The RACF-CC Framework

Resource-aware cybersecurity for organisations that cannot compromise on care.

RACF-CC helps care charities turn recognised cybersecurity principles into affordable, prioritised and measurable action—without assuming enterprise budgets, specialist teams or a dedicated security operations centre.

RACF-CC framework icon
New to RACF-CC? The Starter Path guides you through one manageable improvement—from defining scope and gathering evidence to safe implementation and a defensible outcome. Use the Starter Path →

Designed for operational reality

Strong controls, proportionate delivery

Care charities hold sensitive information and depend on reliable services, yet commonly work with constrained budgets, small technology teams, legacy systems and limited monitoring. RACF-CC preserves the intent of established security guidance while adapting implementation to those realities.

The framework prioritises controls by likely risk reduction, implementation effort, operational impact and cost. Progress is demonstrated through evidence rather than tool ownership or compliance claims alone.

01

Risk-led

Start with realistic attack paths and service consequences.

02

Resource-aware

Make effective use of existing people, platforms and licensing.

03

Care-conscious

Balance protection with continuity, accessibility and safeguarding.

04

Evidence-led

Measure whether controls are deployed, sustained and effective.

A different job, not a competing standard

How RACF-CC complements established frameworks

Established frameworks describe recognised cybersecurity outcomes, controls and management practices. RACF-CC focuses on the local implementation question: how can a resource-constrained organisation turn relevant principles into proportionate, prioritised and evidenced action?

Established frameworksWhat good cybersecurity should achieve

Provide authoritative outcomes, requirements, principles or safeguards against which an organisation can structure its programme.

RACF-CCHow a constrained organisation can make defensible progress towards it

Adds a practical method for sequencing work around credible risk, available resources, operational impact and evidence.

Framework or approachWhat it providesWhere RACF-CC helps
NIST CSF 2.0 and the NIST SP 800 seriesHigh-level cybersecurity outcomes, a risk-management structure and detailed security guidance.Helps translate relevant outcomes and guidance into a manageable sequence based on local risk, evidence and delivery constraints.
ISO/IEC 27001Requirements for an information security management system, centred on risk, governance and continual improvement.Helps connect governance intent to practical technical work that a small team can implement and evidence. It does not replace formal ISO requirements or certification.
CIS Controls v8.1 and IG1Prioritised, practical safeguards, including an essential cyber-hygiene starting point through Implementation Group 1.Adds local prioritisation around hybrid infrastructure, legacy dependencies, care-service impact, compensating controls and residual risk.
Zero Trust ArchitecturePrinciples and architectural models built around explicit verification, resource protection and the removal of implicit trust.Provides a staged route towards those principles where legacy systems, incomplete visibility or operational constraints make the target state difficult to implement immediately.
RACF-CC is not a substitute for NIST, ISO/IEC 27001, CIS Controls or Zero Trust Architecture.

Where an organisation has a contractual, regulatory, certification or formal assurance requirement, the relevant standard or framework should be used directly. RACF-CC helps organisations decide how to move towards recognised security outcomes when resources and operational constraints make full implementation difficult.

See RACF-CC applied in practice. The anonymised worked case study shows measurable improvements across identity, endpoint, vulnerability and data controls—and explains why headline assessment scores did not reveal the whole story. Read the case study →

Eight connected domains

A complete path from prevention to assurance

Each domain can be adopted in stages, but the strongest results come from treating them as one connected system.

Layered defence

How the eight domains reinforce each other

RACF-CC treats cybersecurity as a connected system. Each domain addresses a different part of risk, but the strongest outcomes come when controls reinforce one another across identity, devices, networks, data, monitoring, response and governance.

Layers, not a mandatory sequence. Organisations may work across several domains at the same time according to risk and operational need.

The relationships are not purely linear. A single security outcome often depends on several domains working together, as the examples below show.

Cross-cutting guidance: supplier and third-party risk. Identify the external relationships behind important services, apply assurance according to consequence and govern shared dependencies across the domains. Use the supplier-risk guide →

Control connections

Security outcomes cross domain boundaries

A control is rarely delivered or assured by one domain alone. These examples show how technical controls, operational processes and governance combine into one outcome.

Implementation cycle

From evidence to sustainable improvement

Understand

Establish the current state using configuration, telemetry, policy and operational evidence.

Prioritise

Rank controls by risk reduction, effort, service impact and cost.

Implement

Deliver realistic controls in manageable phases with clear ownership.

Evidence

Validate outcomes, record residual risk and feed learning into the next cycle.

Report progress without claiming compliance. The RACF-CC Control Assurance model distinguishes implementation, current evidence and sustained operation while keeping residual-risk decisions visible. Explore control assurance →
Independent framework statement. RACF-CC is an independently developed framework informed by recognised cybersecurity standards and guidance, including the NIST SP 800 series, NIST Cybersecurity Framework, Zero Trust principles, ISO/IEC 27001 and CIS Controls. It is not affiliated with or endorsed by NIST or those other organisations.