1. Establish scope and ownership
Map entities, services, countries and possible annex categories. Name an accountable programme owner and capture classification assumptions for review.
2. Assess services, risks and dependencies
Connect critical services to systems, people and suppliers. Compare current measures with the applicable legal and operational requirements.
3. Prioritise and implement
Use risk and service impact to plan improvements in incident handling, continuity, access, supply chain, vulnerability handling and training. Assign action owners and decision dates.
4. Document, exercise and review
Keep policies and evidence current. Exercise escalation and recovery. Review changes in the organisation and national framework at a regular cadence.
| Phase | Working output |
|---|---|
| Scope | Entity and service map |
| Assess | Risk and gap record |
| Deliver | Owned improvement plan |
| Operate | Test and review evidence |
Official sources and context
Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.