Authority reference
Guide to Developing a National Cybersecurity Strategy
Third Edition, 2025 (v3) · ISBN 978-92-61-42091-8
A multistakeholder reference for national leaders and policymakers developing or revising a National Cybersecurity Strategy. Produced with 37 contributors. Flexible and tailored to national context — civilian and defensive focus.
Process + content
How the Guide is organised
Two axes: a development process (Lifecycle) and strategy content (Principles + Focus Areas).
Lifecycle I–VI
- IInitiation
- IIStocktaking
- IIISustainable Funding · v3 emphasis
- IVProduction
- VImplementation
- VIMonitoring & Evaluation
Principles 4.1–4.10
- 4.1 Vision
- 4.2 Comprehensive & tailored
- 4.3 Inclusiveness
- 4.4 Economic & social prosperity
- 4.5 Human rights
- 4.6 Risk management & resilience
- 4.7 Policy instruments
- 4.8 Leadership, roles & resources
- 4.9 Trust environment
- 4.10 Technological foresight & adaptability (new in v3)
Focus Areas 5.1–5.7
- 5.1 Governance
- 5.2 Critical infrastructure, CII & essential services
- 5.3 Risk management
- 5.4 Incident response
- 5.5 Capability, capacity & awareness
- 5.6 Legislation & regulation
- 5.7 International cooperation
Editions
Compatibility with v2
Guide 2025 builds on the 2021 Second Edition. Core process and content ideas carry forward. Notable v3 additions include Phase III (Sustainable Funding), Principle 4.10 (foresight), and deeper Focus Area practice — so v2 checklists are not a 1:1 map.
This tool
How Strategy Alignment relates
An alignment assessment against Guide v3 — Lifecycle, Principles, and Focus Areas — using an app-defined Full / Partial / Absent / N/A scale. Not an official Guide score; the Guide itself has no maturity scale.