NCA Critical Systems Cybersecurity Controls
NCA CSCC
What it is
The Critical Systems Cybersecurity Controls — NCA’s requirements, on top of the Essential Cybersecurity Controls, for systems whose disruption would seriously harm national interests.
What it covers
- 01Governance
- 02Defense
- 03Resilience
- 04Third-party and cloud
How we help
- Critical system identification
- CSCC gap assessment
- Hardening and monitoring review
- Remediation roadmap
In depth
The CSCC (CSCC-1:2019) builds on the Essential Cybersecurity Controls. An organization meets the ECC first, then applies the CSCC to each system it classifies as critical — with stricter rules for access, monitoring, data protection and recovery.
We start by confirming which of your systems count as critical, assess each against the controls, and leave your team a prioritized plan it can run.
Related services
Other frameworks we work with
Ready to meet NCA CSCC?
Tell us where you stand. We will show you the shortest path to what your regulator expects.
Built around the regulators you answer to
Ready to talk about your compliance?
Tell us where you stand. We will show you the shortest path to what your regulator expects.