The cybersecurity topical requirement is the IIA’s minimum baseline for any assurance engagement that touches cybersecurity, and it has been in effect since 5 February 2026. It does not tell an organisation how to secure itself. It tells internal auditors which aspects of governance, risk management and control they must assess whenever cyber is in scope, and how to document the items they decide not to test.
This guide covers when it applies, how to handle exclusions, what each of the 17 items asks you to look at, how the items line up with the NIST Cybersecurity Framework 2.0, and the evidence to ask for.
What this guide covers
- What the cybersecurity topical requirement is
- When the cybersecurity topical requirement applies
- Applicability and exclusions
- The 17 items of the cybersecurity topical requirement
- Mapping the cybersecurity topical requirement to NIST CSF 2.0
- Evidence to request for a cybersecurity topical requirement engagement
- Frequently asked questions

What the cybersecurity topical requirement is
The cybersecurity topical requirement and the other Topical Requirements sit alongside the Global Internal Audit Standards as a mandatory part of the IIA’s framework. They are applied together with the Standards, not instead of them. The cybersecurity topical requirement sets a floor: the organisation’s own risk profile may justify going further, but an assurance engagement on the topic should not go below it.
It contains 17 items in three groups, matching the structure of Standard 9.1: four on governance, six on risk management and seven on controls. Assurance engagements must conform; for advisory work, conformance is encouraged rather than required. Conformance is checked during quality assessments, including the external assessment under Standard 8.4.
Free ISO 27001 risk assessment
Which of your risks sit above your appetite line?
Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.
Run the free risk assessment → or View premium report sample
When the cybersecurity topical requirement applies
The IIA gives three triggers, and any one is enough:
- Cybersecurity is an engagement in the plan. If your risk assessment put a cyber engagement in the approved plan, the requirement applies to it.
- Cyber risk surfaces during another engagement. The user guide’s example is a payables audit where the walkthrough reveals a web-based purchase request process with cyber exposure. Once that is in scope, the items must be considered.
- Someone requests a cyber engagement outside the plan. A board asking for a controls review after an attack is the obvious case.
Coverage does not have to come from one large audit. The user guide accepts conformance spread across one or more engagements in the plan, which suits functions that rotate cyber topics over a cycle. Your risk-based internal audit plan is the natural place to show which engagement covers which items.
Applicability and exclusions
Every one of the 17 items in the cybersecurity topical requirement must be assessed for applicability on each engagement where the requirement is triggered, and that assessment must be documented and kept. Excluding an item is allowed, but only with a written rationale that is also retained.
The user guide’s examples of an acceptable rationale include the item being covered by another engagement in a rotation, or the risk being of low significance in that engagement. “Not enough time” is not a rationale; it is a scope limitation, and Standard 13.3 has its own route for those. A simple applicability matrix, one row per item with a covered / excluded / covered-elsewhere status and a reference, satisfies the documentation rule and gives the quality assessor a single place to look.
The 17 items of the cybersecurity topical requirement
The item wording belongs to the IIA, so what follows is our own summary. Read the original text on the IIA’s Cybersecurity Topical Requirement page before you build test steps.
Governance (four items)
The governance items of the cybersecurity topical requirement come down to four questions. Is there a documented cyber strategy with objectives that is kept current, and does the board receive progress reports that include funding and resourcing? Are cyber policies and procedures in place and refreshed? Are cyber roles defined, and is the competence of the people in them reassessed from time to time? Do the right people across the business, including suppliers, meet to act on vulnerabilities and new threats?
Risk management (six items)
With six items, this is the largest risk management section of the four issued Topical Requirements. Does the risk process identify, analyse, treat and monitor cyber threats against strategic objectives, and does it reach beyond IT into HR, legal, supply chain, finance and operations? Is someone accountable for monitoring and reporting cyber risk, including the resources needed? Is there a fast escalation path when a risk breaches appetite or a legal obligation? Are staff made aware of cyber risk, and does management review gaps and failures and track remediation? Is there an incident response and recovery process, and is it tested?
Controls (seven items)
Are internal and supplier controls protecting confidentiality, integrity and availability, and are they evaluated periodically? Is there a training and talent process for cyber staff? Are threats and vulnerabilities monitored continuously, with improvements prioritised? Is security built into the life cycle of hardware, software and vendor services from selection to disposal? Are configuration, device management, encryption, patching, access management, availability monitoring and secure development handled? Are network controls such as segmentation, firewalls, remote-access methods, IoT controls and intrusion detection in place? Are communication channels such as email, browsers, messaging, collaboration, cloud and file sharing secured?
Mapping the cybersecurity topical requirement to NIST CSF 2.0
If the organisation already manages cyber against a framework, note that the IIA’s user guide includes its own appendix mapping each item to NIST CSF 2.0, NIST SP 800-53 and COBIT 2019. The table below is our function-level view, using the six CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond and Recover. Use it to reuse existing control testing rather than duplicate it.
| Item | What to test | CSF 2.0 function |
|---|---|---|
| G-A Strategy and board oversight | Approved strategy, refresh date, board minutes showing progress and budget | Govern |
| G-B Policies and procedures | Policy set, owners, review dates, approval trail | Govern |
| G-C Roles and competence | Role definitions, skills assessments and their dates | Govern |
| G-D Stakeholder engagement | Forum terms of reference, attendance, actions on threats | Govern |
| R-A, R-B Enterprise cyber risk | Risk register entries linked to objectives, coverage outside IT | Govern, Identify |
| R-C Accountability and reporting | Named owner, periodic cyber risk reports | Govern |
| R-D Escalation | Escalation criteria, sample of escalated risks and timing | Govern, Identify, Respond |
| R-E Awareness and remediation | Training records, management gap reviews, remediation tracking | Protect, Govern |
| R-F Incident response and recovery | Plans, test results, post-incident reviews | Respond, Recover |
| C-A Internal and vendor controls | Control inventory, evaluation results, supplier assurance | Govern, Identify, Protect, Detect |
| C-B Cyber talent and training | Technical training plans and completion | Protect |
| C-C Threat and vulnerability monitoring | Threat intelligence inputs, scan results, prioritised fixes | Identify |
| C-D Asset life cycle | Asset inventory, security in acquisition and disposal | Identify, Protect |
| C-E Hardening and access | Baselines, patch metrics, access reviews, encryption, secure development | Protect, Detect |
| C-F Network controls | Segmentation, firewall rules, remote access, IDS/IPS alerts | Protect, Detect |
| C-G Communication channels | Email, browser, collaboration and cloud configuration | Protect |
One caution: the mapping is many-to-many, so a clean CSF assessment does not automatically satisfy the cybersecurity topical requirement; check each item still has a test.
Evidence to request for a cybersecurity topical requirement engagement
A first information request for a cybersecurity topical requirement engagement should cover at least the following. Adjust it to the items you have assessed as applicable.
- The cyber strategy, its approval record and the last two board or committee updates.
- The policy register with owners and review dates.
- The cyber risk register and the enterprise register entries that reference cyber.
- Escalation criteria and a sample of escalated items.
- Incident response and recovery plans, and the latest test report with actions.
- The IT asset inventory and the vendor service inventory.
- Vulnerability and patch reports, access review results and network diagrams.
- Training records for general staff and for technical cyber staff.
Where cyber controls sit with suppliers, the Third-Party Topical Requirement may also be triggered, and the user guides expect you to consider both. Our post on the third party topical requirement covers that overlap, and our overview of the IIA topical requirements sets out all four with their effective dates.
Frequently asked questions
When did the cybersecurity topical requirement take effect?
On 5 February 2026. Each Topical Requirement becomes effective 12 months after the IIA issues it, and the cybersecurity topical requirement was the first of the four to reach its effective date.
Do we need a standalone cyber audit to conform?
No. Coverage can be spread across several engagements in the plan, provided each engagement where the requirement is triggered documents applicability for all 17 items and records why any are excluded.
Is the cybersecurity topical requirement a security framework?
No. It is a baseline for what internal audit must assess. The organisation still needs its own framework, such as NIST CSF 2.0 or ISO/IEC 27001:2022, and the topical requirement is how audit evaluates whether that approach is governed and working.
What if our team lacks cyber skills?
Standard 10.2 requires the CAE to obtain the right mix of skills or tell the board the impact of not having them. One option is co-sourcing a technical specialist for the control items, with the CAE still supervising the work under Standard 12.3.
Our Internal Audit Toolkit provides 87 editable templates built on the 2024 Standards and every item of the four issued Topical Requirements. For the cybersecurity topical requirement, it includes the Cybersecurity Audit Program and the Cybersecurity Requirement Testing Workbook, both covering all 17 items, the Topical Requirements Applicability and Exclusions Assessment for recording applicability and rationale, the IT Governance Audit Program, and the Engagement Planning Memorandum and Information Request List to scope and run the work. It is $99, in Word and Excel, ready to adapt.