Get Demo
Free Self-Assessment · ECC–2:2024 · Client-Side Only

NCA ECC–2:2024 Compliance Checklist

Score your readiness across the four Essential Cybersecurity Controls domains — 28 high-value checkpoints with a live progress bar. Nothing is saved or sent; mark cloud items N/A if they do not apply.

Readiness: 0%
0 / 28 applicable

Check Off Your ECC–2:2024 Posture

Representative highest-value checkpoints per domain — not all 108 main controls. Use this as a fast readiness pulse before a formal gap assessment.

Domain 1 · 8 checkpoints

Cybersecurity Governance

Strategy, management, policies, roles, risk, projects, review, HR & awareness

What auditors typically look for Approved strategy & policy versions with dates; org chart / RACI for cyber roles; recent risk register samples; project security evidence; audit findings + remediation tracking; awareness completion records.
Domain 2 · 8 checkpoints

Cybersecurity Defense

Assets, IAM, protection, crypto, backup/vuln, pen test, logging (2-12), incidents & apps

What auditors typically look for Asset lists with owners; IAM evidence (privileged accounts, access reviews); SIEM/log retention proof for 2-12; vulnerability scan and penetration-test reports with closure status; incident playbooks and sample tickets.
Domain 3 · 6 checkpoints

Cybersecurity Resilience

Cyber resilience aspects of Business Continuity Management (3-1)

What auditors typically look for BCM policy referencing cyber resilience; BIA extracts for critical services; joint incident-response / BCM runbooks; test schedules and after-action reports showing remediation.
Domain 4 · 6 checkpoints

Third-Party & Cloud Computing Cybersecurity

Supplier controls (4-1) and cloud/hosting (4-2) — mark cloud N/A if not used

What auditors typically look for Contract clause samples; vendor risk assessments; cloud inventory + shared-responsibility matrix; cloud IAM/logging/config evidence (where subdomain 4-2 applies).

Your ECC Self-Assessment Summary

Percentage updates as you check items. Cloud (4-2) items marked N/A are excluded from the total so the score stays fair.

Overall readiness

0%

Below 50% — Foundational work needed

Core ECC building blocks are missing or incomplete across domains. Prioritise strategy/governance ownership, baseline Defense controls (especially 2-12 logging), and a clear remediation roadmap.

Book a Gap Assessment

50–75% — Targeted remediation

Foundations exist, but material gaps remain. Focus remediation on unchecked high-impact areas (IAM, monitoring retention, BCM integration, third-party clauses) and evidence readiness for assessment.

Book a Gap Assessment

76–90% — Close the gaps

You are close on these checkpoints. Close remaining items, harden evidence packs, and validate 2-12 retention/monitoring before self-assessment or field review.

Book a Gap Assessment

Above 90% — Strong posture

Strong self-assessed coverage on these representative checkpoints. Confirm continuous evidence and full control mapping beyond this sample — then keep assessment-ready year-round.

Book a Gap Assessment
ScoreInterpretation
< 50%Foundational work needed
50–75%Targeted remediation
76–90%Close the gaps
> 90%Strong posture

Progress is calculated only in your browser. No checklist answers are stored or transmitted.

Checklist Questions

What does this NCA ECC checklist cover?

This tool covers a representative set of 28 high-value checkpoints across ECC–2:2024’s four domains — Governance, Defense, Resilience, and Third-Party & Cloud. It is not a substitute for assessing all 108 main controls. See the full NCA ECC hub for domain context.

Is my checklist data saved or sent anywhere?

No. Progress is calculated entirely in your browser with client-side JavaScript. Nothing is stored on a server or transmitted to CyberSilo when you check items.

Why can I mark cloud items as N/A?

ECC–2:2024 subdomain 4-2 (Cloud Computing and Hosting Cybersecurity) applies to entities currently using or planning to use cloud computing and hosting services. Marking those two checkpoints N/A excludes them from the denominator so organisations without cloud are not penalised (28 → 26 applicable).

How should I interpret the readiness score?

Below 50% typically means foundational work is needed; 50–75% suggests targeted remediation; 76–90% means close remaining gaps; above 90% indicates a strong self-assessed posture for these checkpoints. Scores are directional aids — not an official NCA assessment result.

How does this relate to the full ECC–2:2024 control set?

ECC–2:2024 comprises 4 domains, 28 subdomains, 108 main controls, and 92 subcontrols. This checklist samples the highest-value checkpoints per domain for a fast readiness pulse. For a full gap assessment mapped to all controls, book a CyberSilo ECC gap assessment.

Ready for a full ECC gap assessment?

Turn this self-check into a structured remediation plan across all four domains — including 2-12 logging/monitoring with ThreatHawk SIEM.