Build and mature your Cyber Defence Center¶
A free, vendor-neutral, community-maintained framework for Security Operations Centers and Cyber Defence Centers in the European Union — built on NIST CSF 2.0, anchored in the CIA triad, and mapped to NIS2, GDPR, DORA and the laws of all 27 member states.
Read the framework Start here: first 90 days Assess your maturity
-
New to this? Start guided.
The introduction explains the design principles, Start here orders your first 90 days and first year, and the implementation tiers tell you which capabilities apply at your size — Essential, Standard or Advanced.
-
The six functions
Govern · Identify · Protect · Detect · Respond · Recover — each with concrete capabilities, CIA mapping, maturity criteria and EU regulatory hooks.
-
EU regulatory layer
NIS2, GDPR, DORA, CRA and CER mapped to CDC capabilities, national annexes for all 27 member states, and the interactive regulatory profile selector that tailors the references to the laws that apply to you.
-
People & skills
ECSF-based roles, career paths and hiring, plus team skill mapping: your team fills in the self-assessment sheet, you upload the results into the Team Skill Matrix and see gaps, mentors and what to hire for. Data never leaves your browser.
-
Templates & playbooks
Ready-to-copy templates — charter, IR plan, detection use cases, KPIs, job descriptions — and IR & forensics playbooks for Windows 11, macOS and Linux servers.
-
Open and community-maintained
Everything is CC BY 4.0 on GitHub: read about the project, see the roadmap, or contribute — national annexes especially welcome. Need it offline? Download the whole framework as a zip from GitHub.
Scope
The framework targets enterprise IT environments (endpoints, servers, identity, cloud/SaaS). It is not designed for OT/ICS, telco core networks or classified environments — see About for the reasoning. Orientation only — not legal advice.