Make readiness visible.
Use these prompts to open a team discussion and identify the next piece of work. Your selections stay in this browser session only and do not certify compliance.
We have recorded entities, services and relevant jurisdictions.
An accountable owner coordinates the programme.
Critical services and material cyber risks have been assessed.
Controls and policies have assigned owners.
Escalation and reporting paths have been rehearsed.
Recovery arrangements have been exercised.
Critical direct suppliers are mapped and reviewed.
Management receives decisions and progress reports.
Use this as a conversation starter
An answered prompt may still need testing, documentation and national legal review. Assign an owner to each gap and verify the evidence behind each response.
Official sources and context
Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.