The ECC is the floor, and most organisations are assessed against more than the floor. The industrial control domain moved out to the OTCC in 2024, cloud brings in the CCC, critical systems bring in the CSCC — and a self-assessment that scores only the ECC will look finished when it is not.

This assessment covers all 28 subdomains of ECC-2:2024 plus the scoping, other-control-set and reporting questions that decide what you are actually held to. It is free, it saves as you go, and you can stop and come back to it.

What this is

A structured pass over all 28 subdomains of ECC-2:2024, plus the scoping and reporting questions that decide what the NCA actually holds you to. We have the background elsewhere — the four domains explained, the compliance guide, implementation in six steps, the official Assessment and Compliance Tool and all seven NCA control sets. Come here when you want a score.

What it covers

DomainSubdomains assessed
Scope and applicability — version, systems, conditional controls, ownership6
1 Cybersecurity Governance10
2 Cybersecurity Defence15
3 Cybersecurity Resilience2
4 Third-Party and Cloud Computing2
Other NCA control sets — CCC, CSCC, OTCC, DCC, telework and social media5
Assessment and reporting4

The ECC is rarely the whole obligation

ECC-2:2024 replaced ECC-1:2018 and removed the industrial control systems domain, which moved to the separate Operational Technology Cybersecurity Controls. That pattern repeats: if you use cloud services the Cloud Cybersecurity Controls apply, if you operate critical systems the Critical Systems Cybersecurity Controls apply, and data handling brings in the Data Cybersecurity Controls. The ECC is the floor, not the ceiling, and a self-assessment that scores only the ECC will read as complete when it is not. This assessment asks which of the other sets you are in scope for, so the omission is visible.

Scoring here, and scoring in the NCA tool

The NCA’s own Assessment and Compliance Tool uses four status values and submits through the Haseen platform. This assessment uses a five-step scale instead, because it separates “implemented” from “implemented and evidenced” — and evidence is what your compliance level actually turns on. Map your results across when you file; use this to find what is missing first.

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records someone could sample
Not applicableA justified exclusion, removed from the score

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every subdomain with your status and notes, the score broken down by domain, a prioritised gap list, and the documents from the NCA Cybersecurity Toolkit that close each gap — as a PDF and a working Excel file.

How long does it take?

About 25 minutes. Cybersecurity Defence is 15 of the 28 subdomains and carries most of it.

What to do with your score

Below 40% — start with domain 1. Strategy, governance, policies and roles are prerequisites in the ECC’s own structure, and the defence controls are assessed against them.

40–70% — check the conditional controls. Several subdomains only bite if you use the technology in question, and scoring them zero when they do not apply distorts the picture in the wrong direction.

Above 70% — move to evidence and to the other control sets. The two mistakes that cost most are a scope that omits a control set and a control with no record behind it.

Frequently asked questions

Is this assessment really free?

Yes. All 44 questions, the domain breakdown and your overall score cost nothing. The $39 report is optional.

Is this the official NCA self-assessment?

No. The official one is the NCA’s Assessment and Compliance Tool, submitted through Haseen. This is an independent gap assessment you run first, to find out what you would be declaring.

Who has to comply?

Government organisations and their contractors, and organisations operating critical national infrastructure. Many private organisations adopt it as good practice or because a contract requires it.

ECC-1:2018 or ECC-2:2024?

This scores ECC-2:2024. If you last assessed against ECC-1, expect the industrial control subdomain to be gone and several control statements to have changed.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.