Board Cyber Governance Assessment: could your board demonstrate compliance today?
Score your board against all 22 actions of the UK Cyber Governance Code. Free, instant. Aligned to the NCSC Board Toolkit. Results in under 5 minutes.
Score your board against all 22 actions of the UK Cyber Governance Code. Free, instant. Aligned to the NCSC Board Toolkit. Results in under 5 minutes.
It is the standard for board-level cyber governance published by the Department for Science, Innovation and Technology with the National Cyber Security Centre in April 2025. It sets out 22 actions across five principles (risk management, strategy, people, incident planning, and assurance and oversight) that directors are expected to own.
The Code itself is voluntary, but it is the benchmark regulators, insurers and acquirers increasingly hold boards to, and the Cyber Security and Resilience Bill -- introduced to Parliament in November 2025 and now in committee -- raises the cost of ignoring it materially. Treating it as optional is a board decision with consequences.
The NCSC Cyber Security Board Toolkit is the National Cyber Security Centre's guidance for boards on governing cyber risk. The Code of Practice turns that guidance into 22 specific actions a board is expected to own. This assessment scores you against those 22 actions, so it works as a practical companion to the Board Toolkit: the Toolkit tells you what good governance looks like, this tells you where yours actually stands and what to fix first.
Cyber security governance is how the board directs and oversees cyber risk: who is accountable, how risk decisions are made, what the board sees and challenges, and how it gains assurance that controls work. It is distinct from the technical controls themselves. This assessment measures the governance, not the firewall, which is why it needs no technical knowledge to complete.
Chairs, non-executive directors, CEOs, and audit or risk committee chairs. It needs no technical knowledge. It asks what your board could evidence today, not how your IT is configured.
Each of the 22 actions is rated against four behaviourally anchored levels, from absent to assured. You declare whether each answer rests on documents, knowledge or belief, and the tool grades the reliability of your own profile. Each principle is constrained by its weakest action, the way an assurance reviewer would read it.
You answer all 22 actions and receive a principle-by-principle maturity profile, the exact gap to the Code's bar, the evidence artefact to create for each gap, and an honest grade of how defensible your answers are.
No. It is a readiness signal based on what you tell it. An assurance review tests the artefacts themselves. Where your answers rest on belief rather than documents, treat them as the audit findings they would become.