NCSC Cloud Security Principles
All 14 principles with published goal sections and provider/customer evidence review
All available frameworksWhat the app checks
Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.
Explicit requirement-to-test mappings
| Requirement | Collector / test | What it checks or supports |
|---|---|---|
| 1 | CERTTLS / CERTTLS-POSTURE-001 | Supporting observation only for the observed customer assets. Independently verify complete scope, 14-day fix deadlines, actual MFA enforcement, permitted malware alternatives and provider assurance as applicable. No certification or provider conformity from a scan. |
| 2 | STORAGE / STOR-AT-REST-ENCRYPTION-001 | Supporting observation only for the observed customer assets. Independently verify complete scope, 14-day fix deadlines, actual MFA enforcement, permitted malware alternatives and provider assurance as applicable. No certification or provider conformity from a scan. |
| 2 | BACKUP / VEEAM-REPO-001 | Supporting observation only for the observed customer assets. Independently verify complete scope, 14-day fix deadlines, actual MFA enforcement, permitted malware alternatives and provider assurance as applicable. No certification or provider conformity from a scan. |
| 5 | VULN / VULN-IMPORT-001 | Supporting observation only for the observed customer assets. Independently verify complete scope, 14-day fix deadlines, actual MFA enforcement, permitted malware alternatives and provider assurance as applicable. No certification or provider conformity from a scan. |
| 9 | ENTRA / ENTRA-GUEST-001 | Supporting observation only for the observed customer assets. Independently verify complete scope, 14-day fix deadlines, actual MFA enforcement, permitted malware alternatives and provider assurance as applicable. No certification or provider conformity from a scan. |
| 10 | ENTRA / ENTRA-MFA-REG-001 | Supporting observation only for the observed customer assets. Independently verify complete scope, 14-day fix deadlines, actual MFA enforcement, permitted malware alternatives and provider assurance as applicable. No certification or provider conformity from a scan. |
| 11 | WINDOWS / WIN-FW-001 | Supporting observation only for the observed customer assets. Independently verify complete scope, 14-day fix deadlines, actual MFA enforcement, permitted malware alternatives and provider assurance as applicable. No certification or provider conformity from a scan. |
| 12 | ADSEC / AD-PRIV-001 | Supporting observation only for the observed customer assets. Independently verify complete scope, 14-day fix deadlines, actual MFA enforcement, permitted malware alternatives and provider assurance as applicable. No certification or provider conformity from a scan. |
What requires manual review
Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.
Cloud service assurance guidance; no certification, provider endorsement or automatic conformity. Suggested implementations remain optional approaches. Contains public sector information from the UK National Cyber Security Centre, licensed under the Open Government Licence v3.0: https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/. Text reformatted; ITAF review identifiers, evidence actions and supporting mappings added. No NCSC endorsement.
Where it is available
This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.
Coverage shown here comes from the application’s C32 requirement and mapping catalogs.