Free tool
Where does your entity stand on ECC-2:2024?
Twenty-one general questions across the four main domains of the NCA Essential Cybersecurity Controls. Answer them and you get an indicative picture of your readiness and where the gaps sit.
We collect nothing. The check runs entirely inside your browser — no sign-up, no email, and your answers are never sent anywhere. Answer candidly; candour is the only thing that makes the result useful to you.
·
Your indicative result
By domain
Where to start
These are the items you marked not implemented or partial, ordered the way a roadmap orders them: what unblocks the rest comes first.
Read this before acting on it
- This is an indicative result based on your own answers — not a compliance assessment, an audit or a certificate, and not something to submit to a regulator.
- ECC-2:2024 carries 108 main controls and 92 subcontrols across 28 subdomains. Twenty-one questions give you direction, not detail.
- The real test is evidence, not documents: a control counts as implemented when an operational record exists and can be produced in minutes — not when a policy is signed.
- Applicability is settled first: government or critical national infrastructure, a contractual pass-through, or voluntary adoption — each sets a different bar for what "done" means.
Want the real number?
A real gap assessment walks the controls one by one against their evidence, and produces a control register and a roadmap sequenced by risk and dependency. It starts with a session to understand your scope and situation.
Or directly: +966 53 689 0919 · info@fyntralink.com