Back to Frameworks

NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)

International (NATO — 32 members)
v2024
8 domains
8 controls

The NATO cyber defence framework is defined by the NATO Cyber Defence Policy (original 2014, updated 2021) and operationalised through the NATO Computer Incident Response Capability (NCIRC) managed by the NATO Communications and Information Agency (NCI Agency). The CCDCOE provides research and the Tallinn Manual on the International Law Applicable to Cyber Operations, but these are not NATO policy documents. Key references: NATO Cyber Defence Policy (2021), NCIRC Handbook (2022), NCI Agency publications.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (8)

Classified Systems

1 controls
Controls in the Classified Systems domain of NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)1 controls
CodeTitle
NATO-NCIRC-3Classified Network Segregation and Cryptographic Material Handling

Cyber Defence Policy

1 controls
Controls in the Cyber Defence Policy domain of NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)1 controls
CodeTitle
NATO-NCIRC-1NATO Cyber Defence Policy Alignment and Summit Declarations

Incident Response

1 controls
Controls in the Incident Response domain of NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)1 controls
CodeTitle
NATO-NCIRC-5Incident Triage, Response, and Rapid Reaction Teams

NCIRC Operations

1 controls
Controls in the NCIRC Operations domain of NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)1 controls
CodeTitle
NATO-NCIRC-2NCIRC Technical Centre Operations + NCI Agency Implementation

Personnel and Exercises

1 controls
Controls in the Personnel and Exercises domain of NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)1 controls
CodeTitle
NATO-NCIRC-7Personnel Security Clearances and Cyber Exercises

Strategic Cyber Defence

1 controls
Controls in the Strategic Cyber Defence domain of NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)1 controls
CodeTitle
NATO-NCIRC-8Cyberspace as Operational Domain + Cyber Defence Pledge + Annual Self-Assessment

Technical Controls

1 controls
Controls in the Technical Controls domain of NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)1 controls
CodeTitle
NATO-NCIRC-6Vulnerability Management, Configuration Baselines, and Supply Chain Risk

Threat Intelligence

1 controls
Controls in the Threat Intelligence domain of NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)1 controls
CodeTitle
NATO-NCIRC-4Cyber Threat Intelligence Sharing and Coordinated Vulnerability Disclosure

Your Compliance Coverage

If you comply with NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC), you already cover:

Maps to 25 other frameworks

8 total controls
FFIEC Cybersecurity Assessment Tool (CAT)
2 source controls mapped|4 target controls covered
25%
ISO/IEC 27031:2011
1 source controls mapped|2 target controls covered
13%
South Korea Cloud Security Assurance Program (CSAP)
1 source controls mapped|1 target controls covered
13%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|1 target controls covered
13%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|1 target controls covered
13%
FFIEC IT Examination Handbook
1 source controls mapped|3 target controls covered
13%
APRA CPS 234
1 source controls mapped|3 target controls covered
13%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|3 target controls covered
13%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|2 target controls covered
13%
ISO 20000-1
1 source controls mapped|1 target controls covered
13%
ISO/IEC 25012:2008 - Data Quality Model
1 source controls mapped|1 target controls covered
13%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|1 target controls covered
13%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|1 target controls covered
13%
BS 65000:2014 - Guidance on Organizational Resilience
1 source controls mapped|1 target controls covered
13%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|1 target controls covered
13%
ITIL 4
1 source controls mapped|1 target controls covered
13%
COBIT 2019
1 source controls mapped|1 target controls covered
13%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
13%
US NRC 10 CFR 73.54 - Cyber Security for Nuclear Power Plants
1 source controls mapped|1 target controls covered
13%
OWASP Top 10:2025
1 source controls mapped|1 target controls covered
13%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|1 target controls covered
13%
ISO/IEC 27400:2022
1 source controls mapped|1 target controls covered
13%
BSI IT-Grundschutz
1 source controls mapped|1 target controls covered
13%
ISO/IEC 27011:2024
1 source controls mapped|1 target controls covered
13%

Frequently Asked Questions

What is NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)?

NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) is a compliance framework from International (NATO — 32 members) with 8 domains and 8 controls. The NATO cyber defence framework is defined by the NATO Cyber Defence Policy (original 2014, updated 2021) and operationalised through the NATO Computer Incident Response Capability (NCIRC) managed by the NATO Communications and Information Agency (NCI Agency). The CCDCOE provides research and the Tallinn Manual on the International Law Applicable to Cyber Operations, but these are not NATO policy documents. Key references: NATO Cyber Defence Policy (2021), NCIRC Handbook (2022), NCI Agency publications. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) have?

NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) has 8 controls organised across 8 domains. The largest domains are Classified Systems (1 controls), Cyber Defence Policy (1 controls), Incident Response (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) map to?

NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) maps to 25 other compliance frameworks. The top mapping partners are FFIEC Cybersecurity Assessment Tool (CAT) (25% coverage), ISO/IEC 27031:2011 (13% coverage), South Korea Cloud Security Assurance Program (CSAP) (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) compliance?

Start your NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required