We assess your current compliance level against NCA ECC-2 controls and prepare a detailed remediation roadmap, with implementation support and documentation for full compliance.
What's included
- Determine the applicability of ECC-2:2024 controls to the entity and define the systems, data and sites in scope
- Assess the implementation level of each control across the four domains and 28 subdomains
- Close gaps in the Cybersecurity Governance domain (strategy, policies, roles, risk management and compliance)
- Strengthen the Cybersecurity Defence domain (asset protection, identity, network security, cryptography and vulnerability management)
- Implement the Resilience and the Third-Party and Cloud Computing Cybersecurity domains, covering business continuity and contracts
- Prepare compliance evidence for the National Cybersecurity Authority's measurement and self-assessment tool
Methodology & standards
Scope and applicability: define the systems in scope and the controls applicable to the entity's nature of business
Current-state assessment: measure each control's implementation level and document existing evidence
Remediation plan: prioritize gaps and define the projects, policies and technical controls required
Implementation and documentation: support control implementation, author policies and procedures and collect evidence
Assessment readiness: prepare the entity for the measurement and self-assessment tool and quantify the compliance percentage
Deliverables
- A current-state assessment report with each control's implementation level across the four domains
- A gap register and a remediation roadmap prioritized with timelines
- An ECC policy and procedure set covering Governance, Defence, Resilience and Third-Party
- A compliance evidence matrix mapped to each control
- A readiness file for the Authority's measurement and self-assessment tool
- An executive report on the overall compliance percentage and investment priorities
Regulatory controls it satisfies
Typical timeline
The gap assessment phase is typically completed in three to six weeks, while full remediation implementation spans three to six months depending on the size of the gaps.
Common questions
Does ECC apply to the private sector or only to government?
It applies to government entities and their affiliates and to national entities operating critical national infrastructure; many private-sector organizations comply contractually when serving these entities.
What is the difference between ECC and CSCC?
ECC is the essential baseline for all organizations, while CSCC is a stricter, additional set specific to critical systems, applied on top of the essential controls rather than instead of them.
From the same practice