
ORGANISATIONAL EVIDENCE3 SOURCES
PDF
Information Security Policy.pdf
Risk governance and accountable ownership
XLSX
Enterprise Risk Register.xlsx
Risk treatment and review evidence
PDF
Security Governance TOR.pdf
Committee oversight and cadence
SIFTR
NCSC CAFOBJECTIVE A
A2Risk Management
Supporting evidence identified · 3 sources
Source reference
Information Security Policy.pdf
Page 14 · Section 4.2
“The policy is reviewed annually by the Information Security Steering Group.”
Potential evidence gap
No evidence of review effectiveness was identified in the supplied material.
Human review required
3
Sources
1
Potential gap
HUMAN
Review

A clear view of the evidence behind the outcome.

A clear view of the evidence behind the outcome.

CAF A2.a — Policy and process

SUPPORTING EVIDENCE IDENTIFIED · 3 SOURCES

Information Security Policy.pdf
Risk Management Standard.pdf
Security Governance Terms of Reference.pdf

The supplied evidence describes governance responsibilities, but does not clearly demonstrate how effectiveness is periodically reviewed.

HUMAN REVIEW REQUIRED

START SMALL

How ready are you to evidence your CAF position?

How ready are you to evidence your CAF position?

Request a complimentary Evidence Readiness Check using a controlled sample of organisational evidence.

Request a complimentary Evidence Readiness Check using a controlled sample of organisational evidence.

Controlled scope. No certification claim. Human review remains essential.

CAF EVIDENCE READINESS

Evidence identified — 24
Outcomes explored — 8
Potential gaps — 5
Human review areas — 3
Evidence sources — 12

Automation where it helps. Judgement where it matters.

Automation where it helps. Judgement where it matters.

SIFTR

  • Find evidence

  • Organise evidence

  • Map evidence

  • Surface supporting extracts

  • Identify potential gaps

  • Maintain traceability

ASSURANCE PROFESSIONAL

  • Challenge

  • Interpret

  • Validate

  • Investigate

  • Exercise judgement

  • Sign off

SIFTR assists assurance. It doesn’t certify it.

Evidence intelligence demands trust.

Evidence intelligence demands trust.

SECURITY & UK HOSTING
How SIFTR protects and hosts organisational evidence.
View security →


DATA PROTECTION
How information is handled throughout the SIFTR workflow.
View data protection →


AI GOVERNANCE
Where automation assists — and where human judgement remains.
View AI governance →


AUDITABILITY & LOGIC
Evidence provenance, traceability and reviewable outputs.
View auditability →


FRAMEWORK ALIGNMENT
How SIFTR supports evidence review against recognised frameworks.
View alignment →

SECURITY & UK HOSTING
How SIFTR protects and hosts organisational evidence.
View security →


DATA PROTECTION
How information is handled throughout the SIFTR workflow.
View data protection →


AI GOVERNANCE
Where automation assists — and where human judgement remains.
View AI governance →


AUDITABILITY & LOGIC
Evidence provenance, traceability and reviewable outputs.
View auditability →


FRAMEWORK ALIGNMENT
How SIFTR supports evidence review against recognised frameworks.
View alignment →


Explore the SIFTR Trust Centre →

START SMALL

What would SIFTR find in your evidence?

What would SIFTR find in your evidence?

Request a complimentary CAF Evidence Readiness Check using a controlled sample of organisational evidence. No evidence upload is required at this stage.


WHAT YOU’LL RECEIVE

  • Evidence identified

  • Relevant CAF outcomes

  • Source references

  • Potential evidence gaps

  • Areas requiring professional review


01 — ABOUT YOU 02 — YOUR ASSURANCE 03 — CURRENT EVIDENCE

Complimentary · Controlled scope · No certification claim