Skip to content

Evidence request lists

NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Classified Systems

NATO-NCIRC-3
Classified Network Segregation and Cryptographic Material Handling

Maintain strict segregation of NATO classified networks (NATO Restricted / NATO Confidential / NATO Secret / Cosmic Top Secret) from unclassified networks per AC/35-D/2002 + AC/35-D/2004 + AC/35-D/2005 NATO Security Policies. Apply cross-domain solutions (CDS) per AC/322(SC/4)WP(2017) Communication Information System Cryptographic Policy. Handle COMSEC material per ACO Directive 70-1 + NATO Comsec Authority (NCSA). Implement TEMPEST controls + media sanitisation and destruction per NATO Industrial Security TEMPEST programme.

Artefacts an auditor will ask for
  • Network architecture diagram showing classification levels
  • Cross-domain solution authorisation
  • COMSEC custody records
  • NCSA inspection report
  • TEMPEST zoning certificate
  • Media destruction certificate
Where this commonly fails
  • No segregation evidence
  • Unauthorised CDS
  • Lapsed COMSEC custody
  • No TEMPEST zoning

Cyber Defence Policy

NATO-NCIRC-1
NATO Cyber Defence Policy Alignment and Summit Declarations

Align with the NATO Cyber Defence Policy first established at the 2008 Bucharest Summit + revised at the 2014 Wales Summit (recognising cyberspace as a domain of operations + reaffirmed at 2016 Warsaw Summit as a domain of operations equal to land + sea + air) + further revised at the 2021 Brussels Summit (Comprehensive Cyber Defence Policy with explicit Article 5 application + 2023 Vilnius Summit (counter-hybrid + ransomware framing) + 2024 Washington Summit declaration (75th anniversary + Integrated Cyber Defence Centre activation at SHAPE Mons). Maintain national alignment via Allied Cyber Defence Plan + Comprehensive Approach + NATO Defence Planning Process (NDPP) cyber chapter.

Artefacts an auditor will ask for
  • National Cyber Defence Strategy referencing NATO policy
  • Summit declaration acknowledgement
  • NDPP cyber chapter compliance
  • Allied Cyber Defence Plan participation
  • Cyber Defence Pledge progress report
  • Article 5 cyber threshold analysis
Where this commonly fails
  • No reference to NATO policy
  • Missing summit alignment
  • No NDPP cyber chapter
  • Outdated Pledge report

Incident Response

NATO-NCIRC-5
Incident Triage, Response, and Rapid Reaction Teams

Operate incident triage and categorisation per NATO incident severity matrix (Cat I to Cat V) aligned with NCIRC reporting taxonomy. Maintain capability to support NATO Rapid Reaction Teams (RRT) per the Cyber Defence Pledge - deployable cyber experts who can be activated within 48 hours to assist NATO nations under significant cyber attack. Coordinate with EU Cyber Diplomacy Toolbox + UN Group of Governmental Experts (GGE) + Open-Ended Working Group (OEWG) responsible state behaviour norms. Maintain incident logs for minimum 7 years.

Artefacts an auditor will ask for
  • Incident response plan with NATO severity categories
  • RRT deployment readiness evidence
  • Incident log retention (7 years)
  • NCIRC notification records
  • EU Cyber Diplomacy Toolbox alignment
  • NATO-EU joint exercise records
Where this commonly fails
  • No NATO severity alignment
  • Missing RRT capability
  • Short incident retention
  • No NATO-EU coordination

NCIRC Operations

NATO-NCIRC-2
NCIRC Technical Centre Operations + NCI Agency Implementation

Operate or interface with the NATO Computer Incident Response Capability (NCIRC) technical centre run by the NATO Communications and Information (NCI) Agency from SHAPE (Mons Belgium) + NATO HQ (Brussels) covering 24/7 monitoring + intrusion detection + threat hunting + incident response + forensics across all NATO enterprise networks (NS-WAN + NU-WAN + missions and operations). Integrate with the NATO Cyber Defence Committee + NC3 Board (NATO Consultation Command and Control Board) + Cyber Defence Management Authority (CDMA) governance. NCIRC Full Operational Capability achieved 2014 + Cyberspace as a Domain of Operations 2016 + Cyber Operations Centre (CYOC) at SHAPE 2018.

Artefacts an auditor will ask for
  • NCIRC Memorandum of Understanding
  • 24/7 SOC roster
  • NCI Agency liaison appointment
  • Cyber Defence Committee report
  • NC3 Board technical report
  • CYOC integration evidence
Where this commonly fails
  • No NCIRC MoU
  • Lack of 24/7 capability
  • Missing NCI Agency liaison
  • No NC3 Board reporting

Personnel and Exercises

NATO-NCIRC-7
Personnel Security Clearances and Cyber Exercises

Maintain personnel security clearances per AC/35-D/2000 NATO Personnel Security Policy (CONFIDENTIAL/SECRET/COSMIC TOP SECRET investigations + reinvestigations every 5 years + continuous evaluation). Verify need-to-know and need-to-share controls. Conduct cyber exercises including NATO Cyber Coalition (annual, largest NATO cyber exercise involving 30+ nations) + Locked Shields hosted by CCDCOE in Tallinn (largest live-fire cyber exercise globally with 2000+ participants) + Crossed Swords (red team focused) + national tabletops. Maintain training records aligned to NATO Cyber Range curriculum.

Artefacts an auditor will ask for
  • Personnel clearance register
  • 5-year reinvestigation schedule
  • Cyber Coalition participation evidence
  • Locked Shields participation evidence
  • Tabletop exercise reports
  • NATO Cyber Range training records
  • Need-to-know verification
Where this commonly fails
  • Outdated clearances
  • No Cyber Coalition
  • Skipped Locked Shields
  • Missing tabletops

Strategic Cyber Defence

NATO-NCIRC-8
Cyberspace as Operational Domain + Cyber Defence Pledge + Annual Self-Assessment

Recognise cyberspace as an operational domain per 2016 Warsaw Summit + integrate cyber effects into NATO planning and operations. Submit annual Cyber Defence Pledge progress report to the Cyber Defence Committee covering: national cyber defence strategy progress + cyber budget commitments (target 2% of GDP defence spending with cyber proportion increasing) + cyber expertise gaps + NCIRC capability contributions + Rapid Reaction Team contributions. Achieve and report progress against Cyber Defence Pledge targets adopted at 2016 Warsaw Summit. Participate in Article 5 collective defence in cyberspace where applicable.

Artefacts an auditor will ask for
  • Cyber Defence Pledge progress report
  • Annual self-assessment to NATO
  • Cyber-in-operations doctrine
  • Budget evidence for cyber proportion
  • Cyber expertise inventory
  • RRT contribution record
  • Article 5 cyber consultations evidence
Where this commonly fails
  • No Pledge report
  • No cyber budget tracking
  • Missing self-assessment
  • Cyber not integrated into operations

Technical Controls

NATO-NCIRC-6
Vulnerability Management, Configuration Baselines, and Supply Chain Risk

Apply NATO-specific configuration baselines for NATO-Authorised Information and Communications Systems (ICS) per AC/322(SC/4) Cryptographic Policy + STANAG 4774 Confidentiality Metadata Binding. Conduct continuous vulnerability scanning + patch management within risk-based timelines (Critical 7 days + High 30 days + Medium 90 days). Apply Software Bill of Materials (SBOM) requirements per NATO Software Supply Chain guidance + NCI Agency Acquisition Policy. Pre-screen suppliers via NATO Industrial Advisory Group (NIAG) + national agencies (NSA + GCHQ + ANSSI + BfV + AISI + AIVD + others) for cyber adversary nation linkages.

Artefacts an auditor will ask for
  • NATO configuration baselines
  • Vulnerability scan reports
  • Patch management metrics with NATO timelines
  • SBOM evidence per ICS
  • Supplier pre-screening record
  • NIAG submission
  • National security agency screening evidence
Where this commonly fails
  • No NATO baselines
  • Patches exceed timeline
  • Missing SBOM
  • No supplier pre-screening

Threat Intelligence

NATO-NCIRC-4
Cyber Threat Intelligence Sharing and Coordinated Vulnerability Disclosure

Participate in NATO cyber threat intelligence sharing via Malware Information Sharing Platform (MISP) instances operated by NCIRC + Cyber Threat Assessment Cell (CTAC) at SHAPE + bilateral channels with NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) in Tallinn Estonia. Apply STIX/TAXII formats per CCDCOE recommendations. Operate Coordinated Vulnerability Disclosure programme per CCDCOE Tallinn Manual 3.0 guidance + ISO/IEC 29147. Share indicators of compromise (IOCs) + tactics techniques and procedures (TTPs) with allied nations within 24-48 hours.

Artefacts an auditor will ask for
  • MISP instance configuration
  • CTAC liaison appointment
  • CCDCOE collaboration record
  • STIX/TAXII feed configuration
  • CVD policy aligned with ISO 29147
  • IOC sharing log
  • TTP analysis reports
Where this commonly fails
  • No MISP integration
  • Missing CTAC liaison
  • No CVD policy
  • Stale IOC feeds
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NATO Cyber Defence Policy and NATO Computer Incident Response Capability (NCIRC) framework page.