UK NCSC Cyber Assessment Framework
UK NCSC Cyber Assessment Framework v3.2 (used by NIS Regulations 2018 competent authorities and Cabinet Office GovAssure).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
A Managing Security Risk
| Code | Title |
|---|---|
| A1.a | Board Direction |
| A1.b | Roles and Responsibilities |
| A1.c | Decision Making |
| A2.a | Risk Management Process |
| A2.b | Assurance |
| A3.a | Asset Management |
| A4.a | Supply Chain |
B Protecting Against Cyber Attack
| Code | Title |
|---|---|
| B1.a | Policy and Process Development |
| B1.b | Policy and Process Implementation |
| B2.a | Identity Verification, Authentication and Authorisation |
| B2.b | Device Management |
| B2.c | Privileged User Management |
| B2.d | Identity and Access Management |
| B3.a | Understanding Data |
| B3.b | Data in Transit |
| B3.c | Stored Data |
| B3.d | Mobile Data |
| B3.e | Media Equipment Sanitisation |
| B4.a | Secure by Design |
| B4.b | Secure Configuration |
| B4.c | Secure Management |
| B4.d | Vulnerability Management |
| B5.a | Resilience Preparation |
| B5.b | Design for Resilience |
| B5.c | Backups |
| B6.a | Cyber Security Culture |
| B6.b | Cyber Security Training |
C Detecting Cyber Security Events
| Code | Title |
|---|---|
| C1.a | Monitoring Coverage |
| C1.b | Securing Logs |
| C1.c | Generating Alerts |
| C1.d | Identifying Security Incidents |
| C1.e | Monitoring Tools and Skills |
| C2.a | System Abnormalities for Attack Detection |
| C2.b | Proactive Attack Discovery |
D Minimising the Impact of Cyber Security Incidents
| Code | Title |
|---|---|
| D1.a | Response Plan |
| D1.b | Response and Recovery Capability |
| D1.c | Testing and Exercising |
| D2.a | Incident Root Cause Analysis |
| D2.b | Using Incidents to Drive Improvements |
Frequently Asked Questions
What is UK NCSC Cyber Assessment Framework?
UK NCSC Cyber Assessment Framework is a compliance framework from United Kingdom with 4 domains and 39 controls. UK NCSC Cyber Assessment Framework v3.2 (used by NIS Regulations 2018 competent authorities and Cabinet Office GovAssure). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does UK NCSC Cyber Assessment Framework have?
UK NCSC Cyber Assessment Framework has 39 controls organised across 4 domains. The largest domains are B Protecting Against Cyber Attack (20 controls), A Managing Security Risk (7 controls), C Detecting Cyber Security Events (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does UK NCSC Cyber Assessment Framework map to?
UK NCSC Cyber Assessment Framework does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with UK NCSC Cyber Assessment Framework compliance?
Start your UK NCSC Cyber Assessment Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK NCSC Cyber Assessment Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 39 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required