NCCIC
NCCIC, now operating as CISA, is the U.S. federal cybersecurity and critical infrastructure security agency under DHS, providing free threat intelligence, vulnerability management, incident response coordination, and binding directives to federal civilian agencies, critical infrastructure operators, and the public.
- Company typePublic
- Founded2018
- HeadquartersWashington, United States
- Headcount101–250
- GTM typeB2B
- OfferingServices
What NCCIC does
NCCIC (National Cybersecurity and Communications Integration Center), now operating as the Cybersecurity and Infrastructure Security Agency (CISA), is the operational component of the U.S. Department of Homeland Security responsible for cybersecurity and critical infrastructure security across the United States. Established in 2015 as NCCIC and reorganized under CISA in 2018, the agency serves as the national coordinator for critical infrastructure security and resilience across 16 sectors (energy, water, transportation, healthcare, financial services, etc.) and as the central hub for cyber threat information sharing, vulnerability management, and incident response coordination among federal civilian agencies, state/local/tribal/territorial governments, critical infrastructure operators, and the public.
CISA's core offerings are delivered as free, non-commercial services through the cisa.gov portal, 10 regional offices, and partnership programs. Key technical products include the Known Exploited Vulnerabilities (KEV) Catalog, Industrial Control Systems (ICS) advisories, Binding Operational Directives (BODs) that mandate federal agency remediation, the Joint Cyber Defense Collaborative (JCDC), the Protected Critical Infrastructure Information (PCII) Program, StopRansomware.gov, SAFECOM for emergency communications interoperability, CISA GitHub for open-source tooling, and CISA Central for incident reporting (1-844-Say-CISA). The agency also issues joint advisories with the FBI and partners with the Five Eyes alliance (US, UK, Canada, Australia, New Zealand).
As a U.S. federal government agency, CISA/NCCIC does not generate commercial revenue and is funded entirely through congressional appropriations under DHS oversight. Pricing is uniformly zero across all audiences, and distribution is direct via website, regional offices, and collaborative partnerships rather than commercial channels.
NCCIC firmographics
Firmographics- Name
- NCCIC
- Legal name
- Cybersecurity and Infrastructure Security Agency
- Website
- https://us-cert.gov
- Company type
- Public
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- NCCIC, now operating as CISA, is the U.S. federal cybersecurity and critical infrastructure security agency under DHS, providing free threat intelligence, vulnerability management, incident response coordination, and binding directives to federal civilian agencies, critical infrastructure operators, and the public.
- Ownership category
- akta.pro rank
NCCIC industry classification
Industry- Product category
- Government Cybersecurity Services
- NAICS
- National Security (928110)
- akta.pro primary industry
- Cyber Defense & Information Security (National Security) (BPAIAHAE)
Keywords
Where NCCIC is headquartered
LocationHeadquarters
- HQ city
- Washington
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
NCCIC business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Infrastructure, Others
Revenue model
- Federal Government Appropriations: As a U.S. federal government agency under the Department of Homeland Security, CISA is funded through congressional appropriations and does not generate revenue from commercial activities.
Go-to-market motion1 record
Distribution channels4 records
Marketing channels6 records
NCCIC product offering
Product offeringCore offering
NCCIC (National Cybersecurity and Communications Integration Center), now operating under CISA (Cybersecurity and Infrastructure Security Agency), serves as the U.S. government's central hub for cyber threat information sharing, incident response coordination, and critical infrastructure protection. It delivers free cybersecurity resources, threat advisories, vulnerability catalogs (such as the Known Exploited Vulnerabilities Catalog), Industrial Control Systems guidance, Binding Operational Directives to federal agencies, training, assessments, and coordinates the Joint Cyber Defense Collaborative (JCDC) to unify cyber defenders globally.
Product overview
CISA (Cybersecurity and Infrastructure Security Agency) is America's cyber defense agency and the national coordinator for critical infrastructure security and resilience. The agency offers a unified platform of free cybersecurity and physical security resources rather than a commercial product. The core offerings include CISA Resources & Tools (technical assistance, exercises, assessments, and training), the CISA Services Catalog (access to services across mission areas), and CISA Training (cybersecurity and critical infrastructure education). Key programs include the Joint Cyber Defense Collaborative (JCDC) for unified cyber defense, StopRansomware.gov for ransomware resources, SAFECOM for emergency communications, the Protected Critical Infrastructure Information (PCII) Program, CISA GitHub for open-source tools, and CISA Central for incident reporting. All services are provided at no cost to support government agencies, critical infrastructure operators, and the public.
Differentiator
Problem solved
Functional benefit
Products and services
- CISA Resources & Tools A suite of free resources and tools provided by CISA including technical assistance, exercises, cybersecurity assessments, and free training for government agencies, critical infrastructure operators, and the public.
Quantifiable outcome
- BOD 26-04 requires federal agencies to rapidly remediate high-risk vulnerabilities with comprehensive implementation guidance
- +1 more outcomes
Companies that use NCCIC
Customer profileSegments5 records
Ideal customer profiles5 records
NCCIC technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
NCCIC partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered flagship and core.
- ANCHOR-CI (Advisory National Councils for Homeland Operational Resilience - Critical Infrastructure)flagshipANCHOR-CI is a new advisory body framework designed to strengthen information sharing and broaden partnerships across government and industry to secure the nation's critical infrastructure. This framework represents a significant expansion of CISA's collaborative approach to national critical infrastructure protection.
- Joint Cyber Defense Collaborative (JCDC)coreJCDC unifies cyber defenders from organizations worldwide. The collaborative proactively gathers, analyzes, and shares actionable cyber risk information to enable synchronized, holistic cybersecurity planning, cyber defense, and response. CISA has expanded JCDC to include industrial control systems focus areas.
- Five Eyes AlliancecoreCISA participates in the Five Eyes intelligence-sharing alliance with partner nations to coordinate cybersecurity efforts and share threat intelligence. Five Eyes members include the United States, United Kingdom, Canada, Australia, and New Zealand.
- FBI (Federal Bureau of Investigation)coreCISA and FBI jointly issue public service announcements on cyber threats, including recent advisories on Russian Intelligence Services targeting commercial messaging applications. This partnership enables coordinated law enforcement and civilian cyber defense.
- DHS (Department of Homeland Security)coreCISA is a component agency of the Department of Homeland Security. CISA operates CISA Central and falls under DHS oversight, reporting structures, and departmental policies.
Scale indicators1 record
Recent moves7 records
Expansion highlights6 records
NCCIC competitors and assessment
Company assessmentDirect peers
- National Cyber Security Centre (NCSC UK): United Kingdom's national cybersecurity authority and a core Five Eyes partner. Operates an almost identical model — issuing advisories, coordinating critical infrastructure protection, and providing free services to government and private sector — making it the closest international counterpart to CISA.
- Australian Cyber Security Centre (ACSC / ASD): Australia's national cybersecurity hub within the Australian Signals Directorate. Five Eyes alliance member with directly comparable mission scope: threat advisories, incident response, critical infrastructure protection, and government cybersecurity guidance.
- Canadian Centre for Cyber Security (CCCS): Canada's national cybersecurity authority under the Communications Security Establishment. Five Eyes partner with parallel responsibilities for federal cyber defense, critical infrastructure protection, threat intelligence sharing, and citizen-facing cybersecurity guidance.
- National Cyber Security Centre New Zealand (NCSC NZ): New Zealand's national cyber security authority and Five Eyes member. Operates a near-identical mandate covering CERT functions, critical infrastructure protection, government cybersecurity services, and threat advisories.
Broad incumbents
- National Security Agency (NSA): U.S. national-level signals intelligence and cybersecurity agency with overlapping cybersecurity defense responsibilities. Both operate at the federal layer protecting national assets, though NSA holds offensive/foreign intelligence authorities that complement CISA's civilian domestic focus.
- ENISA (European Union Agency for Cybersecurity): EU-wide cybersecurity agency coordinating cyber defense across member states. Comparable in convening and standards-setting role, though operating at supranational level with less direct operational authority than CISA.
Regional players
- ANSSI (France): France's national cybersecurity agency under the national cybersecurity authority (ANSSI). Operates a similar civilian-focused mandate covering critical infrastructure, government cybersecurity, and threat intelligence — relevant for international benchmarking rather than direct competition.
Others
- FBI Cyber Division: Domestic federal law enforcement cyber unit that partners with CISA on joint advisories and incident response. Overlaps in threat intelligence and incident coordination but operates under law enforcement authority rather than civilian defense mandate.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
NCCIC social profiles
Digital presenceNCCIC financial estimates
Financial estimateRevenue estimate
Valuation estimate
NCCIC leadership team
Management profileNumber of profiles
NCCIC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
NCCIC M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about NCCIC
What does NCCIC do?
NCCIC (National Cybersecurity and Communications Integration Center), now operating under CISA (Cybersecurity and Infrastructure Security Agency), serves as the U.S. government's central hub for cyber threat information sharing, incident response coordination, and critical infrastructure protection. It delivers free cybersecurity resources, threat advisories, vulnerability catalogs (such as the Known Exploited Vulnerabilities Catalog), Industrial Control Systems guidance, Binding Operational Directives to federal agencies, training, assessments, and coordinates the Joint Cyber Defense Collaborative (JCDC) to unify cyber defenders globally.
Is NCCIC a public or private company?
NCCIC is a public company. It is classified as state government owned and is currently operating.
When was NCCIC founded?
NCCIC was founded in 2018. It employs 101 to 250 people.
Where is NCCIC based?
NCCIC is headquartered in Washington, United States, in the North America region.
How does NCCIC make money?
One revenue line is on record: federal Government Appropriations.
Who are NCCIC's main competitors?
Direct peers on record are National Cyber Security Centre (NCSC UK), Australian Cyber Security Centre (ACSC / ASD), Canadian Centre for Cyber Security (CCCS) and National Cyber Security Centre New Zealand (NCSC NZ). Broad incumbents are National Security Agency (NSA) and ENISA (European Union Agency for Cybersecurity). ANSSI (France) is listed as a regional player. FBI Cyber Division is listed as an others.
Does NCCIC have an API?
No public API is recorded for NCCIC.
What industry is NCCIC in?
NCCIC's product category is Government Cybersecurity Services. Its primary akta.pro industry code is BPAIAHAE, Cyber Defense & Information Security (National Security). Its NAICS code is 928110.