Governance, Risk & Compliance

NCA ECC Compliance

Assessment and preparation for compliance with the Essential Cybersecurity Controls (ECC) issued by the National Cybersecurity Authority

We assess your current compliance level against NCA ECC-2 controls and prepare a detailed remediation roadmap, with implementation support and documentation for full compliance.

What's included

  • Determine the applicability of ECC-2:2024 controls to the entity and define the systems, data and sites in scope
  • Assess the implementation level of each control across the four domains and 28 subdomains
  • Close gaps in the Cybersecurity Governance domain (strategy, policies, roles, risk management and compliance)
  • Strengthen the Cybersecurity Defence domain (asset protection, identity, network security, cryptography and vulnerability management)
  • Implement the Resilience and the Third-Party and Cloud Computing Cybersecurity domains, covering business continuity and contracts
  • Prepare compliance evidence for the National Cybersecurity Authority's measurement and self-assessment tool

Methodology & standards

01

Scope and applicability: define the systems in scope and the controls applicable to the entity's nature of business

02

Current-state assessment: measure each control's implementation level and document existing evidence

03

Remediation plan: prioritize gaps and define the projects, policies and technical controls required

04

Implementation and documentation: support control implementation, author policies and procedures and collect evidence

05

Assessment readiness: prepare the entity for the measurement and self-assessment tool and quantify the compliance percentage

Deliverables

  • A current-state assessment report with each control's implementation level across the four domains
  • A gap register and a remediation roadmap prioritized with timelines
  • An ECC policy and procedure set covering Governance, Defence, Resilience and Third-Party
  • A compliance evidence matrix mapped to each control
  • A readiness file for the Authority's measurement and self-assessment tool
  • An executive report on the overall compliance percentage and investment priorities

Regulatory controls it satisfies

NCA ECC-2:2024
Compliance with the Essential Cybersecurity Controls across four domains, 28 subdomains and over one hundred controls at an implementation level accepted by the Authority
NCA CSCC (Critical Systems Cybersecurity Controls)
A separate, additional framework binding on entities operating critical systems, applied alongside the essential controls
NCA CCC (Cloud Cybersecurity Controls)
Applies when systems or data are hosted with cloud service providers
NCA OTCC (Operational Technology Cybersecurity Controls)
Applies to operational technology and industrial control environments, now separate from the essential controls

Typical timeline

The gap assessment phase is typically completed in three to six weeks, while full remediation implementation spans three to six months depending on the size of the gaps.

Common questions

Does ECC apply to the private sector or only to government?

It applies to government entities and their affiliates and to national entities operating critical national infrastructure; many private-sector organizations comply contractually when serving these entities.

What is the difference between ECC and CSCC?

ECC is the essential baseline for all organizations, while CSCC is a stricter, additional set specific to critical systems, applied on top of the essential controls rather than instead of them.