Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient - No AI Slop!
ComplianceForge

NCP 2026.4

Aligns the NCP with Q2 wording changes from the SCF, rebrands the CDPP as the Security, Compliance & Resilience Program (SCRP), and restructures the CSOP around a RASCI model.

What changed in this release

  • Aligned with wording changes from the Q2 release of the Secure Controls Framework (SCF). The SCF’s domain principles were updated, which led to updating the policy statements associated with those domains.
  • The Cybersecurity & Data Protection Program (CDPP) was rebranded as the Security, Compliance & Resilience Program (SCRP).
  • The Cybersecurity Standardized Operating Procedures (CSOP) was not rebranded, but was updated to follow a Responsible, Accountable, Supporting, Consulted and Informed (RASCI) structure for how the procedures can be managed. The CSOP is still based on the NIST NICE Cybersecurity Workforce Framework for roles and responsibilities standardization, but it is now organized by RASCI assignment.
  • For clients receiving the updated version, changes in the policies, standards and procedures are highlighted in green in the Word documents.
  • The authoritative mappings used to determine necessary policies, standards and procedures are the Set Theory Relationship Mapping (STRM) documents located in the “Reference - Crosswalk Mappings” folder.

Did You Purchase An Older Version Of This Product?

Releases older than 2024 (2023 and beyond) are not covered by this errata archive and are significantly out of date. Existing customers are encouraged to repurchase the current version at 50% of the original product price.