NCA's DCC–1:2022 sets additional cybersecurity requirements for protecting data throughout its life cycle. It extends the Essential Cybersecurity Controls and includes its own scope, compliance and monitoring context. See the NCA DCC publication page.
Use in a programme
Identify the data in scope, its classification, where it is held and who handles it. Review protection across collection, use, sharing, storage and disposal rather than assessing a storage system alone.
Connect responsibilities and evidence to the actual data flows. Review third-party handling and changes in processing context as part of ongoing maintenance.
Use in CSFaaS
The reviewed library contains NCA DCC-1:2022 - EN. Verify its source and imported structure before assigning assessment work.
Use the shared information-type and classification vocabulary when documenting Systems and Third Parties. Link the policies and evidence that support the relevant DCC requirements, and record any additional workspace requirements separately from the publisher's text.
Use the applicable NCA materials to determine obligations; an internal maturity score does not establish compliance with data-protection legislation or every DCC requirement.