The European Union Agency for Cybersecurity (ENISA) has launched version 2.0 of its National Capabilities Assessment Framework (NCAF), a strategic tool designed to assist European Union member states in evaluating and strengthening their national cybersecurity posture. The updated framework provides a structured methodology and an online tool for national authorities to assess the implementation maturity of their National Cybersecurity Strategies (NCSS). NCAF 2.0 is closely aligned with the requirements of the NIS2 Directive, aiming to promote a consistent and high level of cybersecurity capability across the EU.
NCAF 2.0 is not a binding regulation but a voluntary framework that offers a comprehensive methodology for self-assessment. Its primary goal is to help member states:
At the EU level, the framework is intended to facilitate mutual learning, the sharing of best practices, and a common understanding of cybersecurity capabilities across all member states.
The primary users of the NCAF 2.0 are the national authorities responsible for cybersecurity in each of the 27 EU member states. This typically includes:
While use of the NCAF is voluntary, its alignment with the NIS2 Directive makes it a highly relevant tool for demonstrating compliance. The NIS2 Directive mandates a higher common level of cybersecurity across the EU, and the NCAF provides a practical way for member states to measure their progress toward meeting these new, more stringent requirements. The framework helps authorities structure their efforts to build capacity in areas such as incident response, risk management, supply chain security, and public-private partnerships, all of which are key components of NIS2.
NCAF 2.0 is available for use by member states immediately. Its release is timely, as member states are currently in the process of transposing the NIS2 Directive into their national laws and developing strategies to meet its requirements. The framework is designed to be a continuous improvement tool, used periodically to reassess maturity and adjust national strategies accordingly.
The adoption of NCAF 2.0 is expected to have a positive impact on the overall cybersecurity resilience of the EU.
For national authorities looking to use NCAF 2.0, ENISA recommends the following steps:
The NCAF framework is a form of structured audit and self-assessment designed to measure and improve cybersecurity capabilities.
The framework helps nations assess their ability to guide and enforce secure configurations at a national level.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats