The Audits page helps you prepare for and track NCA compliance audits. Whether it is an internal assessment or a formal NCA audit, this module keeps your preparation organised and your findings tracked.

Audit Types

TypeDescription
Self-AssessmentInternal review conducted by your cybersecurity team to evaluate ECC readiness
Internal AuditFormal internal audit by your organisation's audit function or internal audit department
NCA AuditOfficial audit conducted by or on behalf of the National Cybersecurity Authority
Third-Party AssessmentAssessment by an external cybersecurity consultancy

Creating an Audit

Start a new audit

Click "New Audit". Select the audit type, enter the audit date range, and assign a lead auditor.

Define scope

Select which ECC domains are in scope for this audit. For a full NCA audit, all 5 domains should be selected. For targeted assessments, select only the relevant domains.

Track findings

As the audit progresses, record findings using the "Add Finding" button. Each finding captures the control reference, severity (Critical, High, Medium, Low), description, and recommended corrective action.

Assign corrective actions

For each finding, create a corrective action with an owner, target date, and description. The owner receives email notifications and the action appears on their personal dashboard.

Finding Severity Levels

SeverityDefinitionExpected Response
CriticalControl completely absent; immediate risk to operationsRemediate within 30 days
HighControl partially implemented with significant gapsRemediate within 60 days
MediumControl implemented but effectiveness not demonstratedRemediate within 90 days
LowMinor improvement opportunity; control is largely effectiveAddress in next review cycle

Corrective Action Tracking

Open findings with corrective actions are tracked in a dedicated view. Filter by status (Open, In Progress, Closed), severity, owner, or due date. Overdue actions are highlighted in red on both the audit page and the responsible user's dashboard.

ℹ️
NCA audits often request evidence packages on short notice. Keep your evidence library current and linked to the correct controls to speed up audit preparation.