NCNICC-1:2025 addresses cybersecurity for private-sector entities that are not critical infrastructure. Before treating it as your mandatory baseline, establish the organization's classification and whether NCA has circulated the controls to it.
The official NCA document, particularly printed pages 5 and 7, sets out applicability and distinguishes Class A and Class B. Its tables identify 65 main controls for Class A and 26 for Class B. The circulation condition matters: employee count alone is not the complete applicability test.
Use the official classification and seek clarification where your circumstances or a boundary case are unclear. Organizations outside the mandatory scope can still use the controls as a reference for improving security.
Turn the applicable controls into a work register
For each applicable requirement, record the system scope, owner, current implementation, evidence and remaining action. Keep the regulatory requirement distinct from the engineering method chosen to satisfy it.
A useful register should answer practical questions. Who owns the asset inventory? Which accounts have privileged access? How are changes reviewed? What happens when a backup test fails? Where are incident records retained?
Avoid beginning with a product list. The assessment should identify the gap before a tool is purchased.
Sequence the infrastructure work
Start by mapping assets and dependencies. Without that scope, it is difficult to know whether patching, monitoring and recovery cover the systems that matter.
Then work through the operational foundations:
- Identity and access, including privileged accounts and remote access.
- Supported configurations, patch ownership and exception handling.
- Backup scope and measured recovery tests.
- Logging, alert ownership and incident escalation.
- Network boundaries and controlled management access.
This is a suggested engineering sequence, not an NCA-prescribed inspection order. Adjust it to the organization's risks and applicable requirements.
Keep evidence in normal operations
Build records into the work itself: approved changes, access reviews, patch results, incident tickets and recovery-test reports. Each record should identify what was checked, when, by whom and what action followed.
A policy and an operating control are different forms of evidence. Make sure the documented process matches what the team actually does. Review gaps after changes to staffing, systems or service providers.
Coordinate with privacy responsibilities
Cybersecurity and privacy work can share inventories and incident processes, but they have different requirements and owners. The PDPL Implementing Regulations should be assessed separately where personal data is involved.
A cybersecurity tool or a completed control checklist does not establish legal compliance by itself. Agree how the technical team will support the people responsible for interpreting and demonstrating the organization's obligations.
Where the asset inventory includes networked cameras or door controllers, the physical security planning guide covers coverage, access permissions and handover checks.
BustanTech provides managed infrastructure services and backup and recovery services. Contact us to discuss a technical gap assessment with defined scope and evidence deliverables.