The NCNICC Category (B) controls checklist: what your organization actually needs
If you're Category (B) — small and medium organizations (6 to 249 employees) — the NCNICC-1:2025 controls require you to apply 26 core controls across 13 domains, within the National Cybersecurity Authority's framework. This page walks through them in practical terms, domain by domain, so you know what's required of you — and where you stand today.
Not sure of your category? Start here: Do the NCNICC controls apply to you?
How are the controls structured?
Category (B) controls sit within a single main component containing 13 sub-components (domains) and 26 core controls, spanning three areas: cybersecurity governance, cybersecurity defense, and third-party & cloud security.
The NCNICC controls are organized into three main components: cybersecurity governance, cybersecurity defense, and third-party & cloud cybersecurity. Category (B) requirements concentrate on the practical fundamentals that genuinely protect your organization, with the heavier governance items eased.
Domain group one: governance and awareness
The governance and awareness area for Category (B) covers two main items: a staff awareness and training program, and cybersecurity policies, procedures, and risk management.
- Awareness and training program — train your staff on the main threats: phishing, ransomware, strong passwords, and reporting suspicious behavior. (This is one of the highest-impact things you can do in a small organization.)
- Cybersecurity policies, procedures, and a governance and risk-management framework — recommended, even in a simplified form.
Domain group two: cybersecurity defense (the core of your requirements)
The defense area holds the largest share of Category (B) controls, and covers: asset management, identity and multi-factor authentication, protection of systems/devices/email, network and mobile-device security, data protection and encryption, backups, vulnerability management and penetration testing, and event logging.
This is where most of what Category (B) needs sits:
- Asset management — an accurate, up-to-date inventory of your devices, systems, and information.
- Identity and access management — secure identity verification, multi-factor authentication (MFA) for remote access (email and external applications), least-privilege access, and periodic review.
- Systems and device protection — protection against viruses and malware, changing default configurations, and time synchronization from a trusted source.
- Email protection — filtering phishing and intrusive mail, and authenticating your mail domain with SPF, DKIM, and DMARC.
- Network security management — firewalls, secure access gateways, wireless-network security, and network segmentation.
- Mobile-device security — protecting laptops and phones, and governing personal-device (BYOD) use where permitted.
- Data and information protection — secure data handling, print security, and secure disposal of assets and documents.
- Encryption — encrypting data at rest and in transit, using modern methods per the national standards.
- Backups — periodic backups of sensitive business systems, and periodic testing to confirm you can restore.
- Vulnerability management — regular patching of systems and software, and periodic vulnerability scanning.
- Penetration testing — testing externally exposed services (websites, web applications, email, and remote access).
- Event logging and security monitoring — enabling logs on sensitive assets and monitoring them to detect attacks.
- Incident management, physical security, and web-application protection.
Domain group three: third parties and cloud
The third-party and cloud area requires you to secure what you share with external service providers and what you host in the cloud — because the responsibility to protect doesn't end at your office walls.
- Secure what you share with external service providers and what you host in the cloud — your responsibility doesn't stop at your office walls.
The 13 mandatory domains for Category (B)
The controls that are mandatory for Category (B) — 26 core controls across 13 domains — all sit within the "cybersecurity defense" component. Each domain has two mandatory controls: defining the requirement, and applying it. Governance, awareness, and third-party & cloud security are recommended for Category (B), not mandatory.
- Asset management
- Identity and access management
- Protection of systems and information-processing devices
- Email protection
- Network security management
- Mobile-device security
- Data and information protection
- Encryption
- Backup management
- Vulnerability management
- Event-log management and security monitoring
- Cybersecurity incident and threat management
- Physical security
These 13 domains are the mandatory sub-components for Category (B) within the NCNICC-1:2025 framework. To know the exact status of each control for your organization, the assessment determines it item by item.
Source: the National Cybersecurity Authority's NCNICC-1:2025 document (classification: public).
What "mandatory" vs "recommended" means
The framework classifies each control for your category as either mandatory (must be applied) or recommended (encouraged). For Category (B), the mandatory scope concentrates on practical defense and awareness, while some of the heavier governance items are recommended. To know the exact status of each control for your organization, the best way is the assessment — it walks you through your category's items one by one.
How do you know where you stand against this list?
Rather than guess, find out. The free assessment (8 minutes) takes you through the Category (B) controls and gives you an instant report showing what you have, what's missing, and where to start — no technical expertise needed, and without your data being shared.
Review your compliance item by item — free
Start your assessment now (8 minutes) →Frequently asked questions
How many Category (B) controls are there?
26 core controls across 13 domains (sub-components).
Are all controls mandatory for Category (B)?
No — some are mandatory and some are recommended. The mandatory scope concentrates on practical defense and awareness, and the assessment shows the status of each control for your organization.
Where do I start?
Start with the high-impact fundamentals: awareness, multi-factor authentication (MFA), backups, and patching — then complete the remaining domains.
Source for the control structure and its domains: the National Cybersecurity Authority's NCNICC-1:2025 document (document classification: public). The exact "mandatory/recommended" status of each control for your category is set out in the official document and clarified by the SecurityRelief assessment.
