Back to Frameworks

UK NCSC Cyber Assessment Framework

United Kingdom
4 domains
39 controls

UK NCSC Cyber Assessment Framework v3.2 (used by NIS Regulations 2018 competent authorities and Cabinet Office GovAssure).

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

A Managing Security Risk

7 controls
Controls in the A Managing Security Risk domain of UK NCSC Cyber Assessment Framework7 controls
CodeTitle
A1.aBoard Direction
A1.bRoles and Responsibilities
A1.cDecision Making
A2.aRisk Management Process
A2.bAssurance
A3.aAsset Management
A4.aSupply Chain

B Protecting Against Cyber Attack

20 controls
Controls in the B Protecting Against Cyber Attack domain of UK NCSC Cyber Assessment Framework20 controls
CodeTitle
B1.aPolicy and Process Development
B1.bPolicy and Process Implementation
B2.aIdentity Verification, Authentication and Authorisation
B2.bDevice Management
B2.cPrivileged User Management
B2.dIdentity and Access Management
B3.aUnderstanding Data
B3.bData in Transit
B3.cStored Data
B3.dMobile Data
B3.eMedia Equipment Sanitisation
B4.aSecure by Design
B4.bSecure Configuration
B4.cSecure Management
B4.dVulnerability Management
B5.aResilience Preparation
B5.bDesign for Resilience
B5.cBackups
B6.aCyber Security Culture
B6.bCyber Security Training

C Detecting Cyber Security Events

7 controls
Controls in the C Detecting Cyber Security Events domain of UK NCSC Cyber Assessment Framework7 controls
CodeTitle
C1.aMonitoring Coverage
C1.bSecuring Logs
C1.cGenerating Alerts
C1.dIdentifying Security Incidents
C1.eMonitoring Tools and Skills
C2.aSystem Abnormalities for Attack Detection
C2.bProactive Attack Discovery

D Minimising the Impact of Cyber Security Incidents

5 controls
Controls in the D Minimising the Impact of Cyber Security Incidents domain of UK NCSC Cyber Assessment Framework5 controls
CodeTitle
D1.aResponse Plan
D1.bResponse and Recovery Capability
D1.cTesting and Exercising
D2.aIncident Root Cause Analysis
D2.bUsing Incidents to Drive Improvements

Frequently Asked Questions

What is UK NCSC Cyber Assessment Framework?

UK NCSC Cyber Assessment Framework is a compliance framework from United Kingdom with 4 domains and 39 controls. UK NCSC Cyber Assessment Framework v3.2 (used by NIS Regulations 2018 competent authorities and Cabinet Office GovAssure). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does UK NCSC Cyber Assessment Framework have?

UK NCSC Cyber Assessment Framework has 39 controls organised across 4 domains. The largest domains are B Protecting Against Cyber Attack (20 controls), A Managing Security Risk (7 controls), C Detecting Cyber Security Events (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does UK NCSC Cyber Assessment Framework map to?

UK NCSC Cyber Assessment Framework does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with UK NCSC Cyber Assessment Framework compliance?

Start your UK NCSC Cyber Assessment Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK NCSC Cyber Assessment Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 39 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required