Overview
The CSCF groups its controls under three objectives and seven principles. The 2026 framework contains 32 controls in total: 26 mandatory and 6 advisory. Mandatory controls apply to your architecture type; advisory controls often preview future mandates.
| Secure your environment | Know and limit access | Detect and respond |
|---|---|---|
| Restrict internet access, protect critical systems, reduce the attack surface, and physically secure the zone. | Prevent credential compromise, manage identities, and segregate privileged access. | Detect anomalous activity across systems and records, and plan for incident response and information sharing. |
Self-attestation without verification is no longer permitted. Each member must complete an annual Independent Assessment Framework (IAF) review, carried out by an independent external assessor or an autonomous internal audit function.

