National Capabilities Assessment Framework 2.0
TLP - CLEAR
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework – 2026 Edition APRIL 2026
National Capabilities Assessment Framework 2.0
About ENISA
The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu.
CONTACT
For contacting the authors, please use info@enisa.europa.eu For media enquiries about this paper, please use press@enisa.europa.eu
LEGAL NOTICE
This publication represents the views and interpretations of ENISA, unless stated otherwise. It does not endorse a regulatory obligation of ENISA or of ENISA bodies pursuant to Regulation (EU) 2019/881.
ENISA has the right to alter, update or remove the publication or any of its contents. It is intended for information purposes only and must be accessible free of charge. All references to it or its use as a whole or in part must contain ENISA as its source.
Third-party sources are quoted as appropriate. ENISA is not responsible or liable for the content of the external sources including external websites referenced in this publication. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. ENISA maintains its intellectual property rights in relation to this publication. Luxembourg: Publications Office of the European Union, 2026
COPYRIGHT NOTICE
© European Union Agency for Cybersecurity (ENISA), 2026 Unless otherwise noted, the reuse of this document is authorised under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence (https://creativecommons.org/licenses/by/4.0/). This means that reuse is allowed, provided appropriate credit is given and any changes are indicated.
Copyright for the image on the cover © Shutterstock For any use or reproduction of elements that are not owned by the European Union Agency for Cybersecurity, permission may need to be sought directly from the respective rightsholders. ISBN 978-92-9204-789-4, DOI 10.2824/5812948
USE OF AI-ASSISTED TOOLS
AI-assisted tools were used in a limited capacity to support language refinement, terminology alignment, translation and preliminary document screening. All outputs were reviewed and validated by subject-matter experts. No AI-generated content was used without substantive human oversight.
National Capabilities Assessment Framework 2.0
Table of Contents
Document History Error! Bookmark not defined. About ENISA 1 Glossary of Terms 4 Executive Summary 7 1. Introduction 10 1.1 Study scope and objectives 10 1.2 Methodological approach 11
1.2.1 Desk research of publicly available sources 11
1.2.2 Update to the NCAF maturity model 12
1.2.3 Survey 12
1.2.4 Development of maturity questions 13
1.2.5 Reviewing feedback from Member States collected during the survey and development of the first draft of NCAF 2.0 13
1.2.6 NCAF 2.0 piloting and feedback by Member States 13
1.2.7 A validation workshop with Member States 13
1.2.8 Finalisation of the NCAF 2.0 Error! Bookmark not defined.
1.3 Target audience 14 1.4 Challenges of NCSS evaluation 14 1.5 Benefits of a national capabilities assessment 14 1.6 Principles of the framework 15 2. NCAF methodology 19 2.1 Maturity levels 19 2.2 Strategic objectives identified within the european ncss 20 2.3 Goals of the strategic objectives 21 2.4 Clustering of the objectives 26 2.5 Scoring mechanism 27 3. NCAF indicators 33
National Capabilities Assessment Framework 2.0
3.1 Framework indicators Error! Bookmark not defined.
3.1.1 Cluster #1: Capacity-building and awareness 34
3.1.2 Cluster #2: Cooperation and collaboration 52
3.1.3 Cluster #3: Cybersecurity governance 68
3.1.4 Cluster #4: Regulatory and policy frameworks 89
3.2 Guidelines to use the framework 103 Annex A– Desk research bibliography 106 A.1 European Commission documents 106 A.2 NCSS and related documents of Member States 108 A.3 Maturity models and indices 113 Annex B– Maturity models review 116 B.1 Cybersecurity Capacity Maturity Model for Nations (CMM) 116 B.2 Cybersecurity Capability Maturity Model (C2M2) 117 B.3 Cybersecurity Maturity Model Certification (CMMC) 118 B.4 Internal Audit Capacity Model (IA-CM) for the Public Sector 120 B.5 The Cybersecurity Strategy Scorecard 122 B.6 The Global Cybersecurity Index (GCI) 123 B.7 The Cyber Defence Index (CDI) 123
National Capabilities Assessment Framework 2.0
Glossary of Terms
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
Executive Summary
As cybersecurity threats continuously expand and intensify and the legislative landscape of the European Union evolves to tackle these cybersecurity challenges, EU Member States need to react effectively by developing and adapting their national cybersecurity strategies (NCSSs). Since 2017, all Member States have had an NCSS. However, the development of a comprehensive NCSS is a challenging and complex process. To support the Member States in the development and implementation of their NCSSs, the European Union Agency for Cybersecurity (ENISA) published a national capabilities assessment framework (NCAF) in 2020. This report represents an updated version (NCAF 2.0) of the framework, which reflects how the threat landscape has evolved and the advancements in legislation since the earlier version.
The framework aims to help Member States to undertake a self-assessment of their level of maturity by assessing their NCSS objectives. This will help them to enhance and build cybersecurity capabilities at both the strategic and the operational levels, thereby strengthening the collective cybersecurity posture across the EU.
The NCAF is a tool that helps Member States by:
providing useful information to help them develop a long-term strategy (e.g., good practices and guidelines); helping them to identify missing elements within their NCSSs; helping them to further build their cybersecurity capabilities; supporting the accountability of political actions; giving credibility to their NCSSs from the perspective of the general public and international partners; supporting outreach and increasing transparency, thus enhancing the public image of participating organisations; helping them to anticipate the issues lying ahead; helping them to identify lessons learned and best practices; providing a baseline on cybersecurity capacity across the EU to facilitate discussions; helping them to evaluate national capabilities regarding cybersecurity. The target audience of this report is policymakers, subject-matter experts and government officials engaged in the design, implementation and evaluation of NCSSs and, more broadly, cybersecurity capabilities.
National Capabilities Assessment Framework 2.0
SECTION 1
Introduction
National Capabilities Assessment Framework 2.0
1. Introduction
The Network and Information Security Directive (NIS2) , which entered into force in January 2023, aims to strengthen the resilience and security of network and information systems across the European Union. It obliges EU Member States to establish comprehensive national strategies for cybersecurity – referred to as national cybersecurity strategies (NCSSs) – in accordance with its updated provisions. An NCSS, within the scope of NIS2, represents a structured framework that articulates strategic principles, objectives, priorities, policies and regulatory measures, collectively ensuring a robust and sustainable level of cybersecurity. The overarching intention of these strategies is not only to mitigate present and emerging threats to network and information systems, but also to foster innovation and support the economic and social advancement of Member States.
Within this evolving legislative landscape, the European Union Agency for Cybersecurity (ENISA) plays a pivotal role in promoting the harmonisation and continual improvement of NCSS development and implementation. In line with the EU Cybersecurity Act , ENISA supports Member States in adopting and executing NIS2 alongside other key cybersecurity-related legislation, such as the Cyber (3) (4) Resilience Act (CRA) and the Digital Operational Resilience Act (DORA) , by sharing best practices, providing methodological guidance and gathering insights from national experiences.
To aid Member States in developing NCSSs, ENISA published the national capabilities assessment framework (NCAF) in 2020. The NCAF aims to support Member States in measuring and enhancing the maturity of their NCSSs, thereby strengthening the collective cybersecurity posture across the EU. Since then, the evolving threat landscape and advancements in legislation have necessitated an update to the framework. This update brings the NCAF in line with NIS2. The update to the NCAF primarily consists of:
updating the maturity model, including descriptions of maturity levels; revising the clustering of strategic objectives and developing goals for revised strategic objectives; developing a comprehensive set of new maturity questions across the maturity levels and strategic objectives.
1.1 Study scope and objectives
The main objective of this study is to update the NCAF, referred to as NCAF 2.0, a tool designed to help Member States to measure the maturity of their cybersecurity capabilities. Specifically, the framework should empower the Member States to:
conduct the evaluation of their national cybersecurity capabilities; enhance awareness of their cybersecurity maturity level;
National Capabilities Assessment Framework 2.0
identify priority areas for improvement; strengthen and build cybersecurity capabilities. This framework is intended to assist Member States, particularly national policymakers, in performing a self-assessment exercise aimed at improving national cybersecurity capabilities.
1.2 Methodological approach
NCAF 2.0 was developed using a methodological approach consisting of the following main steps: conducting desk research using publicly available sources; updating the NCAF maturity model; conducting a survey to validate the updated maturity model and the maturity questions for three prioritised objectives; developing maturity questions for the updated NCAF objectives; reviewing feedback from Member States collected during the survey and development of the first draft of NCAF 2.0; organising a validation workshop with Member States; finalising NCAF 2.0.
1.2.1 Desk research of publicly available sources
The first step involved conducting a comprehensive review of publicly available sources. A full list of the material reviewed is provided in Annex A. The main sources included: NCSSs; cybersecurity-related EU law and directives and other relevant documents published by EU institutions; maturity models.
First, the desk research focused on the NCSSs and related national documents – such as implementation and action plans – from all Member States and from closely cooperating countries including Liechtenstein, Norway and Switzerland. Although the analysis included strategies available at the time of the original NCAF publication, special attention was given to the documents published since its publication in 2020. The primary goal of reviewing the NCSSs and related national documents was to gain insight into how the objectives set out by ENISA in the NCAF, as well as the national cybersecurity priorities and practices of individual Member States, were implemented. In the second step of the desk research, relevant cybersecurity EU regulations and other documents published by EU institutions – such as studies and reports – were analysed. The analysis primarily focused on key cybersecurity-related documents in the EU legislative
National Capabilities Assessment Framework 2.0
landscape, as featured in the 2024 Report on the State of Cybersecurity in the Union ( ), including (7) (8) (9) (10) NIS2 , the Cybersecurity Act , the CRA and DORA . Subsequently, other relevant publications from EU institutions were reviewed, such as Cybersecurity roles and skills for NIS2 (11) (12) essential and important entities , Cybersecurity of 5G Networks and Undersea Cables – What is at stake? .
The review of national- and EU-level documents supported the formulation of new maturity questions in NCAF 2.0.
The final step of the desk research focused on publicly accessible maturity models, either recently published or updated since the publication of the NCAF in 2020. A list of these models, together with their review, is provided in Annex B. The analysis of the new or updated maturity models served as a key input for the revision of the NCAF maturity model.
1.2.2 Update to the national capabilities assessment framework maturity model
In the next phase, the NCAF maturity model was revised to reflect significant changes in the EU cybersecurity landscape since 2020, while retaining the original methodological framework. Updates included incorporating the new requirements for NCSSs and peer reviews under NIS2, revising the descriptions of the five maturity levels and reorganising the clustering of ENISA’s strategic objectives developed for the NCSS map ( ) (see Section 2.2).
1.2.3 Survey
Once the framework update was concluded, a survey was designed to ensure that the updated NCAF aligned with Member States’ needs and expectations. The survey comprises four main parts:
a description of the updated maturity levels (see Section 2.1);
the revised set of goals for the NCSS objectives (see Section 2.3);
the proposed new clustering of strategic objectives (see Section 2.4);
maturity questions for three selected objectives: objective 13 (‘Strengthen national cybersecurity governance’), objective 14 (‘Establish cybersecurity risk-management measures’) and objective 17 (‘Improve the cybersecurity of the supply chain’).
The input collected by Member States served to validate these four elements of NCAF 2.0 and to inform the next steps in developing the revised framework. In total, 14 Member States completed the survey.
National Capabilities Assessment Framework 2.0
1.2.4 Development of maturity questions
The update of the NCAF maturity model guided the development of maturity questions in the next phase. The goals of each objective, as described in Section 2.3, were further developed into more granular subgoals, detailing the activities necessary to achieve the objectives. Maturity questions were then formulated for each subgoal and maturity level, ensuring comprehensive coverage of different levels of maturity across all topics. These questions were based on both EUlevel legislation and other relevant documents, as well as on best practices and activities in the Member States, as described in the NCSSs and action plans. This process was initially applied to the three strategic objectives included in the survey and later extended to the remaining 17 strategic objectives.
1.2.5 Reviewing feedback from Member States collected during the survey and development of the first draft of NCAF 2.0
In parallel with the development of maturity questions, feedback from the Member States collected during the survey was reviewed and incorporated into the relevant sections of NCAF 2.0. The updated maturity levels, the revised set of goals for the objectives and the new clustering, together with the maturity questions developed for all 20 objectives, were integrated into the first draft of NCAF 2.0.
1.2.6 NCAF 2.0 piloting and feedback by Member States
The first draft of NCAF 2.0 was piloted with Greece, Italy and Luxembourg to assess its effectiveness in supporting the development and revision of the NCSSs. Overall, the pilot confirmed the practical relevance and added value of the framework. Luxembourg highlighted the usefulness of NCAF 2.0 in promoting a structured approach to NCSS preparation, particularly through the systematic mapping of existing frameworks, legislation and practices, including the minimum requirements set out in Article 7, supported by appropriate institutional coordination. Luxembourg also emphasised the need for simplification of the framework. Greece underlined the strong alignment of the framework with NIS2 and its effectiveness in mapping national and governmental policies; in identifying strengths, gaps and overlaps; and in supporting implementation planning, resource allocation and interinstitutional coordination, including in public administrations with limited resources. In this context, Greece considered that the framework is well suited to supporting a structured approach to future strategic planning and prioritisation. Italy considered that NCAF 2.0 provides valuable strategic input for the forthcoming policy cycle, notably by supporting improved prioritisation, clearer timelines and the establishment of benchmarks. Considering the NCAF 2.0 objectives, Italy also provided constructive feedback and proposals to strengthen its methodology, to simplify it and to ensure complementarity with the EU Cybersecurity Index (EU-CSI).
1.2.7 An engaging session with Member States
A world cafe session was organised to gather feedback on NCAF 2.0 through structured, practice-oriented discussions with representatives from Member States. The session provided a collaborative forum in which participants shared national best practices for implementing cybersecurity objectives and assessed whether the proposed NCAF maturity-level questions accurately reflected operational realities.
Working in groups, participants examined the goals for selected objectives, evaluating their coherence, completeness and clarity. Particular attention was paid to the relevance and practical
National Capabilities Assessment Framework 2.0
applicability of the maturity level-3 questions. Participants discussed national implementation examples to determine whether additional questions should be included or existing questions should be removed, in order to better capture emerging practices across Member States.
Key insights and recommendations from each group were documented by rapporteurs and presented during a plenary session. These contributions were subsequently integrated into this version of NCAF 2.0, helping to ensure that the framework remains practical, grounded in realworld experience and effective in supporting both national and collective cybersecurity capabilities across the EU.
1.3 Target audience
The primary audience of this report comprises policymakers, subject-matter experts and government officials engaged in the design, implementation and evaluation of NCSSs and, more broadly, national cybersecurity capabilities. Additionally, the findings set out in this document can be of value to cybersecurity policy experts and researchers at both the national and the European levels.
1.4 Challenges of national cybersecurity strategy evaluation
Member States face numerous challenges when building cybersecurity capabilities particularly in ensuring that these capabilities remain aligned with the latest developments. Below is a summary of the challenges identified by Member States:
Coordinating national Depending on the local Some Member States need cybersecurity efforts to context and national to carry out an evaluation ensure an efficient cybersecurity governance phase to identify gaps and response can be structure, evaluating the limitations before securing challenging due to the large NCSS and its objectives budget and support for number of stakeholders can require more than 15 capability development. involved. person-days.
As threats evolve and Metrics can be collected to Member States operate in technology advances, assess progress, diverse political, action plans must be implementation, maturity, organisational, cultural, and constantly adapted. and effectiveness. While societal contexts, and at However, evaluating an measuring progress and varying levels of NCSS NCSS and linking changes implementation is relatively maturity. This makes it directly to the strategy straightforward, evaluating challenging to implement a remains challenging, effectiveness is more “one-size-fits-all” selfmaking it harder to identify meaningful for assessing assessment framework. limitations and the outcomes and impacts shortcomings. of an NCSS.
National Capabilities Assessment Framework 2.0
1.5 Benefits of a national capabilities assessment
Since 2017, all Member States have had an NCSS. While this is a positive development, it is also important that Member States are able to properly assess these NCSSs and thus bring added value to their strategic planning and implementation.
One of the goals of NCAF 2.0 is to evaluate cybersecurity capabilities based on the priorities set forth in the various NCSSs. Fundamentally, the framework assesses the level of maturity of the cybersecurity capabilities of the Member States in the domains defined by the NCSS objectives. Thus, the results of the framework support Member State policymakers in framing national strategies on cybersecurity by providing them with national-level intelligence on the state of play. NCAF 2.0 is ultimately intended to help Member States identify areas of improvement and build capabilities. The revised framework also takes into account recent regulatory frameworks such as NIS2 (e.g., Articles 7, 19, 21 and 23), the CRA and others, helping Member States to identify areas for improvement and strengthen their cybersecurity capabilities.
The framework aims to help Member States to undertake a self-assessment of their level of maturity by assessing their NCSS objectives. This will help them to enhance and build cybersecurity capabilities at both the strategic and the operational levels.
On a more practical level, ENISA identified various benefits of the NCAF, namely that it:
National Capabilities Assessment Framework 2.0
1.6 Principles of the framework
The NCAF presented in this section is based on the needs highlighted by the Member States and built around the following set of requirements.
Can be voluntarily used by a Member State as a self-assessment framework;
The framework aims at measuring the maturity level of a Member State’s cybersecurity capabilities;
Aims to measure Member States’ cybersecurity
capabilities with respect to the 20 objectives.
Member States can conduct the assessment at the national level for all objectives, a cluster of objectives, or for a single objective;
Assessment results are not published
unless the Member State chooses to do so voluntarily.
All assessed objectives are equally relevant within the assessment framework and are therefore of equal importance.
Member States are able to track their progress over time.
The self-assessment framework is designed to support Member States in strengthening their cybersecurity capabilities by defining maturity levels at multiple layers – objective level, cluster level and overall (global) level.
National Capabilities Assessment Framework 2.0
1.7 Other Usages
It needs to be noted that the NCAF may also be used as a basis for the discussion within the voluntary peer reviews as set out by Article 19 of the NIS2 Directive. In this context, the NCAF can be used as a tool to support mutual learning and exchange of national practices. The EU-CSI also uses some of the NCAF’s questions to measure certain aspects of a country’s cybersecurity posture. The EU-CSI might evolve in closer alignment with the NCAF.
SECTION 2
NCAF methodology
National Capabilities Assessment Framework 2.0
2. National capabilities assessment framework methodology
The main objective of the NCAF is to measure the maturity level of Member States’ cybersecurity capabilities, supporting them in evaluating their national cybersecurity posture, increasing awareness of their maturity level, identifying areas for improvement and building cybersecurity capabilities.
2.1 Maturity levels
The maturity model retains the five-level structure introduced in the NCAF of 2020. These levels align with the successive stages through which Member States progress when developing cybersecurity capabilities in relation to each NCSS objective. They represent a continuum of increasing maturity, beginning with the foundation level 1 – at which Member States have taken initial steps, having established broad goals and implemented the minimum measures to build cybersecurity capabilities in the areas covered by the NCSS objectives – and progress up to advanced level 5, at which the strategy for cybersecurity capacity building is dynamic and responsive to evolving environmental developments.
IMPORTANT NOTICE: Level 5 is considered as extremely high and very few countries, if any, are expected to reach this level for all objectives. Still, it is important to include such a level to illustrate the horizon that a country may aspire to.
Table 1 presents the maturity levels developed for NCAF 2.0.
National Capabilities Assessment Framework 2.0
2.2 Strategic objectives identified within european national cybersecurity strategies
Despite the diversity of the NCSSs and action plans, Member States often establish strategic objectives that cluster around similar themes. ENISA has therefore analysed these common objectives and compiled the following list of 20 key strategic objectives . This list not only builds on the 17 objectives included in the original NCAF but also introduces new thematic areas:
strengthen the cyber resilience and cyber hygiene of the private sector, including small and medium-sized enterprises (SMEs);
promote cybersecurity awareness and cyber hygiene on cybersecurity;
address the cybersecurity skills gap;
foster research and development (R & D) and innovation;
enhance incident preparedness and response (IPR);
address cybercrime;
engage in international cooperation;
establish trusted information-sharing mechanisms;
establish mutual assistance processes;
develop crisis-management frameworks;
secure digital identity and build trust in digital public services;
establish national-level risk assessment;
strengthen national cybersecurity governance;
National Capabilities Assessment Framework 2.0
establish cybersecurity risk-management measures;
establish incident-reporting mechanisms;
balance security with privacy;
improve the cybersecurity of the supply chain;
protect critical sectors;
establish a coordinated vulnerability disclosure (CVD) policy;
promote active cyber protection (ACP).
2.3 Goals of the strategic objectives
The 20 key strategic objectives were thoroughly examined, leading to the development of a set of goals for each objective. These goals represent the core characteristics of each objective and provided guidance for the formulation of the corresponding maturity questions. Table 2 presents the goals associated with each objective.
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
2.4 Clustering of the objectives
NCAF 2.0 is structured around four clusters, each representing a key thematic area of cybersecurity capacity within an NCSS: (1) capacity building and awareness, (2) cooperation and collaboration, (3) cybersecurity governance and (4) regulatory and policy frameworks.
1) Capacity-building and awareness: This cluster assesses the capacity of Member States to raise awareness of cybersecurity risks and threats and to strengthen cyber resilience and cyber hygiene. It also evaluates their ability to continuously develop cybersecurity capabilities and enhance the overall level of knowledge and skills within this domain. Furthermore, it addresses improvements in IPR and advancements in cybersecurity R&D.
2) Cooperation and collaboration: This cluster evaluates cooperation and information sharing between different stakeholders at both the national and the international levels (including as part of mutual assistance processes), recognising it as an important tool for better understanding and responding to a constantly changing threat environment. It also assesses the capacity of Member States to address and counter cybercriminal activities.
3) Cybersecurity governance: This cluster measures the capacity of Member States to establish effective governance and good practices in the cybersecurity domain. It considers various aspects of national cybersecurity governance, risk assessment and management, while supporting the development of crisis-management and incident-reporting mechanisms and fostering trust in public services and digital identities.
4) Regulatory and policy frameworks: This cluster measures the capacity of Member States to establish the necessary regulatory and policy instruments to improve supply chain cybersecurity, promote ACP and safeguard critical information infrastructure. It also assesses their capacity to create a policy framework for CVD or a regulatory framework that balances security with privacy.
Depending on its focus, each cluster includes a set of strategic objectives that Member States may incorporate into their NCSS. While clustering is an integral feature of NCAF 2.0, Member States are free to organise the objectives in their NCSS as they see fit. The four clusters and underlying objectives of NCAF 2.0 are structured as follows.
Cluster #1: Capacity-building and awareness
1) Strengthen the cyber-resilience and hygiene of private sector, including SMEs. 2) Promote cybersecurity awareness and cyber hygiene on cybersecurity. 3) Address the cybersecurity skills gap. 4) Foster R&D and innovation. 5) Enhance IPR.
Cluster #2: Cooperation and collaboration
6) Address cybercrime. 7) Engage in international cooperation.
National Capabilities Assessment Framework 2.0
8) Establish trusted information-sharing mechanisms. 9) Establish mutual assistance processes.
Cluster #3: Cybersecurity governance
10) Develop crisis management frameworks. 11) Secure digital identity and build trust in digital public services. 12) Establish national level risk assessment. 13) Strengthen national cybersecurity governance. 14) Establish cybersecurity risk-management measures. 15) Establish incident reporting mechanisms.
Cluster #4: Regulatory and policy frameworks
16) Balance security with privacy. 17) Improve the cybersecurity of the supply chain. 18) Protect critical sectors. 19) Establish a CVD policy. 20) Promote ACP.
2.5 Scoring mechanism
The scoring mechanism of the framework takes into consideration the elements outlined above and the principles listed in Section 1.6. The model generates a score based on two parameters: the maturity level and the coverage ratio. Each parameter can be calculated at one of three different levels: (1) per objective, (2) per cluster of objectives or (3) overall.
Scores at the objective level
The maturity level score provides an overview of a Member State’s maturity by showing which capabilities and practices were put in place. The maturity score is calculated as the highest level for which the respondent has satisfied all of the requisites (i.e. answered ‘yes’ to all of the requisite questions), including all requisites of the previous maturity levels.
The coverage ratio indicates the extent to which all indicators for an objective are answered positively, irrespective of their maturity level. It complements the maturity level score by considering all indicators measuring the objective. The coverage ratio is calculated as the proportion of questions for which the answer is positive relative to the total number of questions within the objective.
It is important to note that, throughout this document, the term ‘score’ refers collectively to both the maturity level and the coverage ratio. Figure 1 shows the scoring mechanism per objective.
National Capabilities Assessment Framework 2.0
Additionally, to account for the specific characteristics of each Member State while also ensuring a consistent overall perspective, the score is calculated from two different samples at the cluster and overall levels:
• General scores: based on a complete sample that includes all objectives within the cluster or within the overall framework (from one to 20);
National Capabilities Assessment Framework 2.0
• Specific scores: based on a tailored sample that covers only the objectives selected by the Member State (usually corresponding to the objectives present in the country’s NCSS) within the cluster or within the overall framework.
Scores at cluster level
The general level of maturity of each cluster is calculated as the arithmetic mean of the maturity levels of all objectives within that cluster.
The specific level of maturity of each cluster is calculated as the arithmetic mean of the maturity levels of the objectives within that cluster that the Member State has chosen to assess (usually corresponding to the objectives present in the country’s NCSS).
For example, as shown in Section 2.4, cluster 1, ‘Capacity building and awareness’, is composed of five objectives. Assuming that the respondent chose to assess only the first three objectives, but not the fourth and fifth, and assuming that the first three objectives present levels of maturity of 2, 4 and 4, then the level of maturity of the cluster considering all the objectives is level 2 (cluster 1 generic maturity level = (2 + 4 + 4) / 5), while the level of maturity of the cluster considering only the specific objectives selected by the assessor is level 3 (cluster 1 specific maturity level = (2 + 4 + 4) / 3).
The general coverage ratio of each cluster is calculated as the proportion of positively answered questions to the total number of questions within the cluster.
The specific coverage ratio of each cluster is calculated as the proportion of positively answered questions to the total number of questions within the cluster that pertain to the objectives selected by the Member State (usually corresponding to the objectives present in the NCSS of the specific country).
Scores at overall level
The overall general level of maturity of a country is calculated as the arithmetic mean of the level of maturity of all the objectives within the framework, from 1 to 20.
The overall specific level of maturity of a country is calculated as the arithmetic mean of the level of maturity of the objectives within the framework that the Member State has chosen to assess (usually corresponding to the objectives present in the NCSS of the specific country).
The overall general coverage ratio of a country is calculated as the proportion of positively answered questions to the total number of questions across the objectives in the framework (from 1 to 20).
The overall specific coverage ratio of a country is calculated as the proportion of positively answered questions to the total number of questions within the objectives that the Member State has
National Capabilities Assessment Framework 2.0
chosen to assess (usually corresponding to the objectives present in the NCSS of the specific country).
For each indicator, respondents may also select a third option, ‘don’t know / not applicable’. When selected, the indicator is excluded from the total calculation of the results. Figure 2 shows the overall scoring mechanism.
The maturity levels at the cluster level and at the overall level are calculated using the arithmetic mean to show the progress between two assessments. The alternative approach of determining the cluster and overall maturity levels based on the least mature objective, while valid from a maturity standpoint, does not capture the progress made in areas covered by other objectives. Because the cluster and overall levels are consolidated for reporting purposes, the arithmetic mean has been selected as the calculation method. However, for more precise insights, reporting should be based on the scores at the objective level.
National Capabilities Assessment Framework 2.0
SECTION 3
NCAF indicators
National Capabilities Assessment Framework 2.0
3. National capabilities assessment framework indicators
This section presents the ENISA NCAF indicators. The following sections are organised by cluster. For each cluster, a table presents the full set of indicators in the form of questions aligned with specific maturity levels. The questionnaire serves as the primary instrument for the self-assessment. For each objective, there are two sets of indicators included: generic strategy maturity questions – five generic questions for each maturity level and repeated across all objectives; cybersecurity capacity questions – 871 cybersecurity capacity questions, numbered for each maturity level and specific to the area covered by the objective. Each question is accompanied by a tag (0 or 1) indicating whether the question is a requisite indicator (1) or a non-requisite indicator (0) for the corresponding maturity level. Each question is assigned an identification number composed of the: objective number; maturity level; question number. For example, question 14.2.5 refers to the fifth question in maturity level 2 of strategic objective 14: ‘Establish cybersecurity risk-management measures’. Unless otherwise specified, all questions apply at the national level. The pronoun ‘you’ refers to the Member State in a general sense, not to the individual or government body conducting the assessment. The list of objectives and their corresponding goals is provided in Section 2.3.
National Capabilities Assessment Framework 2.0
3.1.1 Cluster #1: Capacity-building and awareness
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
3.1.1 Cluster #2: Cooperation and collaboration
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
3.1.2 Cluster #3: Cybersecurity governance
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
3.1.3 Cluster #4: Regulatory and policy frameworks
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0
National Capabilities Assessment Framework 2.0 Version: xx
3.2 Guidelines to use the framework
This section provides Member States some guidelines and recommendations for rolling out the framework and for filling out the questionnaire:
Anticipate coordination activities to gather and consolidate data. Most Member States indicate that completing a self-assessment typically requires around 15 person-days. Conducting the assessment involves engaging a wide range of stakeholders. It is therefore recommended to allocate sufficient time during the preparation phase to identify all relevant stakeholders across government bodies, public agencies, and the private sector.
Identify a central body in charge of completing the self-assessment at national level. Since gathering material for NCAF 2.0 indicators might involve numerous stakeholders, it is recommended to establish a central body or agency responsible for coordinating with and liaising among all relevant stakeholders to complete the self-assessment.
Use the assessment exercise as a way to share and communicate on cybersecurity topics. Lessons learnt from Member States indicate that discussions, whether through individual interviews or collective workshops, provide a valuable forum to foster dialogue, share perspectives and identify areas of improvement. In addition to highlighting key achievements, sharing results can help raise awareness and promote cybersecurity initiatives.
Use the NCSS to define the scope of the objectives for assessment. The 20 objectives in NCAF 2.0 were derived from the objectives commonly addressed by Member States in their NCSS. While the NCSS can guide which objectives to include, it should not limit the assessment. Since the NCSS naturally prioritises certain areas, some objectives may be omitted, but this does not imply that the corresponding capacities are absent. For example, if a specific objective is not included in the NCSS but the country has related cybersecurity capabilities, that objective can still be assessed.
When the NCSS scope evolves, ensure that the score interpretation remains consistent with
these changes. The NCSS lifecycle spans multiple years, with many Member States implementing 3 to 5-year roadmaps that may include changes in scope between successive editions. Consequently, special care is needed when comparing self-assessment results across NCSS editions, as scope changes can affect the final maturity score. It is recommended to compare scores across the full set of strategic objectives from one year to the next (i.e., the overall general score).
Reminder on the scoring mechanism – example on the coverage ratio
The scoring mechanism includes two levels of scores: (i) an overall general coverage ratio based on the complete list of strategic objectives present in the self-assessment framework; and (ii) an overall specific coverage ratio based on strategic objectives selected by the Member State (usually corresponding to the objectives present in the NCSS of the specific country). By design (see section 2.5 on the scoring mechanism), the overall specific coverage ratio is equal to or higher than the overall general coverage ratio. This is because the overall general coverage ratio may include objectives not yet addressed by the Member State, which can lower the ratio. When a Member State adds a new objective, the overall coverage ratio will increase
National Capabilities Assessment Framework 2.0 Version: xx
(i.e., more maturity indicators are covered), while the overall specific maturity may decrease if the newly added objective is at an early stage and therefore has a low maturity level.
• When filling out the self-assessment questionnaire, remember that the primary purpose is to support Member States in cybersecurity capacity-building. Even if it is sometimes difficult to provide a definite answer, it is recommended to select the response that is most generally accepted. For example, if a question is answered YES for one scope but NO for another, the NO response indicates that action is required—either a remediation plan or a plan to address the improvement area in future developments.
SECTION 4
Annex A – Desk research bibliography
National Capabilities Assessment Framework 2.0 Version: xx
Annex A – Desk research bibliography
A.1 European Commission documents
Official Journal of the European Union (2022) DIRECTIVE (EU) 2022/2557 of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC. Available at: https://eurlex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2557&qid=1749128838444
Official Journal of the European Union (2022) DIRECTIVE (EU) 2022/2555 of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive). Available at: https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
Official Journal of the European Union (2016) DIRECTIVE (EU) 2016/1148 of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union. Available at: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX%3A32016L1148&qid=1749128737957
Official Journal of the European Union (2024) REGULATION (EU) 2024/2847 of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act). Available at: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX%3A32024R2847&qid=1751962706527
Official Journal of the European Union (2022) REGULATION (EU) 2022/2554 of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011. Available at: https://eurlex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&qid=1751972468415
Official Journal of the European Union (2021) REGULATION (EU) 2021/887 of 20 May 2021 establishing the European Cybersecurity Industrial, Technology and Research Competence Centre and the Network of National Coordination Centres. Available at: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX%3A32021R0887&qid=1751962872176
Official Journal of the European Union (2019) REGULATION (EU) 2019/881 of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act). Available at: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=CELEX%3A32019R0881&qid=1751963273613
Official Journal of the European Union (2024) COMMISSION RECOMMENDATION (EU) 2024/1101 of 11 April 2024 on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography. Available at: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=intcom:C%282024%297151
National Capabilities Assessment Framework 2.0 Version: xx
Official Journal of the European Union (2024) COMMISSION IMPLEMENTING REGULATION (EU) C/2024/7151 final of 17 October 2024 laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of the cases in which an incident is considered to be significant with regards to “various providers”. Available at: https://eur-lex.europa.eu/legalcontent/EN/TXT/?uri=intcom:C%282024%297151
European Commission (2023) COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL COM (2023) 207 final of 18 April 2023 – Closing the cybersecurity talent gap to boost the EU’s competitiveness, growth and resilience (“The Cybersecurity Skills Academy”. Available at: https://ec.europa.eu/newsroom/dae/redirection/document/95048
European Commission (2020) JOINT COMMUNICATION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL JOIN (2020) 18 final of 16 December 2020 – The EU’s Cybersecurity Strategy for the Digital Decade. Available at: https://ec.europa.eu/newsroom/dae/redirection/document/72164
European Commission - NIS Cooperation Group (2020) CG Publication 01/2020 - Cybersecurity of 5G networks EU toolbox of risk mitigating measures. Available at: https://ec.europa.eu/newsroom/dae/document.cfm?doc_id=64468
European Network and Information Security Agency (2025) Technical Implementation Guidance: On Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 laying down rules for the application of NIS2 Directive as regards technical and methodological requirements of cybersecurity risk-management measures. Available at: https://www.enisa.europa.eu/publications/nis2-technicalimplementation-guidance
European Network and Information Security Agency (2025) Handbook for Cyber Stress Tests. Available at: https://www.enisa.europa.eu/publications/handbook-for-cyber-stress-tests
European Network and Information Security Agency (2023) Building Effective Governance Frameworks for the implementation of National Cybersecurity Strategies. Available at: https://www.enisa.europa.eu/publications/building-effective-governance-frameworks-for-theimplementation-of-national-cybersecurity-strategies
European Network and Information Security Agency (2023) Undersea Cables – What is at Stake? Available at: https://www.enisa.europa.eu/publications/undersea-cables
European Network and Information Security Agency (2020) National Capabilities Assessment Framework. Available at: https://www.enisa.europa.eu/publications/national-capabilities-assessmentframework
European Network and Information Security Agency (2018) Information Sharing and Analysis Centres (ISACs): Cooperative models. Available at: https://www.enisa.europa.eu/publications/informationsharing-and-analysis-center-isacs-cooperative-models
European Network and Information Security Agency (2016) NCSS good practice guide: designing and implementing national cyber security strategies. Available at: https://www.enisa.europa.eu/publications/ncss-good-practice-guide
National Capabilities Assessment Framework 2.0 Version: xx
European Network and Information Security Agency (2014) Report on Cyber Crisis Cooperation and Management: Comparative study on the cyber crisis management and the general crisis management. Available at: https://www.enisa.europa.eu/publications/ccc-study
European Network and Information Security Agency (2011) Cooperative Models for Effective Public Private Partnerships: Desktop Research Report Available at: https://www.enisa.europa.eu/publications/copy_of_desktop-reserach-on-public-private-partnerships
A.2 NCSS and related documents of Member States
Federal Chancellery of the Republic of Austria (2021) Austrian Cyber Security Strategy. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/AT_NCSS_2021_en.pdf
Federal Ministry of the Interior (Austria) (2024) Austrian Security Strategy. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/AT_SECURITY_STRATEGY_2024_en.pdf
Federal Ministry of the Interior (Austria) (2024) Maßnahmenkatalog der Österreichischen Strategie für Cybersicherheit 2021: Fortschrittsbericht 2/2024. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/AT_MEASURES_CATALOGUE_2024_de.pdf
Centre for Cybersecurity Belgium (2021) CYBERSECURITY STRATEGY BELGIUM 2.0 2021-2025. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/reports/BE_NCSS_2021_en.pdf
Centre for Cybersecurity Belgium (2024) ACTIVE CYBER PROTECTION (ACP). Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/BE_POLICY_DOCUMENT_2024_en.pdf
Government of Bulgaria (2021) Updated National Cybersecurity Strategy: “Cyber-Resistant Bulgaria 2023”. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/reports/BG_NCSS_2021_en%20%28draft%20translation%29.pdf
Government of Croatia (2022) Annual Report 2023 - NACIONALNOG VIJEĆA ZA KIBERNETIČKU SIGURNOST. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/additional-documents/HR_ANNUAL_REPORT_2023_hr.pdf
Government of Croatia (2023) Action Plan 2023 - IZVJEŠĆE O PROVEDBI AKCIJSKOG PLANA ZA PROVEDBU NACIONALNE STRATEGIJE KIBERNETIČKE SIGURNOSTI 2022. Available at: https://www.uvns.hr/UserDocsImages/dokumenti/informacijskasigurnost/Izvje%C5%A1%C4%87e%20o%20provedbi%20mjera%20Akcijskog%20plana%20NSKS%2 0u%202022..pdf?vel=997919
Deputy Ministry of Research, Innovation and Digital Policy of Cyprus (2020) Cybersecurity Strategy of the Republic of Cyprus 2020. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/reports/CY_NCSS_2020_en.pdf
National Cyber Security Centre (2021) National Cyber Security Strategy of the Czech Republic. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/reports/CZ_NCSS_2021_en.pdf
National Capabilities Assessment Framework 2.0 Version: xx
National Cyber Security Centre (2021) Action Plan for the National Cyber Security Strategy of the Czech Republic from 2021 to 2025. Available at: https://nukib.gov.cz/download/publikace/strategie_akcni_plany/akcni_plan_2021-2025.pdf
National Cyber Security Centre (2021) 2021 REPORT ON CYBER SECURITY IN THE CZECH REPUBLIC. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/additionaldocuments/2021%20Report%20on%20Cyber%20Security%20in%20the%20Czech%20Republic_en.p df
National Cyber Security Centre (2022) 2022 REPORT ON THE STATE OF CYBERSECURITY IN THE CZECH REPUBLIC. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/additionaldocuments/2022_Report_on_the_State_of_Cybersecurity_in_the_Czech_Republic_en.pdf
National Cyber Security Centre (2023) 2023 Report on the State of Cybersecurity in the Czech Republic. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/2023_Report_on_the_State_of_Cybersecurity_in_the_Czech_Republic_en.pdf
The Danish Government (2021) The Danish National Strategy for Cyber and Information Security 2022. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/reports/DK_NCSS_2022_en.pdf
Republic of Estonia, Ministry of Economic Affairs and Communications (2024) CYBERSECURITY STRATEGY 2024–2030 ‘CYBER-CONSCIOUS ESTONIA’. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/EE_NCSS_2024_en.pdf
Republic of Estonia, Information System Authority (2024) CYBER SECURITY IN ESTONIA 2024’. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/EE_REPORT_ON_CYBER_SECURITY_2024_en.pdf
Prime Minister’s Office of Finland (2024) Finland’s Cyber Security Strategy 2024-2035. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/FI_NCSS_2024_en.pdf
Prime Minister’s Office of Finland (2024) Implementation plan for Finland's Cyber Security Strategy 2024-2035. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/actionplans/FI_ACTION_PLAN_2024_en.pdf
National Cyber Security Centre Finland (2022) Strengthening cyber security at Finnish organisations: Instructions for management and experts. Available at: https://www.kyberturvallisuuskeskus.fi/sites/default/files/media/publication/Strengthening%20cyber%2 0security%20at%20Finnish%20organisations%20- %20Instructions%20for%20management%20and%20experts.pdf
République Française (2025) Plan stratégique de l’Agence nationale de la sécurité des systèmes d’information 2025-2027. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/reports/FR_NCSS_2025_fr.pdf
National Capabilities Assessment Framework 2.0 Version: xx
Government of France (2023) National Cybersecurity Strategy, France 2030. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/FR_NCSS_PRESENTATION_2023_en.pdf
République Française (2022) National strategic review. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/FR_STRATEGIC_REVIEW_2022_en.pdf
Federal Ministry of the Interior (2021) Cyber Security Strategy for Germany 2021. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/DE_NCSS_2021_en.pdf
Hellenic Republic, Ministry of Digital Governance, National Cybersecurity Authority (2020) National Cyber Security Strategy 2020-2025. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/reports/EL_NCSS_2020_en.pdf
Hellenic Republic, Ministry of Digital Governance, National Cybersecurity Authority (2021) Cybersecurity Handbook: Best Practices for the Protection and Resilience of Network and Information Systems. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/EL_CYBERSECURITY_HANDBOOK_en.pdf
Government of Hungary (2025) National Cybersecurity Strategy of Hungary. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/HU_NCSS_2025_hu.pdf
Government of Hungary (2024) Act on Cybersecurity in Hungary. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/HU_ACT_ON_CYBERSECURITY_2024_hu.pdf
Government of Italy (2022) National Cybersecurity Strategy 2022-2026. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/IT_NCSS_2022_en.pdf
Government of Italy (2022) Implementation Plan: National Cybersecurity Strategy 2022-2026. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/IT_IMPLEMENTATION_PLAN_2022_en.pdf
Agenzia per la Cybersicurezza Nazionale (2023) Monitoraggio della Strategia di Cybersecurity Governance: Introduzione. Available at: https://www.acn.gov.it/portale/w/monitoraggio-della-strategiadi-cybersecurity-governance-introduzione
Government of Ireland (2019) National Cyber Security Strategy 2019-2024. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/IE_NCSS_2019_en.pdf
Government of Ireland (2023) National Cyber Security Strategy 2019-2024 Mid-Term Review. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/IE_NCSS_MID_TERM_REVIEW_2023_en.pdf
Government of Latvia (2023) The Cybersecurity Strategy of Latvia 2023-2026. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/LV_NCSS_2023_en.pdf
National Cybersecurity Unit, Principality of Liechtenstein (2025) National Strategy for Protection Against Cyber Risks. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/reports/LI_NCSS_2025_en.pdf
National Capabilities Assessment Framework 2.0 Version: xx
Government of Liechtenstein (2025) Cyber Security Act 2025 - Cyber-Sicherheitsgesetz (CSG). Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/LI_CYBER_SECURITY_ACT_2025_de.pdf
Government of Liechtenstein (2025) Cyber Security Regulation 2025 – Cyber-Sicherheitsverordnung (CSV). Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/LI_CYBER_SECURITY_REGULATION_2025_en.pdf
Government of Lithuania (2024) Progress Measure Description - 2023–2030 METŲ PLĖTROS PROGRAMOS VALDYTOJOS LIETUVOS RESPUBLIKOS, PROGRAMOS PAŽANGOS PRIEMONĖS NR. 06-007-10-05-07 „STIPRINTI KIBERNETINĮ ATSPARUMĄ“ APRAŠAS. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/LT_PROGRESS_MEASURE_DESCRITPION_lt.pdf
Government of Lithuania (2024) Cybersecurity Programme Justification - 2023–2030 METŲ PLĖTROS PROGRAMOS VALDYTOJOS LIETUVOS RESPUBLIKOS - Nacionalinio pažangos plano (toliau – NPP). Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/additional-documents/LT_CYBERSECURITY_PROGRAMME_JUSTIFICATION_lt.pdf
Government of Lithuania (2021) National Progress Plan - 2021–2030 METŲ NACIONALINIS PAŽANGOS PLANAS. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/additional-documents/LT_NATIONAL_PROGRESS_PLAN_2021_lt.pdf
Government of Lithuania (2024) Law on Cybersecurity - LIETUVOS RESPUBLIKOS KIBERNETINIO SAUGUMO ĮSTATYMAS. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/additional-documents/LT_LAW_ON_CYBERSECURITY_lt.pdf
Government of Lithuania (2021) National Cybersecurity Strategy. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/LT_SECURITY_STRATEGY_2021_lt.pdf
Government of Luxembourg (2021) National Cybersecurity Strategy IV. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/LU_NCSS_2021_en.pdf
Government of Malta (2023) National Cyber Security Strategy 2023-2026. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/MT_NCSS_2023_en.pdf
Government of Netherlands (2022) Netherlands Cybersecurity Strategy 2022-2028. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/NL_NCSS_2022_en.pdf
Government of Netherlands (2022) Action plan: Netherlands Cybersecurity Strategy 2022-2028. Available at: https://english.nctv.nl/binaries/nctv-en/documenten/publications/2022/12/06/thenetherlands-cybersecurity-strategy---action-plan/NCTV+%E2%80%A2+Actieplan+NCSS+22- 28+%E2%80%A2+handreiking+EN+RGB+HR.pdf
National Coordinator for Counterterrorism and Security, Ministry of Justice and Security (2024) Cybersecurity Assessment Netherlands 2024. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/NL_ASSESSMENT_2024_en.pdf
National Capabilities Assessment Framework 2.0 Version: xx
Ministry of Digital Affairs of Poland (2019) Cybersecurity Strategy of the Republic of Poland for 2019 – 2024. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/reports/PL_NCSS_2019_en.pdf
Government of Poland (2020) National Security Strategy of the Republic of Poland. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/PL_SECURITY_STRATEGY_2020_en.pdf
Government of Portugal (2019) National Strategy for Cyberspace Security 2019-2023. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/PT_NCSS_2019_en.pdf
Government of Portugal (2022) Estratégia Nacional de Segurança do Ciberespaço 2019-2023 – Implementation report. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/additional-documents/PT_NCSS_IMPLEMENTATION_REPORT_2022_pt.pdf
Government of Romania (2022) NCSS - Strategiei de securitate cibernetică a României, pentru perioada 2022—2027. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/reports/RO_NCSS_2022_ro.pdf
National Security Authority of Slovakia (2021) The National Cybersecurity Strategy 2021-2025. Available at: https://www.enisa.europa.eu/sites/default/files/ncssmap/strategies/reports/SK_NCSS_2021_en.pdf
National Security Authority of Slovakia (2021) Security Strategy of the Slovak Republic. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/SK_SECURITY_STRATEGY_2021_en.pdf
National Security Authority of Slovakia (2021) Akčný plán realizácie: Národná Stratégia Kybernetickej Bezpečnosti 2021 – 2025. Available at: https://www.nbu.gov.sk/data/att/2760.pdf
National Security Authority of Slovakia (2021) Odpočet Implementácie Akčného Plánu realizácie Národnej stratégie kybernetickej bezpečnosti na roky 2021 až 2025. Available at: https://www.nbu.gov.sk/data/att/398.pdf
Government of Spain (2019) National Cybersecurity Strategy. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/ES_NCSS_2019_en.pdf
The Federal Council (Confédération Suisse) (2023) National Cyberstrategy (NCS). Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/CH_NCSS_2023_en.pdf
Government of Sweden (2025) NCSS - Nationell strategi för cybersäkerhet 2025-2029. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/reports/SE_NCSS_2025_se.pdf
Government of Sweden (2024) NCSS – Official document, Nationell strategi för cybersäkerhet 2025- 2029. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/SE_NCSS_2025_OFFICIAL_DOCUMENT_se.pdf
Government of Sweden (2025) NCSS Annex 2, Bilaga 2: Organisationer med roller och ansvarsområden inom cybersäkerhet Nationell strategi för cybersäkerhet 2025–2029. Available at: https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/additionaldocuments/SE_NCSS_2025_ANNEX_2_se.pdf
National Capabilities Assessment Framework 2.0 Version: xx
Government of Sweden (2025) NCSS Annex 1, Bilaga 1: Handlingsplan, Nationell strategi för cybersäkerhet 2025-2029. Available at: https://www.regeringen.se/contentassets/0903061f79204084b6acf4ce1a978830/bilaga-1handlingsplan.pdf
Government of Sweden (2023) Revision report, Riksrevisionens rapport om regeringens styrning av samhällets informations- och cybersäkerhet. Available at: https://www.regeringen.se/contentassets/cd23ea9b36fd4d59b990f7541023214d/riksrevisionensrapport-om-regeringens-styrning-av-samhallets-informations--och-cybersakerhet-skr.-20232426.pdf
A.3 Maturity models and indices
Cybersecurity Maturity Model Certification (CMMC), CMMC Assessment Guide (Level 2), Available from: https://www.acq.osd.mil/cmmc/docs/CMMC-Assessment-Guide-Level-2-v2.0.pdf
Harvard Kennedy School - Belfer Center (2025) Cybersecurity Strategy Scorecard. Available at: https://www.belfercenter.org/research-analysis/cybersecurity-strategy-scorecard
Harvard Kennedy School – Belfer Center (2025) Cybersecurity Strategy Scorecard. Available at: https://www.belfercenter.org/sites/default/files/2025-03/Cyber%20Strategy%20Scorecard_3.1.pdf
Institute of Internal Auditors (2017) Internal Audit Capability Model (IA-CM) for the Public Sector: IA- CM Assessment Tool. Available at: https://iia-dl.theiia.org/BookstorePublic/IA- CM%20Assessment%20Tool.docx
International Telecommunication Union (2024) Global Cybersecurity Index 2024 5th edition (GCI). Available at: https://www.itu.int/epublications/publication/global-cybersecurity-index-2024
International Telecommunication Union (2025) Global Cybersecurity Index. Available at: https://www.itu.int/en/ITU-D/Cybersecurity/pages/global-cybersecurity-index.aspx
MIT Technology Review (2022) MIT Cyber Defence Index (CDI) 2022/2023. Available at: https://www.technologyreview.com/2022/11/15/1063189/the-cyber-defence-index-2022-23/
MIT Technology Review Insights (2022) MIT Cyber Defence Index (CDI) 2022/2023, Methodology White Paper, Available at: https://mittrinsights.s3.amazonaws.com/CDIreport.pdf
Public Expenditure and Financial Accountability (2023) (Internal Audit Capability Model (IA-CM) - Institute of Internal Auditors. Available from: https://www.pefa.org/sites/pefa/files/PEFA%202022%20Stocktaking%20-%20B25.pdf
University of Oxford – Oxford-Martin School (2021) Development and Evolution of the CMM. Available at: https://gcscc.ox.ac.uk/development-and-evolution-of-the-cmm
University of Oxford – Global Cyber Security Capacity Centre (GCSCC) (2021), Cybersecurity Capacity Maturity Model for Nations (CMM). Available at: https://gcscc.web.ox.ac.uk/files/cmm2021editiondocpdf
U.S Department of Energy - Office of Cybersecurity, Energy Security, and Emergency Response (2022) Cybersecurity Capability Maturity Model (C2M2) Version 2.1 of June 2022, Available at: https://c2m2.doe.gov/Documents/C2M2-v2-1.pdf
National Capabilities Assessment Framework 2.0 Version: xx
U.S Department of Energy - Office of Cybersecurity, Energy Security, and Emergency Response (2022) Self-Evaluation Guide: Companion Document to C2M2 Version 2.1 of June 2022, Available at: https://c2m2.doe.gov/C2M2%20Self-Evaluation%20Guide.pdf
U.S. Department of Energy (2022) Cybersecurity Capability Maturity Model (C2M2), Available at: https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2
U.S. Department of Defence – Chief Information Officer (2025) Cybersecurity Maturity Model Certification (CMMC). Available at: https://dodcio.defence.gov/CMMC/
U.S. Department of Defence (2024) Federal Register / Vol. 89 / Rules and Regulations of 15 October 2024, Cybersecurity Maturity Model Certification (CMMC) Program. Available at: https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-modelcertification-cmmc-program
SECTION 5
Annex B – Maturity models review
National Capabilities Assessment Framework 2.0 Version: xx
Annex B – Maturity models review
Research on the methodology of maturity models continues to evolve and since the publication of the original NCAF in 2020, a range of recognised maturity models and indices has been published including:
• Cybersecurity Capacity Maturity Model for Nations (CMM), • Cybersecurity Capability Maturity Model (C2M2), • Cybersecurity Maturity Model Certification (CMMC), • Internal Audit Capability Model (IA-CM), • Cybersecurity Strategy Scorecard, • Global Cybersecurity Index (GCI); and • Cyber Defence Index (CDI).
A detailed review of these models highlighted both enduring principles and significant developments since 2020. The following subsections analyse the changes in each model across four key elements: attributes/dimensions, maturity levels, assessment methods and results representation.
B.1 Cybersecurity Capacity Maturity Model for Nations (CMM)
The Cybersecurity Capacity Maturity Model for Nations (CMM), developed in 2014 by the Global Security Capacity Centre (GCSCC) at the University of Oxford, is a framework designed to help nations assess and strengthen their overall cybersecurity capacity. It provides a structured approach to evaluate a country’s readiness, identify gaps, and guide the development of effective policies, skills, and practices aimed at building national cyber resilience. After initial pilot deployment, the model was revised in 2017 to refine its structure and factors. The 2021 edition incorporated lessons learned from the worldwide implementation and addressed emerging challenges, with a stronger focus on digital inclusion, data protection, and resilience to disinformation, areas that were less emphasized in the earlier version.
Attributes/Dimensions
The CMM defines five core dimensions that collectively represent the full spectrum of national cybersecurity capacity:
• Cybersecurity Policy and Strategy: Focuses on the development and implementation of national cybersecurity strategies, incident response, critical infrastructure protection, and defence integration. • Cybersecurity Culture and Society: Assesses societal awareness, trust in online services, user understanding of privacy, reporting mechanisms, and the role of media in shaping cybersecurity attitudes. • Building Cybersecurity Knowledge and Capabilities: Evaluates awareness programs, formal education, professional training, and research and innovation efforts. • Legal and Regulatory Frameworks: Reviews the existence and effectiveness of laws and regulations related to cybersecurity, cybercrime, data protection, and judicial capacity. • Standards and Technologies: Examines the adoption of cybersecurity standards, deployment of security controls, software quality, infrastructure resilience, and responsible disclosure practices
National Capabilities Assessment Framework 2.0 Version: xx
Each dimension is broken down into Factors, which are further divided into Aspects, and measured using Indicators that reflect specific actions or capabilities.
Maturity levels
• The CMM uses a five-stage maturity scale to assess progress within each aspect: • Start-up: No or minimal capacity; early discussions may exist but lack formalisation. • Formative: Initial structures or policies are emerging; activities may be ad hoc or fragmented. • Established: Systems and processes are in place and functioning; evidence of effectiveness exists. • Strategic: Capacity is aligned with national priorities; decisions are informed by risk assessments and strategic planning. • Dynamic: Capacity is adaptive, forward-looking, and contributes to global leadership; mechanisms exist to respond to evolving threats and technologies
Each stage includes a set of binary indicators that must be evidenced to confirm attainment.
Assessment method
The CMM assessment is conducted through a combination of:
• In-country stakeholder consultations • Desk research and document analysis • Evidence-based scoring against indicators
The process is collaborative and multi-stakeholder, involving government, private sector, academia, and civil society. The output is a detailed report that benchmarks national capacity, identifies gaps, and recommends targeted actions for improvement
Results representation
Results are presented in a structured format. Each country is scored across all five dimensions and their respective factors. Maturity levels are assigned per aspect, based on fulfilment of indicators. The final report includes:
• Visual maturity map • Narrative analysis of strengths and weaknesses • Prioritised recommendations for capacity building • Guidance for strategic investment and policy development
This format enables countries to track progress over time, compare with peers, and align cybersecurity efforts with broader national goals.
B.2 Cybersecurity Capability Maturity Model (C2M2)
The Cybersecurity Capability Maturity Model (C2M2) was developed by the U.S. Department of Energy (DOE) to assist organisations in evaluating and enhancing their cybersecurity capabilities. Initially released in 2014 (version 1.1), C2M2 aimed to provide a structured approach for assessing cybersecurity maturity and guiding improvements. The model underwent significant updates in July 2021, consolidating previous sector-specific versions (electricity, oil and natural gas sectors) into a unified framework tailored for the energy sector. The most recent update, version 2.1, was released in
National Capabilities Assessment Framework 2.0 Version: xx
June 2022. This version refined the model based on real-world testing and user feedback, enhancing its applicability and effectiveness in addressing evolving cybersecurity challenges in the energy sector. C2M2 serves as a valuable tool for organisations seeking to strengthen their cybersecurity posture and resilience against emerging threats.
Attributes/Dimensions
The C2M2 model continues to be built around the same ten core domains, each representing a distinct cybersecurity capability area with associated management and approach objectives. With version 2.1, the overall framework and domain structure remained unchanged, but two-thirds of the practices were revised.
Maturity levels
The C2M2 model uses a scale of maturity indicator levels:
• MIL0 – no practice performed • MIL1 – Initiated • MIL2 – Performed • MIL3 – Managed
The content and the description of the MILs stayed the same as per the previous version.
Assessment method
While still designed for self-assessment, newer toolkits (C2M2 Toolkit) and resources have been developed to enable more structured scoring, prioritisation of domains, and longitudinal tracking. Assessments can be conducted as facilitated workshops or self-evaluation, allowing flexibility depending on organisational needs.
Results representation
The C2M2 Self-Evaluation Report provides a structured visual summary of the assessment results, generated once all responses are entered into the self-evaluation tool. The core visualisation is a 3x10 matrix of donut charts, where each chart represents one domain at a specific Maturity Indicator Level (MIL). The coloured segments indicate the number of practices rated as: “Fully Implemented (FI)”, “Largely Implemented (LI)” - dark and light blue, or as “Partially Implemented (PI)”, “Not implemented (NI)” - light and dark yellow. In addition, the report features horizontal bar charts showing implementation levels for each practice within a domain, as well as domain-specific summaries that break down results by objectives. A separate Management Practices summary highlights how institutionalised cybersecurity activities are across all domains.
B.3 Cybersecurity Maturity Model Certification (CMMC)
The Cybersecurity Maturity Model Certification (CMMC), initially designed for U.S. Department of Defence contractors to strengthen cybersecurity across the Defence Industrial Base and protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). Although focused on the U.S. context, its modularity makes it a valuable reference for supply chain resilience and auditability. CMMC 1.0 was introduced in 2020, and since then it has undergone several changes. In CMMC 2.0 (announced in 2021), implementation guidance has been fully aligned with NIST 800-171 and SP 800-172 and introduced more flexibility (e.g., Plans of Action and Milestones – POA&M). The
National Capabilities Assessment Framework 2.0 Version: xx
final rule of CMMC 2.0 was published in October 2024, with phased implementation expected through 2025, including the activation of CMMC Level 2 self-assessments effective on February 2025.
Attributes/Dimensions
The CMMC 1.0 included 17 capability domains, each containing multiple practices and processes to be evaluated. It focused on assessing both presence and institutionalisation of cybersecurity practices at different maturity levels. This approach led to a relatively large number of assessment items, contributing to complexity in implementation and auditing. In contrast CMMC 2.0 simplifies this structure significantly by reducing the number of domains and focusing directly on the implementation of specific security controls derived from earlier mentioned NIST standards. The explicit concept of multiple dimensions was removed, favouring a more streamlined approach. This results in fewer total assessment requirements, making the certification process more straightforward and practical for organisations.
Maturity levels
The Cybersecurity Maturity Model Certification (CMMC) defines three levels of cybersecurity maturity, each reflecting a different degree of protection for sensitive government information.
• Level 1: focuses on basic safeguarding of Federal Contract Information (FCI). Organisations at this level are expected to meet a set of 15 requirements from FAR clause 52.204–21 and confirm compliance through an annual self-assessment. • Level 2: is designed to protect Controlled Unclassified Information (CUI). It includes a broader set of requirements based on NIST standards (110 security requirements from NIST SP 800–171 R2). Depending on the sensitivity of the contract, organisations may either self-assess or undergo a formal third-party certification. In some cases, partial compliance is allowed temporarily, provided there’s a clear plan to close the gaps within a set timeframe. • Level 3: applies to the most sensitive environments, where protection against Advanced Persistent Threats (APTs) is essential. It builds on Level 2 and additionally adds 24 enhanced requirements from NIST SP 800–172. Certification at this level is conducted by a government-led assessment team and must be renewed every three years.
Each level is tied to the type of information handled and the level of assurance the Department of Defence requires from its contractors.
Assessment method
CMMC assessments are conducted to verify that an organisation has implemented the required cybersecurity controls. The method depends on the level:
• Level 1: Organisations perform a self-assessment annually to confirm that basic security practices are in place. This can be done internally or with help from a third party, but it remains a selfassessment. • Level 2: Depending on the contract, organisations either self-assess or hire a certified third-party assessor (C3PAO). Certification assessments are required every three years and must cover all systems that handle Controlled Unclassified Information (CUI). • Level 3: This level requires a government-led assessment by DCMA DIBCAC. Before starting, the organisation must already hold a valid Level 2 certification. The Level 3 assessment is more rigorous and occurs every three years.
National Capabilities Assessment Framework 2.0 Version: xx
Each assessment follows a defined scope, based on which systems process, store, or transmit sensitive data. If some requirements are not met, the organisation may receive a conditional status and must resolve the gaps within 180 days.
Results representation
Assessment results are recorded and submitted to the Department of Defence using secure systems (SPRS or eMASS). The outcome is documented in a formal Assessment Findings Report, which includes:
• A score based on how many requirements were met. • A breakdown of findings: each requirement is marked as Met, Not Met, or Not Applicable. • If applicable, a Plan of Action and Milestones (POA&M) listing items to be fixed.
Organisations must also submit an affirmation—a statement confirming they continue to meet the requirements. This is done annually, even if the certification is valid for three years. If an organisation disagrees with the assessment outcome, it can initiate a formal appeal process.
B.4 Internal Audit Capacity Model (IA-CM) for the Public Sector
The Internal Audit Capability Model (IA-CM) is a structured framework designed to assess and develop the maturity of internal audit functions within the public sector. It was originally developed between 2006 and 2009 under the auspices of the Institute of Internal Auditors Research Foundation (IIARF), in response to the need for a universal tool that could evaluate internal audit capabilities across diverse jurisdictions and organisational structures. IA-CM enables organisations to identify their internal audit requirements, assess current capabilities, and define a roadmap for improvement.
In 2022, the model was significantly expanded through its integration into the broader Public Expenditure and Financial Accountability (PEFA) framework, where it serves as a diagnostic tool for analysing the internal audit performance indicator PI-26. This formal linkage elevated IA-CM’s role in public financial management and positioned it as a reference standard for evaluating audit effectiveness and institutional alignment.
Further enhancements followed in 2023, when IA-CM was supplemented with digital self-assessment tools and structured templates. These additions support more efficient implementation by internal audit teams, senior management, and legislators.
Today, IA-CM functions not only as a methodological framework but also as a strategic instrument for quality assurance, capacity planning, and reinforcing the credibility of internal audit as a cornerstone of public sector governance.
Attributes/Dimensions
The IA-CM Assessment Tool is structured around six core dimensions, referred to as “internal audit elements of the IA-CM.” These are:
• Services and Role of Internal Auditing • People Management • Professional Practices • Performance Management and Accountability • Organisational Relationships and Culture
National Capabilities Assessment Framework 2.0 Version: xx
• Governance Structures
Each element is further broken down into Key Process Areas (KPAs), which represent clusters of related activities that, when institutionalised, contribute to achieving a specific capability level.
Maturity levels
• IA-CM defines five progressive capability levels that reflect the maturity of an internal audit function: • Level 1 – Initial: No sustainable, repeatable capabilities; dependent on individual effort. • Level 2 – Infrastructure: Sustainable and repeatable internal audit practices and procedures. • Level 3 – Integrated: Internal audit management and professional practices are uniformly applied. • Level 4 – Managed: Internal audit integrates information across the organisation to improve governance and risk management. • Level 5 – Optimising: Internal audit learns from internal and external sources to drive continuous improvement.
Each level is achieved only when all KPAs at that level are mastered and institutionalised
Assessment method
The IA-CM assessment is typically conducted as a self-assessment, though it may be externally validated or independently performed. The process includes:
• Understanding the IA-CM model • Identifying institutionalised KPAs • Reviewing documentation on the internal audit activity and its environment • Interviewing senior managers and stakeholders • Confirming capability level based on institutionalised KPAs • Communicating results
Results representation
The IA-CM model is visually represented as a one-page matrix:
• Vertical axis: Capability levels (1 to 5), increasing from bottom to top • Horizontal axis: Elements of internal auditing • Cells: KPAs for each level and element
This matrix illustrates the extent to which the internal audit activity influences each element at a given maturity level.
The final assessment result includes:
• A profile of strengths and areas for improvement • The overall capability level, defined as the lowest level for which all KPAs are institutionalised • A summary report with conclusions, recommendations, and comparison to organisational needs • Identification of leading practices and a roadmap for improvement.
National Capabilities Assessment Framework 2.0 Version: xx
B.5 The Cybersecurity Strategy Scorecard
Cybersecurity Strategy Scorecard 3.1 is a strategic evaluation framework developed in 2025 by specialists from the Harvard Kennedy School, specifically under the Belfer Centre for Science and International Affairs. The Scorecard provides a comparative analysis of national cybersecurity strategies from seven major cyber powers—Australia, Germany, Japan, Singapore, South Korea, the United Kingdom, and the United States. Building on previous Belfer Centre research such as the 2022 National Cyber Power Index, this edition aims to identify best practices, highlight policy gaps, and offer actionable recommendations for future strategy development. It combines qualitative and quantitative data, expert interviews, and document analysis to guide policymakers in designing forward-looking, context-sensitive cybersecurity strategies.
Attributes/Dimensions
The Scorecard evaluates national cybersecurity strategies across five core categories, each broken down into sub-categories and detailed elements:
• Protecting People and Infrastructure: Assesses how strategies address national cyber defence, including critical infrastructure, personal data, supply chains, SMEs, and vulnerable populations. • Generating Capacity: Evaluates how countries build the human and institutional capabilities needed for cybersecurity, including workforce development and education. • Building Partnerships: Measures collaboration with domestic and international stakeholders, including public-private partnerships and interagency coordination. • Codifying Roles and Responsibilities: Examines how clearly countries assign duties to cyberrelevant agencies and establish procedural and technical requirements such as incident reporting. • Communicating Clear Policy: Assesses how well the strategy articulates its vision, sets accountability mechanisms, and communicates implementation plans.
These categories are further divided into 18 sub-categories and 70 subject elements, supported by 268 binary criteria used internally to reduce subjectivity in scoring.
Assessment method
The Scorecard uses a relative scoring approach rather than absolute numerical scores. Each country is evaluated against the other six and classified as:
• Leading • Meeting the Bar • Lagging
This method avoids arbitrary weightings and allows for more nuanced comparisons. The evaluation is based on:
• Publicly available strategy documents • Supporting materials directly related to national strategies • Expert interviews with policymakers, researchers, and practitioners from each country
It’s important to note that, the methodology emphasises intent over implementation, focusing on the strategic vision rather than real-world outcomes. This is due to the inherent difficulty in measuring cybersecurity effectiveness and the lack of publicly available data on implementation. The approach is
National Capabilities Assessment Framework 2.0 Version: xx
designed to highlight policy innovation and strategic clarity, making it a valuable tool for benchmarking and future strategy development
B.6 The Global Cybersecurity Index (GCI)
The Global Cybersecurity Index (GCI) assesses the cybersecurity capabilities of countries worldwide, focusing on governmental frameworks and policies. Launched by the International Telecommunication Union (ITU) in 2015, the GCI aims to highlight best practices and encourage improvements across various sectors. The 2024 update enhances its relevance by providing more detailed insights into country-specific strategies and challenges. Ultimately, the GCI promotes a more secure global cyberspace through improved national preparedness, leveraging the expertise of diverse organisations to foster international cooperation and facilitate knowledge exchange.
Attributes/Dimensions
The GCI focuses on five key pillars: Legislative Measures, Technical Measures, Organisational Measures, Capacity Development Measures, and Cooperation Measures.
• Legislative Measures • Technical Measures • Organisational Measures • Capacity Development Measures • Cooperation Measures • Assessment method
The GCI employs a mixed-method approach, utilising both quantitative and qualitative data to evaluate national cybersecurity capabilities. Countries complete a structured questionnaire that collects information across the defined pillars, which is then analysed to generate overall scores. The methodology emphasises a self-assessment process, allowing countries to report on their cybersecurity measures and initiatives.
B.7 The Cyber Defence Index (CDI)
The Cyber Defence Index (CDI) is a national-level benchmark developed by MIT Technology Review Insights, first published in 2022/2023. It evaluates how well major economies, primarily the G20, have adopted technological and policy measures to resist cyberattacks and enable secure digital operations.
Attributes/Dimensions
This index evaluates 20 leading digital economies across governance, resilience, capability, and trust. It applies several measured indicators grouped into four weighted pillars:
• Critical Infrastructure • Cybersecurity Resources • Organisational Capacity and • Policy Commitment. • Assessment method
The Cyber Defence Index uses a multi-layered assessment approach, combining public data analysis, structured surveys of senior cybersecurity professionals and consultations with expert panellists.
National Capabilities Assessment Framework 2.0 Version: xx These inputs are synthesised into 16 indicators across the four pillars, normalised and peer-reviewed to provide a comparative ranking.
TP -01 -26 -00 6- EN -N
ABOUT ENISA
The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu.
ENISA
European Union Agency for Cybersecurity Athens OfficeAgamemnonos 14 Chalandri 15231, Attiki, Greece
Brussels Office
Rue de la Loi 107 1049 Brussels, Belgium
enisa.europa.eu
Fotnoter
- Acronym Definition ACP Active Cyber Protection AI Artificial Intelligence BGP Border Gateway Protocol BRP Business Recovery Plan C2M2 Cybersecurity Capability Maturity Model CCDCoE Cooperative Cyber Defence Centre of Excellence CDEP Committee on Digital Economy Policy CDI Cyber Defence Index CEF Connecting Europe Facility CER Directive Critical Entities Resilience Directive CI Critical infrastructure CIIP Critical Information Infrastructure Protection CIRAS Cybersecurity Incident Response and Analysis System CMM Cybersecurity Capacity Maturity Model for Nations CMMC Cybersecurity Maturity Model Certification COBIT Control Objectives for Information and related Technology CRA Cyber Resilience Act CSoA Cyber Solidarity Act CSIRT Computer Security Incident Response Teams CVD Coordinated Vulnerability Disclosure DEP Digital Europe Programme DNS Domain Name System DORA Digital Operational Resilience Act DPIA Data Protection Impact Assessment ECCC European Cybersecurity Competence Centre ECCG European Cybersecurity Certification Group ECSF European Cybersecurity Skills Framework ECSM European Cybersecurity Month EDIH European Digital Innovation Hubs
- Acronym Definition EDR Endpoint Detection and Response EEAS European External Action Service EU-CSI EU Cybersecurity Index EU-Cyclone European Cyber Crisis Liaison Organisation Network Eurojust European Union Agency for Criminal Justice Cooperation Europol European Union Agency for Law Enforcement Cooperation EC3 European Cybercrime Centre FIRST Forum of Incident Response and Security Teams GCI Global Cybersecurity Index GDPR General Data Protection Regulation GFCE Global Forum on Cyber Expertise HR Human Resources IA-CM Internal Audit Capability Model ICS2 International Information System Security Certification Consortium ICT Information and Communication Technologies IEC International Electrotechnical Commission IPR Incident Preparedness and Response ISACs Information Sharing and Analysis Centres ITU International Telecommunication Union LEA Law Enforcement Agency LED Law Enforcement Directive LLMs Large Language Models MFA Multifactor authentication MS Member State NATO North Atlantic Treaty Organisation NCAF National Capabilities Assessment Framework NCC National Coordination Centre NCCA National Cybersecurity Certification Authority NCSS National Cybersecurity Strategy NIS2 Network and Information Security Directive 2 NIST National Institute of Standards and Technology OECD Organisation for Economic Co-operation and Development
- Acronym Definition OSCE Organisation for Security and Co-operation in Europe PET Privacy Enhancing Technologies PoC Point of Contact PPP Public-private partnership R&D Research & Development SMEs Small and medium-sized enterprises SOC Security Operation Centre SOP Standard Operating Procedures SPOC Single Point of Contact TF-CSIRT Task Force – Computer Incident Response Teams
- (1) https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng. (2) https://eur-lex.europa.eu/eli/reg/2019/881/oj/eng. (3) https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32024R2847. (4) https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng. (5) https://www.enisa.europa.eu/publications/national-capabilities-assessment-framework.
- (6) https://enisa.europa.eu/sites/default/files/2024- 11/2024%20Report%20on%20the%20State%20of%20the%20Cybersecurity%20in%20the%20Union.pdf. (7) https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng. (8) https://eur-lex.europa.eu/eli/reg/2019/881/oj. (9) https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32024R2847. (10) https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng. (11) https://www.enisa.europa.eu/publications/cybersecurity-roles-and-skills-for-nis2-essential-and-important-entities. (12) https://digital-strategy.ec.europa.eu/en/library/cybersecurity-5g-networks-eu-toolbox-risk-mitigating-measures. (13) https://www.enisa.europa.eu/publications/undersea-cables.
- provides useful information to help in the development of a long-term strategy (e.g. good practices and guidelines);
- helps to identify missing elements within NCSSs;
- helps in further building cybersecurity capabilities;
- supports Member States in preparing for the NIS2 peerreview process (e.g. in establishing the scope of the review);
- helps anticipate the issues lying ahead;
- gives credibility to NCSS from the perspective of the general public and international partners;
- supports outreach and increases transparency, thus enhancing the public image of participating organisations;
- Table 1: The ENISA National Capabilities Assessment Framework five-level maturity scale
- Level 1 – Level 2 – Level 3 – Level 4 – Level 5 – Foundation Developing Established Mature Advanced
- The Member State A national Capacity-building Cybersecurity The Member State (MS) has adopted approach to measures and planning and demonstrates a an NCSS. capacity building initiatives are implementation are dynamic and However, a aligned with NCSS systematically strategically aligned adaptive strategy, comprehensive and objectives has developed and across sectors and attentive to structured been decided on. implemented levels of evolving approach to Action plans and across the NCSS governance. The technological, capacity-building activities are in objectives. national action plan geopolitical and across all NCSS place, although Governance is prioritised, threat landscapes. objectives is still many are in the structures for optimised and A culture of lacking. Initial steps early stages of implementation and supported by long- innovation is may include broad implementation. oversight are fully term, fostered through goals and limited Some measures operational, with institutionalised ongoing research measures or are being planned clearly assigned mechanisms (e.g., and international initiatives, which and initiated in responsibilities. legislation, funding, cooperation. are often generic priority areas. Key Activities are national agencies). Strategic decisions and not stakeholders have executed with Capacity-building are driven by systematically been identified and allocated activities are continuous implemented. are beginning to resources, regularly evaluated monitoring of specified timelines and refined based emerging and consistent on performance challenges and
- engage in the documentation at data. Formal, forward planning, process. the national level. cross-sectoral enabling timely and Relevant collaboration effective responses stakeholders are mechanisms and regularly engaged structured throughout the cooperation with policy cycle. The other Member Member State States are in place. contributes to Monitoring, selected EU-level performance initiatives based on assessment and its priorities. continuous improvement mechanisms are embedded to identify gaps and success factors, and guide evidence-based decision-making.
- https://www.enisa.europa.eu/topics/national-cyber-security-strategies/ncss-map/national-cyber-security-strategiesinteractive-map/objectives?objective=1.
- Table 2: Common strategic objectives covered by Member States in their NCSSs
- OBJECTIVE NCSS STRATEGIC OBJECTIVE GOALS NUMBER
- 1 Strengthen the cyber resilience and Enforce mandatory cybersecurity standards by law to ensure cyber hygiene of the private sector, that businesses implement appropriate security measures. including SMEs Promote and develop cybersecurity education, training, awareness and R & D initiatives to foster a strong security culture across the private sector. Provide practical guidance and promote good cyber-hygiene practices tailored to the operational needs of businesses, particularly SMEs. Provide guidance and assistance in strengthening the resilience of SMEs (e.g., vouchers, support programmes). Strengthen the cyber-hygiene baseline of SMEs. 2 Promote cybersecurity awareness Develop and implement ongoing awareness-raising initiatives and cyber hygiene on cybersecurity to educate civil society and academia about cybersecurity threats. Offer guidance on good cyber-hygiene practices and controls to users and entities. Include the need for cybersecurity awareness and cyber hygiene in the NCSS. 3 Address the cybersecurity skills gap Integrate the promotion and development of education and training on cybersecurity and cybersecurity skills development into the NCSS. Enhance the development of cybersecurity skills in technical, operational and strategic areas. Adopt specific measures within the NCSS to mitigate the cybersecurity skills shortage and close skills gaps.
- Undertake EU-wide collaborative initiatives to promote the single market for cybersecurity skills. 4 Foster R & D and innovation Support R & D initiatives to create and enhance innovative cybersecurity tools and secure network infrastructure. Encourage the integration of innovative technologies (e.g. AI and post-quantum cryptography) in cybersecurity solutions to enhance detection and prevention capabilities. Promote R & D activities within the NCSS that facilitate the use of automated or semi-automated tools in cybersecurity and support the sharing of data necessary for technology advancement. Ensure that the use of cutting-edge technologies complies with EU data protection law. Exploit the requirements of data protection by design and by default. Encourage participation in EU and global innovation networks. 5 Enhance IPR Develop and implement comprehensive frameworks and protocols for IPR and acknowledge their existence in the NCSS. Enhance the role of national/governmental computer security incident response teams (CSIRTs) as central coordinating bodies, ensuring effective collaboration among public and private sector stakeholders. Integrate IPR activities such as incident handling, reporting, analysis and response coordination at the national and international levels. Develop measures to ensure preparedness, responsiveness and recovery from incidents, focusing on cooperation between private and public sectors. 6 Address cybercrime Establish and coordinate efforts of relevant stakeholders to fight cybercrime collaboratively. Encourage awareness raising about identification of cybercriminal activities among essential and important entities. Participate in coordination efforts among competent authorities and law enforcement facilitated by the European Cybercrime Centre (EC3) and ENISA. Strengthen the detection, investigation and prosecution capabilities of law enforcement and judicial authorities.
- 7 Engage in international cooperation Establish and maintain international cybersecurity partnerships to support joint actions and strategic alignment on cybersecurity. Promote cross-border incident response coordination through trusted international channels and protocols. Participate in information-sharing mechanisms internationally to better comprehend the latest developments of the threat landscape. Support CSIRTs’ participation in international cooperation networks and their coordination protocols. Promote responsible state behaviour in cyberspace and support coordinated EU responses to malicious cyber activities (the EU cyber diplomacy toolbox and the strategic compass). Defend a global, open, secure and interoperable internet and strengthen international cooperation through multilateral and multistakeholder engagement (e.g., the cyberdefence policy, the cybersecurity strategy for the Digital Decade, the European External Action Service (EEAS) cyber dialogue and engagement in international cyber dialogues and forums such as those of the UN, the Organization for Security and Cooperation in Europe (OSCE), NATO and the Global Forum on Cyber Expertise (GFCE)). 8 Establish trusted information-sharing Integrate robust, trusted information-sharing cooperation mechanisms between public and private stakeholders within the NCSS. Foster strategic partnerships between critical-infrastructure owners and public authorities on information exchange about threats, vulnerabilities and national security status to enhance situational awareness. Support information-sharing and analysis centres (ISACs) and public–private partnerships (PPPs) as strategic tools for pooling expertise and resources. Implement procedures and tools that facilitate voluntary cybersecurity information sharing. Address legal, organisational and cultural barriers to information sharing. 9 Establish mutual assistance Establish mutual assistance processes among Member States processes to ensure effective cooperation and support in supervisory and enforcement actions across borders. Develop frameworks for information sharing, inspections and audits among Member States’ authorities. Promote coordination and consultation among Member States’ authorities to address potential refusal of assistance. Encourage joint supervisory action through mutual agreement. 10 Develop crisis-management Develop a comprehensive cyber crisis-management frameworks framework whose concept and measures are anchored within the NCSS, ensuring coherence with general national crisismanagement structures. Establish dedicated cyber crisis-management authorities and empower them with adequate resources to manage largescale cybersecurity crises.
- Enhance cross-border cooperation and coordination in cyber crisis response by implementing transboundary collaboration mechanisms within the cyber crisis-management framework. Embed regular testing of the crisis-management framework in the NCSS. 11 Secure digital identity and build trust Promote the digital transformation of public administrations in digital public services with a focus on ensuring cybersecurity, efficiency and accessibility of digital public services. Build trust in government in relation to digital identity and public services. 12 Establish national-level risk Establish a mechanism to consolidate risk assessments assessment across sectors, ensuring a national-level view of critical assets and threats, in line with existing requirements under NIS2 and the Critical Entities Resilience Directive (CER Directive). Align cybersecurity strategy objectives with national security needs through comprehensive national risk assessment. Facilitate sector-specific risk assessments to address the risks to critical sectors. 13 Strengthen national cybersecurity Create a governance framework to achieve the objectives and governance priorities set out in the NCSS and related policies, including on critical sectors. Establish the roles, responsibilities and accountability of relevant stakeholders and create a list of the stakeholders and authorities. Establish and maintain cooperation and the coordination of activities related to the implementation of the NCSS at the national level, especially between the competent authorities, CSIRTs and single points of contact designated under NIS2, including cross-sectoral and cross-border collaboration. Enhance coordination among competent authorities under NIS2 for the purpose of information sharing and carrying out an assessment at the level of capabilities (including financial, technical and human resources) and the effectiveness of the performance of their operational and supervisory tasks. 14 Establish cybersecurity risk- Establish a framework that promotes and facilitates the management measures implementation of suitable risk-management measures by essential and important entities to protect the security of their systems. Establish mechanisms to promote and facilitate the adoption of relevant technologies and their incorporation into state-of-theart risk-management measures demonstrating commitment to innovation and technological capacity building. 15 Establish incident-reporting Establish incident-reporting mechanisms for essential and mechanisms important entities to ensure the timely reporting of significant incidents to the CSIRTs or competent authorities in accordance with NIS2. Encourage essential and important entities to notify their service users about incidents that are likely to affect service delivery. Require essential and important entities to provide adequate information to CSIRTs or competent authorities to assess the potential cross-border impact of incidents.
- Ensure seamless communication and rapid notification processes between competent authorities and CSIRTs. Develop protocols for timely information sharing with single points of contact in cases of cross-border or cross-sector incidents. 16 Balance security with privacy Embed the principles of security and privacy in the NCSS, seeking balance between them both. Contribute to enhancing the protection of the right of privacy within cybersecurity. Foster cooperation between data protection authorities, national competent authorities and other stakeholders. 17 Improve the cybersecurity of the Implement state-of-the-art measures to address the supply chain cybersecurity of the supply chain for ICT products and ICT services used by essential and important entities for the provision of their services. Introduce measures (including awareness raising and sharing best practices) aimed at strengthening the cyber resilience of SMEs, in particular in relation to their supply chain. Conduct coordinated security risk assessments of critical supply chains as specified in NIS2. Set baseline security requirements. Establish policies and provide guidelines to ensure that public administration procurement procedures include clear cybersecurity requirements and prioritise the selection of trustworthy and reliable suppliers. 18 Protect critical sectors Ensure strategic alignment between the protection of critical sectors (as per Annexes I and II to NIS2) and related physical resilience obligations under the CER Directive. Adopt specific policies to ensure the availability, integrity and confidentiality of critical sectors, including the public core of the internet and underseas communications cables, if applicable. 19 Establish a CVD policy Establish a CVD process outlining a structured approach for reporting vulnerabilities to manufacturers and service providers. Develop and implement a national policy to facilitate CVD and provide a framework for managing vulnerability reports. Promote the adoption of protective guidelines and legal clarity to foster good-faith vulnerability research, including, where appropriate, exemptions or safeguards from civil or criminal liability, in line with national legal frameworks. 20 Promote ACP Integrate ACP into the NCSS. Promote policies on proactive ACP measures as part of a wider defence strategy. Promote the implementation of internal (and, in the best case scenario, external) ACP capabilities to prevent, detect, monitor and mitigate network security breaches. Promote the use of ACP tools and services to enhance the ability to share threat intelligence.
- For the definition of ACP, please refer to recital 57 of NIS2.
- Figure 1: Scoring mechanism per objective
- Cluster #1: Capacity-Building and Awareness
- 1 Strengthen the Cyber-Resilience and Hygiene of Private 2. Promote Cybersecurity Awareness and Cyber-Hygiene on Sector, Including SMEs Cybersecurity 3. Address the Cybersecurity Skills Gap
- Covered by NCSS? Covered by NCSS? Covered by NCSS?
- Complete all Complete all Complete all
- Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to
- show score show score show score
- 4 Foster Research and Development (R&D) and Innovation 5. Enhance Incident Preparedness and Response
- Covered by NCSS? Covered by NCSS?
- Complete all Complete all
- Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to
- show score show score
- Cluster #2: Cooperation and Collaboration
- 6 Address Cyber Crime 7. Engage in International Cooperation 8. Establish Trusted Information-Sharing and Mechanisms
- Covered by NCSS? Covered by NCSS? Covered by NCSS?
- Complete all Complete all Complete all
- Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to
- show score show score show score
- 9 Establish Mutual Assistance Processes
- Covered by NCSS?
- Complete all
- Maturity level: 0 Coverage ratio: questions to
- show score
- Cluster #3: Cybersecurity Governance
- 11 Secure Digital Identity and Build Trust in Digital Public 10. Develop Crisis Management Frameworks Services 12. Establish National Level Risk-Assessment
- Covered by NCSS? Covered by NCSS? Covered by NCSS?
- Complete all Complete all Complete all
- Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to
- show score show score show score
- 13 Strengthen National Cybersecurity Governance 14. Establish Cybersecurity Risk-Management Measures 15. Establish Incident Reporting Mechanisms
- Covered by NCSS? Covered by NCSS? Covered by NCSS?
- Complete all Complete all Complete all
- Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to
- show score show score show score
- Cluster #4: Regulatory and Policy Frameworks
- 16 Balance Security with Privacy 17. Improve the Cybersecurity of the Supply Chain 18. Protect Critical Sectors
- Covered by NCSS? Covered by NCSS? Covered by NCSS?
- Complete all Complete all Complete all
- Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to
- show score show score show score
- 19 Establish a CVD Policy 20. Promote Active Cyber Protection
- Covered by NCSS? Covered by NCSS?
- Complete all Complete all
- Maturity level: 0 Coverage ratio: questions to Maturity level: 0 Coverage ratio: questions to
- show score show score
- Figure 2: Overall scoring mechanism
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 1 – Strengthen the a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 cyber-resilience and objective in your NCSS (formally or informally) defined and documented mechanism to regularly mechanisms in place to hygiene of private or do you plan to cover intended results, guiding action plan that includes review and assess your ensure that the action sector, including it in the next edition? principles, or key specific activities with action plan to ensure that plan is monitored and Small and Medium activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to Enterprises (SMEs) plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Do you promote the 1 Have you considered 1 Is there a mandatory 1 Are mandatory standards 1 Is there a process in 1 use of European and mandating the national cybersecurity reviewed regularly, place to maintain and international standards implementation of standard applicable to coordinated across update national and technical European, national and essential and important sectors and aligned with cybersecurity standards specifications for international entities, aligned with EU-level frameworks in line with EU securing network and cybersecurity standards NIS2 requirements and (e.g. the CRA, the EU regulatory information systems? and frameworks (e.g. incorporating European cloud services scheme) developments, emerging International and international best to ensure interoperability threats and international Organization for practices? and continuous revisions (e.g. the Standardization (ISO) improvement, while transition to the latest and International avoiding discrimination version of ISO/IEC Electrotechnical against specific 27001)? Commission (IEC) technologies? standard ISO/IEC 27001, the National Institute of Standards and Technology (NIST) framework, the CyberFundamentals framework), especially for ICT products,
- services and processes through EU certification schemes, for essential and important entities? 2 Have key priorities for 1 Have you developed or 1 Are national 1 Do you involve the 1 Do you continuously 1 cybersecurity supported national cybersecurity training private sector, in any monitor developments in awareness-raising and cybersecurity programmes form, in cybersecurity technological trends and cyber-hygiene awareness-raising and operational, with awareness-raising and evolving threats, and initiatives for private training programmes dedicated funding, training initiatives (e.g. integrate them into sector entities, aimed at private sector stakeholder involvement course design and cybersecurity including SMEs, been entities, aligned with and measurable delivery, internships, awareness-raising and identified? NIS2 and the European outcomes (aligned with work placements or training programmes for cybersecurity skills the digital Europe facilitation of free training private sector entities, framework (ECSF)? programme priorities)? offered by the incorporating lessons Cybersecurity Skills learned from incidents Academy’s pledgers, and research outputs? such as ISC2 (the International Information System Security Certification Consortium), the SANS (SysAdmin, Audit, Network and Security) Institute and the ISACA (Information Systems Audit and Control Association))? 3 Does your NCSS 1 Do you have a 1 Is cyber-hygiene 1 Do you have a 1 Do you have 1 identify the need to designated budget to guidance included in mechanism to identify mechanisms to ensure provide guidance and launch best practice private sector policies and assess the most that awareness-raising awareness-raising awareness-raising and reinforced by effective approaches for campaigns and cyberactivities, including ad campaigns and national awareness digital outreach to private hygiene practices for hoc initiatives (e.g. structured guidance on campaigns or sector entities, including essential and important capture-the-flag cyber hygiene and cyber recognition schemes in coordinated cross-sector entities remain relevant exercises, webinars or resilience for private partnership with industry campaigns and incentive to technological workshops), to sector entities? associations? programmes linked to advancements, evolving enhance cyber EU-wide events? threats and regulatory resilience and promote changes, and lead to cyber-hygiene best observable behavioural practices in the private changes? sector? 4 Have you identified the 1 Are cybersecurity 1 When developing 1 Do you gather feedback 1 Do you adapt 1 specific cybersecurity guidance materials or cybersecurity materials from SMEs that are cybersecurity guidance
- needs for SMEs toolkits also available for and toolkits and/or excluded from NIS2, to and toolkits based on excluded from the SMEs that are excluded guidelines for SMEs that improve the usability and SME characteristics, the scope of NIS2, to from the scope of NIS2, are excluded from the relevance of evolving threat industry enhance their to support basic cyber scope of NIS2, do you cybersecurity toolkits and context, ICT resilience as well? hygiene and cyber emphasise simplicity guidance materials? dependency and the resilience? and actionable guidance criticality of processed in line with EU information? frameworks, ENISA recommendations and/or SME-specific needs? 5 Have you nominated a 1 Does the NCC engage 1 Does the NCC facilitate 1 Is there a structured 1 Have the NCC, the 1 national coordination with SMEs and sector access for SMEs to NCC programme that ECCC and national centre (NCC) and associations to raise ECCC resources, EU uses ECCC-supported stakeholders cooperated established basic awareness of available funding opportunities initiatives (e.g. targeted on designing a communication EU-level resources (e.g. and research outputs, training, threat mechanism to assess channels to inform ECCC funding calls such supporting their adoption intelligence sharing) to and refine SME-focused SMEs about their role as the digital Europe of advanced improve SMEs’ cyber cybersecurity and the potential programme and Horizon cybersecurity solutions? resilience and cyber programmes, taking into benefits of participating Europe, training hygiene, including the account feedback, in initiatives supported materials and research adoption of privacy-by- emerging threats and by the European outputs)? design security innovations? Cybersecurity technologies? Competence Centre (ECCC)? 6 Do you invite industry 1 Is there a national 1 Do you encourage 1 Do you assess the 1 Do you actively 1 associations and SMEs programme or initiative industry associations effectiveness of encourage industry to participate jointly in dedicated to supporting and SMEs to be part of cooperation between associations and SMEs any formal or informal cooperation between a national or sectoral industry associations and to participate in cybersecurity industry associations and information systems SMEs (e.g. using international- and EUawareness-raising SMEs, such as through audit and control associations as trusted level support networks events or platforms? scale training or shared association, to multipliers for (e.g. the ECCC, Global resources? strengthen cyber-threat cybersecurity outreach) Cyber Alliance) to awareness and incident and, more broadly, the discuss forward-looking response capabilities? impact of joint initiatives information on threats on SMEs’ preparedness and cyber resilience? (e.g. national- or EUlevel exercises), based on measurable outcomes and feedback?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 2 – Promote a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 cybersecurity objective in your NCSS or (formally or informally) defined and documented mechanism to regularly mechanisms in place to awareness and do you plan to cover it in intended results, guiding action plan that includes review and assess your ensure that the action cyber hygiene on the next edition? principles, or key specific activities with action plan to ensure that plan is monitored and cybersecurity activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Is the need to raise 1 Has a single point of 1 Have you developed a 1 Are providers of services 1 Is there a process in 1 awareness of contact been designated national cybersecurity (e.g. place to regularly update cybersecurity and privacy to coordinate and assist awareness framework to telecommunications, your national issues among citizens in cybersecurity guide the building of banking, digital cybersecurity awareness and entities explicitly awareness-raising awareness at the platforms) incentivised to framework to ensure addressed in your NCSS? activities at the national national level? invest in cybersecurity that it remains relevant or regional levels? awareness and cyber to the evolving national hygiene? cybersecurity threat landscape? 2 Have key priorities for 1 Have you identified 1 Have you developed a 1 Do you evaluate your 1 Are changes in the 1 national cybersecurity specific target audiences communication cybersecurity national cybersecurity awareness-raising and for users’ cybersecurity plan/strategy for awareness-raising and threat landscape cyber-hygiene initiatives awareness-raising and cybersecurity cyber hygiene activities reflected in your been identified? cyber-hygiene activities awareness-raising after execution? cybersecurity (e.g. citizens, young campaigns and cyber- awareness-raising and people, older people, hygiene activities and cyber-hygiene initiatives public sector employees, initiatives for the to ensure that they personnel of SMEs, targeted audiences? continue providing timely employees of essential and effective and important entities)? information? 3 Have you assessed the 1 Do you use different 1 Are different delivery 1 Do you have any 1 Are new delivery 1 effectiveness of different delivery methods for methods systematically mechanisms in place to methods regularly delivery methods for cybersecurity employed during identify the most relevant explored or developed to cybersecurity awareness- awareness-raising cybersecurity media or communication enhance the
- raising campaigns (e.g. campaigns, at least on awareness-raising and channel depending on effectiveness of social media, public an ad hoc basis? cyber-hygiene activities the target audience to cybersecurity service announcements, to maximise maximise outreach and awareness-raising and community events)? effectiveness? engagement? cyber-hygiene campaigns? 4 Are there any formal or 1 Have mechanisms been 1 Do you have any 1 Are your cybersecurity 1 Are mechanisms in 1 informal coordination proposed or initiated to mechanisms in place to awareness-raising and place to ensure that actions between identify relevant external identify target areas for cyber-hygiene activities cybersecurity cybersecurity and and internal factors (e.g. cybersecurity updated (frequently or on awareness-raising legal/policy teams to threat intelligence, policy awareness-raising an ad hoc basis) to measures remain share information used to updates, legal changes) measures based on reflect internal and continuously relevant, drive awareness-raising that could be used to cybersecurity external factors (e.g., reflecting technological and cyber-hygiene enhance cybersecurity intelligence sources recent security incidents developments, changes activities? awareness-raising and (e.g. the ENISA Threat or updated policies or in the national and cyber-hygiene efforts? Landscape report, legislation)? international threat information on the landscape, applicable national and legal and regulatory international threat requirements, and landscapes, feedback national cybersecurity from national cybercrime directives? centres)? 5 Does your NCSS or other 1 Are tailored materials 1 Do you bring together 1 Do you consult with 1 Are the materials 1 strategic document and recommendations stakeholders with behavioural experts to provided regularly acknowledge the need to developed for specific experts (e.g. relevant tailor your cybersecurity reviewed and updated to tailor cybersecurity user groups (e.g. associations and awareness-raising and reflect the evolving awareness-raising and individuals, SMEs, community groups) and cyber-hygiene national cybersecurity cyber-hygiene material to healthcare providers, communication teams to campaigns to the target threat landscape and different user groups (e.g. educators) on basic tailor the content of audience? threats specific to target individuals, SMEs, cyber-hygiene practices? cybersecurity sectors or communities? healthcare providers, awareness-raising and educators)? cyber-hygiene campaigns? 6 Is there a plan to 1 Have minimum expected 1 Are the minimum 1 Do you regularly review 1 Are minimum expected 1 establish a set of cybersecurity practices expected cybersecurity and update the minimum cybersecurity practices minimum expected been established, practices and tools expected cybersecurity and tools updated based cybersecurity practices supported by tools actively promoted practices and tools to on foresight research (e.g. multifactor developed to help among citizens and ensure that they provide and predictive authentication, secure citizens and SMEs adopt SMEs to increase their appropriate protection techniques to prepare passwords) and tools that secure behaviours adoption in a structured against current and citizens and SMEs for can be adopted by online? and coordinated emerging threats? emerging and future citizens and SMEs? manner? cybersecurity threats?
- 7 Does your leadership 1 Are resources available 1 Is training provided to 1 Is there a mechanism in 1 Are relevant educators, 1 publicly support the need for educators, educators, place to evaluate communicators, HR to train educators, communicators, HR communicators, HR whether the dedicated professionals and local communicators, human professionals and local professionals and local resources and training authorities encouraged resources (HR) authorities to support authorities to enable provided to educators, to continuously enhance professionals and local them in effectively them to effectively communicators, HR their delivery skills by authorities to effectively delivering cybersecurity deliver cybersecurity professionals and local integrating innovative convey cyber awareness- awareness-raising and awareness-raising and authorities on delivering methods and emerging raising and cyber-hygiene cyber-hygiene activities? cyber-hygiene cybersecurity best practices into messages? messages? awareness-raising and cybersecurity cyber-hygiene messages awareness-raising are allocated efficiently training? and provide adequate support? 8 Do you have policies in 1 Have you developed any 1 Is there structured 1 Are statistics on 1 Are innovative 1 place recognising the cybersecurity collaboration with civil cybersecurity literacy communication channels need to focus on awareness-raising or society, digital among hard-to-reach or actively explored to cybersecurity awareness cyber-hygiene initiatives influencers, consumer digitally excluded distribute key raising and cyber hygiene targeting hard-to-reach organisations or local communities regularly awareness-raising and for hard-to-reach or or digitally excluded governments in collected and evaluated cyber-hygiene digitally excluded communities? developing and to optimise awareness- messages to hard-tocommunities? distributing cybersecurity raising and cyber- reach or digitally awareness-raising or hygiene programmes excluded communities? cyber-hygiene content and to identify new for hard-to-reach or channels for outreach? digitally excluded communities? 9 Is the need to establish 1 Has any national survey 1 Have national metrics 1 Do you perform periodic 1 Are real-time data 1 national metrics (e.g. been conducted to such as surveys, evaluations to measure leveraged to evaluate surveys, incident trends, measure cybersecurity incident trends or attitude shifts or trends in the national phishing test results) to awareness levels and phishing test results behaviour changes cybersecurity landscape track awareness levels, cyber-hygiene been established to regarding cybersecurity and identify topics for ad cyber-hygiene behaviours behaviours among monitor cybersecurity and privacy matters hoc awareness-raising and programme citizens and entities? awareness levels and among citizens and measures addressing effectiveness identified in cyber-hygiene entities? emerging threats? your cybersecurity behaviours among policies or strategy citizens and entities? documents? 10 Do national strategies or 1 Do you encourage 1 Are primary, secondary 1 Are statistics on 1 Are topics related to 1 policies consider the primary, secondary and and tertiary education cybersecurity literacy disruptive technologies integration of tertiary education institutions provided with among children and incorporated into cybersecurity into digital institutions to integrate supporting materials to students regularly cybersecurity curricula
- literacy and civics cybersecurity into digital include cybersecurity in collected and evaluated to prepare younger curricula from primary to literacy and civics their digital literacy and to optimise awareness- generations for tertiary education as part curricula? civics curricula? raising and cyber- emerging and future of awareness-raising and hygiene materials and threats? cyber-hygiene initiatives? recommendations for each level of education? 11 Is there a plan to 1 Do you have resources 1 Do you have a national 1 Do you regularly collect 1 Does your national 1 establish a national that are easily available cybersecurity portal that and utilise user feedback cybersecurity portal cybersecurity portal that and identifiable (e.g. actively provides cyber- to update materials and include interactive, provides information, through a single online hygiene-related resources on cyber dynamic content and materials and toolkits to portal or in an awareness information, materials hygiene that are continuously updated support personal and kit) for users and entities and toolkits for available through your information (e.g. a organisational cyber seeking to educate stakeholders of varying national cybersecurity chatbot, gamification, hygiene as part of themselves on cyber- types and maturity levels portal to reflect the latest live broadcasts, awareness-raising hygiene topics? (e.g. citizens, SMEs, cybersecurity trends and daily/weekly measures? public administration needs? cybersecurity-related entities)? news) to enhance user engagement and broaden reach?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 3 – Address the a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 cybersecurity skills objective in your NCSS (formally or informally) defined and documented mechanism to regularly mechanisms in place to gap or do you plan to cover intended results, guiding action plan that includes review and assess your ensure that the action it in the next edition? principles, or key specific activities with action plan to ensure that plan is monitored and activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Have you considered 1 Have you identified the 1 Have you adopted a 1 Are mechanisms in place 1 Do you monitor 1 implementing a key national national roadmap with to regularly assess and emerging technical, coordinated national stakeholders who can concrete steps and update the national legal, and sociostrategy with clear contribute to developing designated stakeholders cybersecurity roadmap in economic risks and objectives and cybersecurity specialists' to build cybersecurity line with the evolving trends among measurable outcomes competencies? specialists' professional needs of cybersecurity cybersecurity to address shortages in capabilities? specialists? specialists, and adapt cybersecurity your national roadmap specialists? accordingly? 2 Is the cybersecurity 1 Have you established a 1 Have you conducted a 1 Do you regularly conduct 1 Have you conducted or 1 skills gap explicitly methodology to assess national assessment of national assessments of planned structured included in your NCSS cybersecurity skills at the cybersecurity skills cybersecurity skills to foresight exercises to or related policy national level? across technical, legal, update and adapt your identify emerging trends documents? and policy domains, national roadmap to and future needs in the including the public and address the national cybersecurity private sectors, and cybersecurity skills gap? workforce? academia? 3 Have you conducted a 1 Do you provide training 1 Does the national 1 Do you promote 1 Do you regularly monitor 1 study on the integration for educators, regardless education policy information security cybersecurity trends and of cybersecurity of their field, on promote cybersecurity courses in secondary provide tailored fundamentals into information security and awareness and internet and tertiary education for guidance on national educational privacy issues such as safety courses at early students beyond cybersecurity education curricula? online safety, personal stages of education, computer science, across all levels of the including primary, including courses tailored
- data protection and middle, and high to other professional national education cyberbullying? school? fields? system?
- 4 Does your current or 1 Have strategic objectives 1 Do you promote or 1 Do you engage relevant 1 Are there mechanisms 1 upcoming NCSS and key policy measures develop tailored stakeholders (e.g. the (including through your include measures to been established to cybersecurity training private sector, civil NCSS) that ensure that promote and develop promote cybersecurity and activities for society, academia) in cybersecurity education cybersecurity education, training and different audiences, and developing cybersecurity and training activities education, training and skills development do you have timelines training and education are regularly updated to skills for citizens and nationally, supported by and, PPPs, with a activities, that are stay relevant amid relevant stakeholders activities for citizens for defined specific set of periodically assessed emerging technologies, through dedicated that purpose? resources to support and updated based on evolving threats, and programmes? this? performance indicators new legal regulations and evolving needs? and national security directives? 5 Have you conducted a 1 Do you promote 1 Have you developed or 1 Do you use EU support 1 Do you have 1 study or gap analysis to dedicated training funded any national mechanisms or funding mechanisms to quickly identify upskilling and activities for reskilling or activities to reskill (e.g. the digital Europe adapt upskilling and reskilling needs to upskilling of the interested individuals, programme, the reskilling programmes in strengthen cybersecurity workforce? such as career changers European Social Fund response to evolving cybersecurity skills and unemployed Plus, Horizon Europe) to cybersecurity workforce across all relevant individuals, in upskill or reskill the needs and labour audiences? cybersecurity? workforce generally or in market trends? sector-specific cybersecurity roles (e.g. in healthcare, energy or SMEs)? 6 Do you actively 1 Does your country 1 Has your country 1 Do you provide financial 1 Does your country 1 promote the provide structured established a broader and career incentives ensure the long-term importance of obtaining pathways for advanced cybersecurity capacity- across the public and relevance of cybersecurity cybersecurity education building ecosystem, private sectors (e.g. cybersecurity education certifications in (e.g. specialised including research labs, scholarships, and certifications by technical, operational Master’s and PhD specialised educational apprenticeships, supporting activities and strategic areas and programmes, recognised institutions, regular internships, guaranteed such as academic support public certifications and security events (e.g. jobs) to encourage the centres of excellence administration entities microcredentials)? hackathons) and uptake of cybersecurity and maintaining the in encouraging their partnerships with degrees, accreditation or alignment of learning personnel to pursue academic and certification? programmes with these certifications? professional bodies to technological align training with advancements, evolving recognised career threats and regulatory changes?
- frameworks such as the ECSF? 7 Do public 1 Have you identified 1 Have you implemented 1 Do you systematically 1 Do you continuously 1 administration entities concrete measures to concrete measures to assess the effectiveness monitor, benchmark and recognise the risks of address the address and reduce the of the measures evaluate international the cybersecurity cybersecurity skills gap? cybersecurity skills gap? implemented to close the best practices to workforce skills gap at cybersecurity skills gap? address the the national and EU cybersecurity workforce levels? skills gap and systematically adapt and integrate those proven measures into the national context through structured stakeholder engagement and policy feedback loops? 8 Have you conducted Have priority actions 1 Have stakeholders from 1 Do you assess the 1 Have you conducted or 1 any formal or informal 1 been set out to address the public and private impact of cybersecurity planned foresight study – including ad the cybersecurity skills sectors been involved in skills development exercises to anticipate hoc efforts – to identify gap across different the identification and policy/activities across future challenges and measures for closing sectors and stakeholder prioritisation of the public and private opportunities in the cybersecurity skills groups? policy/activities to sectors using cybersecurity workforce gap? address the performance indicators? development? cybersecurity skills gap? 9 Has an initial Have you established 1 Have you implemented 1 Do you have funding 1 Do you continuously 1 assessment been 1 cybersecurity role cybersecurity role instruments targeting update cybersecurity conducted to establish profiles / job families in profiles / job families different cybersecurity role profiles to reflect cybersecurity roles and your national within your national role profiles or job technological competencies in line occupational workforce development families based on the advancements and align with national workforce classification? plan? current state of the skills with international and planning and gap? EU frameworks (e.g. the frameworks, such as National Initiative for the ECSF and the Cybersecurity Education National Initiative for workforce framework for Cybersecurity cybersecurity, the Education workforce ECSF)? framework for cybersecurity? 10 Have you formally Have you conducted a 1 Have you supported or 1 Have you implemented 1 Do you continuously 1 acknowledged the 1 study or assessment of developed any or funded any monitor socioeconomic importance of attracting under-represented policies/activities or scholarships, outreach or trends and adapt under-represented programmes to inclusive hiring cybersecurity
- groups (e.g. women, groups in the national encourage under- campaigns to support programmes targeting minorities, people with cybersecurity market? represented groups to under-represented under-represented disabilities) to pursue a join the cybersecurity groups in cybersecurity groups to ensure their cybersecurity career? field? careers? ongoing relevance and effectiveness? 11 Has any formal or 1 Have you designated a 1 Have you set indicators 1 Do you regularly 1 Do you actively 1 informal assessment – competent authority (e.g. on the number of evaluate the participate in including ad hoc efforts responsible for trained professionals, effectiveness of your international activities – been conducted to coordinating and gender balance or skills development efforts and forums to promote explore suitable assessing cybersecurity employment outcomes) based on the set cybersecurity skills indicators for skills development to evaluate the indicators? development and share evaluating the impact efforts? effectiveness of your best practices? of cybersecurity skills development education and training efforts? activities? 12 Have you engaged in 1 Do you promote EU-level 1 Have you adopted 1 Do you systematically 1 Do you lead or actively 1 preliminary discussions activities aimed at measures to support the monitor and evaluate participate in the EUwith other Member closing the cybersecurity development of a single joint cybersecurity skills wide discussions and States and EU skills gap (e.g. the Cyber market for cybersecurity activities developed in forums, sharing national agencies on how to Skills Academy, national skills, including activities cooperation with other best practices and address the chapters of that enhance workforce Member States through contributing to joint cybersecurity skills gap Women4Cyber, the mobility and recognition EU frameworks (e.g. the efforts to close the across the EU? digital skills and jobs of qualifications across ECCC) to ensure cybersecurity skills gap? platform) within your Member States? effectiveness and country? continuous improvement?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 4 – Foster Research a Do you cover the 1 Have you defined Do you have a formally 1 Do you have a formal 1 Do you have 1 and Development objective in your NCSS (formally or informally) defined and mechanism to regularly mechanisms in place to (R&D) and or do you plan to cover intended results, guiding documented action plan review and assess your ensure that the action Innovation it in the next edition? principles, or key that includes specific action plan to ensure plan is monitored and activities in your action activities with clear that it is correctly dynamically adapted to plan that contribute to goals, timelines, and prioritized and optimized, evolving technological, achieving the objective allocated resources? including progress geopolitical and threat in an uncoordinated tracking, performance landscapes? way? evaluation, and identification of areas for improvement? 1 Do you recognise the 1 Do you have a process 1 Do you have 1 Are there mechanisms to 1 Are there mechanisms 1 need to support R & D to establish national R & mechanisms to regularly assess that to ensure the alignment activities dedicated to D priorities (e.g. incorporate national instruments over time of the national cybersecurity? emerging topics relating cybersecurity R & D (e.g. NCCs) have the cybersecurity R & D to deterring, protecting findings into policy and resources required? priorities with EU against, detecting and explore opportunities in strategic policies, adapting to evolving EU-wide initiatives and objectives and initiatives cyber threats)? funding (e.g. Horizon (e.g. the digital single Europe, the digital market, Horizon Europe, Europe programme)? the EU cybersecurity strategy, the digital Europe programme, European Digital Innovation Hub calls) and the evolving regulatory frameworks? 2 Do you organise 1 Are stakeholders from 1 Do you actively promote 1 Do you have any 1 Have you established 1 conferences/ the private sector, the partnerships that cooperation agreements cybersecurity centres of workshops to identify public sector and enhance cybersecurity in place or incentives excellence or effective ways to academic and research R & D among the with academic and competence, equipped promote partnerships institutions involved in private sector, the public research institutions, with advanced with academic and establishing national sector and academic potentially involving the predictive analytics and research institutions, institutions? private and public strategic foresight tools,
- industry, civil-society cybersecurity R & D sectors, to support the to serve as practical, organisations and the priorities? development and state-of-the-art research public sector in deployment of and innovation hubs? fostering cybersecurity cybersecurity tools and innovation? secure network infrastructure? 3 Have you conducted 1 Have strategic 1 Is there a 1 Do you regularly assess 1 Do you actively 1 any initial assessments objectives, priority areas comprehensive national the contribution of (semi- participate in or lead or studies on (semi and key stakeholders programme that )automated tools or any international- and EU- )automated tools or the been identified to drive supports (semi- other implemented level forums and integration of national R & D efforts to )automated tools, R & D innovative technologies discussions on cuttinginnovative technologies integrate (semi- or the adoption of any to the effectiveness of edge cybersecurity (e.g. AI or post- )automated tools or any other innovative cybersecurity solutions? research, innovation quantum cryptography) other innovative technologies (e.g. AI or and good practices in into cybersecurity technologies in post-quantum the use of (semipractices? cybersecurity solutions? cryptography), offering )automated tools or any incentives and other innovative collaboration cybersecurity opportunities to a wide technologies? range of public stakeholders and private entities? 4 Have you conducted a 1 Have guidelines been 1 Does the national 1 Are national data-sharing 1 Do you proactively 1 study on implementing developed to promote mechanism for mechanisms regularly contribute to responsible data- responsible data sharing responsible data sharing reviewed and updated to international research to sharing mechanisms for training and in cybersecurity ensure alignment with develop responsible for training users of improving cybersecurity research and innovation evolving legal data sharing for innovative tools with legal and include governance and frameworks, ethical cybersecurity cybersecurity ethical safeguards, coordination measures standards and innovations (e.g. opentechnologies, while incorporating practices that align with strategic operational needs? source initiatives, also considering how that encourage open- priorities such as open- standards and principles such as source projects, source collaboration, interoperability), while open source, recognised standards standards adoption and continuously integrating standards and and interoperability? interoperability? lessons learned into interoperability can national innovation strengthen these policies? mechanisms? 5 Has the integration of 1 Has coordination begun 1 Are there mechanisms 1 Do national 1 Do you actively 1 the General Data between cybersecurity in place to ensure that cybersecurity innovation contribute to the Protection Regulation and data protection the design, development programmes include development of good (GDPR) principles into authorities to align and use of innovative performance indicators practice focused on cybersecurity cybersecurity innovation technology, including AI, or review mechanisms to preserving privacy and
- technology efforts with privacy comply with EU privacy systematically ensure data protection in development been requirements? and data protection law that GDPR principles are innovative cybersecurity formally acknowledged (e.g. principles of data embedded by design technologies? in your NCSS or in accuracy, minimisation, and by default in relevant cybersecurity fairness, transparency innovative cybersecurity policy documents? and data security)? technologies? 6 Has the need to embed 1 Do you provide national 1 Do you have a 1 Is stakeholder feedback 1 Do you actively promote 1 data protection by guidance for mechanism to control periodically collected to and share good design and by default implementing data the integration of data assess and improve practices for data in cybersecurity R & D protection by design and protection by design and national efforts in protection by design and activities been officially by default in by default into the supporting data by default in prioritised in a strategic cybersecurity R & D design of new protection by design and cybersecurity R & D or policy document? activities? cybersecurity solutions? by default in activities at the cybersecurity R & D international level? activities? 7 Are there any informal 1 Do you have a national 1 Do you actively promote 1 Are there formal 1 Are national 1 or formal framework to guide and or facilitate opportunities agreements or stakeholders (e.g. communication coordinate stakeholder for national stakeholders partnerships between government agencies, channels between participation in EU and (e.g. government your government and academic and research national stakeholders international agencies, academic and other Member States on institutions) actively (e.g. government cybersecurity R & D research institutions) to cybersecurity R & D? participating in leading agencies, academic initiatives (e.g. engage in EU-level or international discussions and research guidelines, contact international in the area of institutions) and EU points, matchmaking cybersecurity R & D cybersecurity R & D and international platforms)? projects and initiatives? activities? innovation networks (e.g. ENISA, the ECCC) to share information about cybersecurity R & D opportunities and funding (e.g. calls for consortia, calls for proposals, grants)?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 5 – Enhance a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 incident objective in your NCSS (formally or informally) defined and mechanism to regularly mechanisms in place to preparedness or do you plan to cover intended results, guiding documented action plan review and assess your ensure that the action and response it in the next edition? principles, or key that includes specific action plan to ensure plan is monitored and activities in your action activities with clear that it is correctly dynamically adapted to plan that contribute to goals, timelines, and prioritized and optimized, evolving technological, achieving the objective allocated resources? including progress geopolitical and threat in an uncoordinated tracking, performance landscapes? way? evaluation, and identification of areas for improvement? 1 Have discussions been 1 Has a draft national 1 Is your national cyber 1 Do you monitor and 1 Is research conducted 1 held to establish a cyber IPR framework IPR framework, as well regularly update the on improving the cyber national cyber IPR been developed and as associated protocols national cyber IPR IPR framework and its framework? shared with relevant and cooperation framework, associated associated protocols or stakeholders? mechanisms, protocols and cooperation implemented and cooperation mechanisms mechanisms, taking into operational? to ensure their account future threats effectiveness? and technological changes? 2 Have you initiated the 1 Are national cyber 1 Are national cyber 1 Are national cyber 1 Do national cyber 1 development of incident response incident response incident response incident response national cyber incident procedures documented procedures procedures regularly procedures incorporate response procedures and communicated to implemented and reviewed and refined, threat intelligence and (e.g. standard relevant stakeholders, to adopted by relevant incorporating input from analysis techniques, operating procedures) effectively identify, stakeholders to ensure relevant stakeholders informed by key national for identifying, classify and respond to efficient cyber incident (e.g. feedback and stakeholders and classifying and cybersecurity incidents? identification, lessons learned, national collaborative experience responding to classification and CSIRTs, EU-level across the EU and other cybersecurity incidents coordinated response to networks such as the international networks? (including large-scale cybersecurity incidents? European Cyber Crisis cybersecurity Liaison Organisation incidents)? Network (EU-Cyclone) or the CSIRTs Network)?
- 3 Have preliminary roles 1 Have formal roles and 1 Are well-defined roles 1 Are formal roles and 1 Do the formal roles and 1 and responsibilities for responsibilities within the and responsibilities responsibilities within the responsibilities within relevant competent incident response chain formally established and incident response chain the incident response authorities (including been clearly established documented for regularly reviewed and chain allow for dynamic law enforcement and and communicated to competent authorities, optimised to align with adjustments and flexible sectoral authorities) relevant competent CSIRTs, law national- and EU-level public–private been outlined in cyber authorities, supported by enforcement and frameworks (including collaboration to incident response a centralised registry of sectoral actors to coordination with EU- strengthen response management chain? points of contact across ensure accountability Cyclone or the CSIRTs capabilities in evolving all actors? and coordination during Network)? threat landscapes? cyber incident response, supported by a regularly updated centralised registry of points of contact? 4 Is the role of CSIRTs 1 Have preliminary efforts 1 Are CSIRTs fully 1 Does your CSIRTs’ 1 Are CSIRTs employing 1 as national been undertaken to equipped with adequate supervisory body adaptive strategies and coordination hubs estimate and allocate resources and staffing regularly monitor, innovative technologies clearly understood by necessary resources to to function effectively as evaluate and adjust to enhance operational all relevant CSIRTs, ensuring that national coordination CSIRTs’ resources and resilience and fulfil stakeholders, ensuring they possess the hubs, including meeting staffing to ensure that proactive tasks (e.g. that they recognise the technical capabilities and the NIS2 requirements they can effectively fulfil proactive scanning, risk need to provide staffing required to fulfil for redundancy, secure their mandate as the analysis of future adequate resources for their tasks under NIS2? infrastructure and national coordination threats)? their operations? emergency protocols? hub? 5 Has the establishment 1 Are preliminary joint 1 Are joint incident 1 Are joint incident 1 Are joint incident 1 of joint incident incident response response protocols response protocols response protocols response protocols or protocols under documented and regularly reviewed and subject to continuous trusted communication development to facilitate operational, ensuring optimised, incorporating improvement, including channels between trusted communication seamless and secure lessons learned by both through the use of competent authorities and coordinated coordination between the competent adaptive methodologies, and operators of response between competent authorities authorities and the integration of advanced essential and important competent authorities and operators of operators of essential threat intelligence or entities been initiated? and operators of essential and important and important entities? new information-sharing essential and important entities during tools? entities during cybersecurity incidents, cybersecurity incidents in line with NIS2 (in accordance with cooperation principles? Article 10 of NIS2)? 6 Have discussions been 1 Are proactive 1 Are proactive 1 Are the proactive 1 Are the proactive 1 held to promote a approaches (e.g. the cybersecurity measures, cybersecurity measures cybersecurity measures proactive approach to European Cybersecurity including advanced regularly evaluated and continuously adapted,
- identifying Alert System, regular detection capabilities, refined, incorporating utilising innovative tools cybersecurity threats at national sectoral actively implemented, lessons learned from (e.g. advanced threat the national level, exercises, training supported by incidents, exercises and intelligence, AI, data focusing on sessions, awareness- documented processes best practices? analytics) to enhance anticipating and raising campaigns) and stakeholder effectiveness and preventing incidents leveraged to establish engagement, to responsiveness to (e.g. workshops, frameworks and policies enhance incident emerging cyber threats, studies, exercises)? for threat management handling, reporting, and in line with NIS2 and the and coordinated analysis? Cyber Solidarity Act? response at the national and EU levels? 7 Is the significance of 1 Has the implementation 1 Are there frameworks in 1 Is the integration of 1 Do disaster recovery 1 integrating disaster of policies or pilot place that include disaster recovery and and resilience strategies recovery and continuity programmes been disaster recovery and resilience strategies adaptively incorporate of operations initiated to incorporate resilience, with regularly monitored, cutting-edge practices recognised within your disaster recovery and documented procedures evaluated and improved and innovative national cybersecurity resilience into the and cooperation to ensure technologies to ensure preparedness strategy, NCSS? between competent comprehensive operational continuity as encouraged by authorities, essential cybersecurity against emerging cyber NIS2 and the and important entities preparedness, in threats, in line with EU- Cybersecurity and other relevant accordance with NIS2 level coordination Emergency stakeholders? and EU-level mechanisms? Mechanism? coordination mechanisms? 8 Is the importance of 1 Have clear procedures 1 Are structured protocols 1 Are lessons-learned 1 Do lessons-learned 1 producing lessons- been established and consistently outcomes regularly processes evolve learned reports after applied for conducting implemented to integrated into the dynamically, leveraging significant lessons-learned reports document lessons NCSS, supported by data-driven insights and cybersecurity incidents and root cause analyses, learned across all periodic reviews to advanced analytics to acknowledged in initial incorporating relevant stakeholders, ensure continuous continuously refine and guidance or strategic stakeholder input and with outcomes improvement and enhance national planning documents? aligning with NIS2 systematically used to alignment with EU-level cybersecurity requirements? strengthen national- and coordination? capabilities? EU-level cybersecurity capabilities? 9 Are plans in place to 1 Have foundational 1 Are national 1 Is the alerting and threat- 1 Do alerting mechanisms 1 establish national systems or frameworks mechanisms fully intelligence-sharing continuously evolve, mechanisms and been developed to operational for real-time system regularly leveraging advanced platforms that are enable real-time alerting and threat assessed and integrated analytics and real-time secure and accessible distribution of intelligence sharing, with cross-sectoral and data capabilities (e.g. AI, for issuing cybersecurity alerts and supported by clearly EU-level networks (e.g. data analytics) to cybersecurity alerts cross-border cyber hubs, enhance threat
- and sharing threat threat intelligence defined roles and cross- EU-Cyclone, CSIRTs) to intelligence distribution, intelligence? sharing? sectoral processes? optimise incident in line with NIS2 and the response? European Cybersecurity Alert System? 10 Are there discussions 1 Have preliminary 1 Are national CSIRTs 1 Is the role of national 1 Do national CSIRTs 1 or initiatives aimed at frameworks been operational with CSIRTs and their employ innovative threat enhancing the role of developed to formalise adequate resources to engagement with EU intelligence and national CSIRTs as the roles of national manage national and global coordination coordination central coordinating CSIRTs, including their cybersecurity incidents platforms regularly methodologies to adapt bodies, enabling their participation in platforms and enhance incident reviewed, optimised in real time to evolving engagement with EU such as ENISA, the response capabilities based on lessons cyber threats and and global incident CSIRTs Network and through collaborative learned from incidents continuously enhance response coordination other EU-level frameworks and and exercises, and their participation in EU platforms to strengthen coordination bodies? participation in EU and enhanced to strengthen and global platforms by situational awareness global coordination international integrating foresight and international platforms? cooperation? strategies and cooperation? innovative practices to anticipate and manage international cybersecurity risks? 11 Are there active 1 Have cooperative 1 Are structured 1 Is public–private 1 Is public–private 1 engagements and measures been mechanisms, including cooperation for collaboration evolving to discussions aimed at established to improve national cyber hubs, cybersecurity integrate advanced fostering public–private readiness and incident operational and preparedness, analytics and innovative cooperation in response, in line with the facilitating joint responsiveness and tools for anticipating cybersecurity, including Cyber Solidarity Act preparedness, real-time recovery regularly cyber threats, with preliminary meetings to guidelines for joint response and recovery reviewed and optimised, preparedness and develop sector-specific testing, threat activities between integrating cross-sector response measures objectives and intelligence sharing and competent authorities resilience measures regularly updated based measures for IPR? clear governance roles and private entities, endorsed by the EU and on national evaluations between authorities and leveraging cooperative aligning with and best practices? private entities? exercises and secure coordination policies in communication the NCSS, through channels? ongoing evaluation processes to refine incident response frameworks?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 6 – Address a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 cybercrime objective in your (formally or informally) defined and documented mechanism to regularly mechanisms in place to NCSS or do you plan intended results, guiding action plan that includes review and assess your ensure that the action to cover it in the next principles, or key specific activities with action plan to ensure that plan is monitored and edition? activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Do you have any 1 Do you have a national 1 Is your national legal 1 Do you regularly assess 1 Is there a mechanism in 1 informal or formal framework for detecting, framework compliant whether sufficient place to promptly update procedures in place reporting and with the EU legal human, financial and your national cybercrime to facilitate prosecuting cybercrime framework on technical resources are strategy or framework in coordination between that sets out a structured cybercrime (e.g. as allocated at the national response to emerging law enforcement coordination approach regards illegal access to level to combating cyber threats and trends authorities, judiciary involving law information systems, cybercrime? at the national, regional authorities, enforcement, system interference, and global levels? cybersecurity cybersecurity competent data interference, competent authorities authorities and private interception and the use and private sector sector stakeholders? of tools to commit stakeholders in offences)? addressing cybercrime-related activities? 2 Do you have 1 Are you developing 1 Have you established 1 Are mechanisms in place 1 Do you actively lead or 1 established taxonomies, templates or formal cooperation to assess collaboration influence international cooperation channels national initiatives to mechanisms to enable between CSIRTs, and EU-level forums and (formal or informal) align the classification of secure and timely cybersecurity competent discussions on good for addressing cybercrime incidents information exchange authorities and national practices of cooperation, cybercrime-related between CSIRTs, between CSIRTs, law enforcement bodies including cross-border topics between cybersecurity competent cybersecurity competent and to implement cooperation?
- CSIRTs, authorities and national authorities and national measures for its cybersecurity law enforcement bodies? law enforcement bodies enhancement? competent authorities involved in combating and national law cybercrime? enforcement bodies? 3 Do you have any 1 Are there national 1 Have you established or 1 Have you established an 1 Do you continuously 1 informal or formal initiatives to strengthen designated a central interinstitutional monitor and collect collaboration collaboration between coordinating entity to framework and inputs (e.g. emerging mechanisms in place public and private sector oversee national efforts cooperation mechanisms cybercrime trends, best between private stakeholders in in combating between all relevant practices for sector stakeholders combating cybercrime cybercrime? stakeholders (e.g. law cooperation) to and national (e.g. cooperation enforcement agencies, dynamically adjust authorities to share networks, joint task national CSIRTs and the cooperation information on forces, trusted judiciary), including the mechanisms with public cybercrime-related information-sharing private sector (e.g. and private sector incidents? platforms)? operators of essential stakeholders? services, service providers) where appropriate? 4 Do you have any 1 Are there 1 Have you established a 1 Have you established an 1 Do you collect 1 informal or formal policies/activities in your governance framework interinstitutional disaggregated collaboration NCCS and/or national that sets out the roles framework and cybercrime statistics mechanisms in place initiatives (e.g. and responsibilities of cooperation mechanisms (e.g. operational data, between private cooperation networks, key stakeholders between all relevant data for trend analysis, sector stakeholders joint task forces, trusted (CSIRTs, law stakeholders (e.g. law financial impact and national information-sharing enforcement agencies enforcement agencies, information) and monitor authorities to share platforms) that govern and the judiciary) and/or national CSIRTs and the emerging cybercrime information on and strengthen designates a central judiciary), including the trends to regularly cybercrime-related collaboration between coordinating entity to private sector (e.g. inform national policies incidents? public and private sector oversee national efforts operators of essential and adjust cooperation stakeholders in and ensure a services, service mechanisms with public combating cybercrime? coordinated response to providers) where and private sector cybercrime incidents? appropriate? stakeholders? 5 Have competent 1 Have you organised 1 Do you provide 1 Do you collect statistics 1 Do you regularly 1 authorities awareness-raising guidance to essential on the reporting of evaluate and adapt recognised the need campaigns for essential and important entities on cybercrime activities by awareness-raising to raise awareness and important entities identifying and reporting essential and important activities for essential among essential and aimed at improving the suspected cybercrime entities and use this and important entities important entities, identification of activities? information to adapt your based on emerging regarding the cybercrime activities? awareness-raising cybercrime trends, identification of activities? lessons learned and cybercrime activities?
- feedback from previous campaigns?
- 6 Are there any 1 Have you designated an 1 Is there a formal 1 Do you regularly assess 1 Do you participate in 1 informal or formal operational national point mechanism in place to and optimise your coordinated actions with cooperation channels of contact to exchange foster cooperation with participation in European other Member States for sharing information and respond other Member States Union Agency for Law and Europol to disrupt information on to urgent information and share information to Enforcement cybercrime activities cybercrime activities requests from other effectively prevent, Cooperation (Europol) (e.g. dismantling of with cybersecurity Member States detect and respond to cooperation networks organised groups, competent authorities regarding offences set cybercrime incidents? (e.g. EC3, the Joint takedown of criminal and law enforcement out in Directive Cybercrime Action infrastructure, dark web agencies in other 2013/40/EU on attacks Taskforce or the Europol markets or botnets) and Member States? against information platform for experts)? is there a structured systems and Directive process in place to (EU) 2016/680 (the Law review the aftermath of Enforcement Directive these incidents, (LED))? analysing what went wrong and what went right, to learn lessons and improve future responses to cybercrime? 7 Have you identified 1 Do you prioritise 1 Are appropriate tools 1 During cybercrime 1 Do you participate in 1 the privacy rules you compliance with personal and procedures in place investigations, do you developing and need to comply with data protection rules to ensure that consult or leverage maintaining during cybercrime during coordination and information sharing in guidance from Europol’s standardised tools, investigations? information sharing in cybercrime Data Protection Experts methodologies, forms cybercrime investigations complies Network to ensure and procedures for investigations? with personal data compliance with personal information sharing protection rules? data protection rules? during cyber investigations that are shared with EU stakeholders (law enforcement agencies, CSIRTs, ENISA and Europol’s EC3)?
- 8 Have you assessed 1 Has your national 24/7 1 Do you cooperate and 1 Do you promote and 1 Do you use the EU 1 how key stakeholders point of contact for the share information with implement standards and Blueprint and/or the EU combating cybercrime EU law enforcement EU agencies (e.g. guidelines issued by EC3 law enforcement can benefit from the emergency response Europol’s EC3, the or ENISA for emergency response expertise and protocol established an European Union Agency collaboration and protocol to respond resources offered by information-sharing for Criminal Justice information sharing (e.g. effectively to large-scale EC3 and ENISA? procedure to get Cooperation (Eurojust), ENISA’s taxonomy for cyber incidents? expertise from EC3 ENISA) to ensure the the CSIRT community)? during a cyberattack effective prevention and response? detection of, and response to, cybercrime? 9 Have you identified 1 Are training materials 1 Is specialised training 1 Do you evaluate the 1 Are there 1 the requirements (e.g. and programmes on regularly provided to law adequacy of the training interinstitutional training knowledge, skills, cybercrime-related topics enforcement officials provided to law courses or workshops resources) for law provided at both the (e.g. police officers, enforcement agencies, for law enforcement, enforcement officials national and the EU prosecutors, judges) on the judiciary and national judges, prosecutors and (e.g. police officers, levels (e.g. by Europol, cybercrime-related CSIRT personnel to national/ prosecutors, judges) Eurojust, the European topics (e.g. prosecution address cybercrime? governmental CSIRTs at to effectively carry out Anti-Fraud Office, the EU of cyber-enabled crimes, the national level and/or their duties in the Agency for Law collection and handling the multilateral level? context of Enforcement Training, of electronic evidence, cybercrime? ENISA) to law computer forensics)? enforcement officials? 10 Have initial measures 1 Do CSIRTs provide law 1 Do law enforcement and 1 Do you have a 1 Do your law 1 been implemented to enforcement and judicial judicial authorities have mechanism in place to enforcement and judicial strengthen the authorities with guidance sufficient capabilities regularly evaluate the authorities actively detection, or support in identifying, (e.g. tools, personnel) to adequacy of law participate in the investigation and reporting or analysing effectively detect, enforcement and judicial transborder exchange of prosecution suspected cybercrime investigate and authorities’ resources best practices and legal capabilities of law incidents? prosecute cybercrime and adjust them as expertise (e.g. through enforcement and incidents? necessary? the European Judicial judicial authorities Cybercrime Network)? (e.g. police officers, prosecutors, judges) to address cybercrime?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 7 – Engage in a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 international objective in your NCSS (formally or informally) defined and documented mechanism to regularly mechanisms in place to cooperation or do you plan to cover intended results, guiding action plan that includes review and assess your ensure that the action it in the next edition? principles, or key specific activities with action plan to ensure that plan is monitored and activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Has your government 1 Are you engaged in 1 Do key national 1 Are international 1 Do you take a leading 1 established a formal bilateral or multilateral stakeholders (e.g. the cybersecurity role or engage actively strategy and/or does it cooperation agreements ministry of foreign cooperation initiatives in discussions on one or maintain formal or with Member States, affairs, the national regularly assessed for more topics within informal cooperation non-EU countries or cybersecurity authority, effectiveness and multilateral cybersecurity channels with international partners for CSIRTs) have alignment with national- agreements? authorities or purposes such as sufficient/dedicated and EU-level objectives stakeholders in non-EU information sharing, means and budget to (e.g. as per the EU countries, expressing capacity building or the engage in international cybersecurity strategy)? the intention to engage provision of mutual cybersecurity in international assistance in the field of partnerships and cooperation on cybersecurity? cooperation frameworks cybersecurity-related to support strategic issues? alignment on cybersecurity topics? 2 Do you have any 1 Do you have procedures 1 Do you actively 1 Do you regularly identify 1 Do you proactively 1 formal or informal in place to facilitate the participate in any lessons learned and participate in coordination or coordination with your international cooperation areas for improvement international initiatives information-exchange international partners to network or partnership from your participation in that contribute to channels in place with tackle large-scale to coordinate and international cooperation enhancing the international partners cybersecurity incidents facilitate timely and networks and prevention of and (beyond the EU’s beyond the EU’s secure information partnerships for incident response to large-scale borders) to support the borders? exchange during large- response beyond the cybersecurity incidents response to large-scale scale cybersecurity EU’s borders? (e.g. OSCE confidence-
- cybersecurity incidents beyond the building measures, the incidents? EU’s borders? UN Global Mechanism for Cyberspace) and build trust and confidence with international partners (beyond the EU’s borders)? 3 Do you have any 1 Are initial steps or 1 Do you have established 1 Do you provide any 1 Do you actively build 1 formal or informal negotiations under way cooperation incentives (e.g. trust, through secure cooperation or to establish formalised mechanisms between participation in national and reciprocal cybersecurity reciprocal cybersecurity key competent and cross-border cybersecurity information-sharing information-sharing authorities (e.g. cybersecurity exercises, information sharing, with channels established arrangements on threats, cybersecurity and NIS2 access to government multinational private between key vulnerabilities and best supervision authorities, briefings) to multinational sector entities operating competent authorities practices between key cyber crisis- private sector entities to in your Member State? (e.g. cybersecurity and competent authorities management encourage their NIS2 supervision (e.g. cybersecurity and authorities) and engagement in authorities, cyber crisis- NIS2 supervision multinational private cybersecurity information management authorities, cyber crisis- sector entities, and are sharing? authorities) and management authorities) these mechanisms multinational private and multinational private compliant with national sector entities sector entities operating and EU law (e.g. on the operating in your in your Member State? sharing of sensitive or Member State? classified information)? 4 Do you officially 1 Do your national CSIRTs 1 Do your national CSIRTs 1 Is the involvement of 1 Do your national CSIRTs recognise (e.g. in plan to or have they actively participate in your national CSIRTs in take a leading role in strategic documents or already taken initial steps international or regional international and regional international CSIRT guidelines) the to engage in any cybersecurity cybersecurity networks (e.g. the importance of your international or regional cooperation frameworks cooperation frameworks Forum of Incident national CSIRTs cybersecurity beyond the EU’s CSIRTs regularly evaluated to Response and Security participating in cooperation frameworks Network (e.g. the GFCE, ensure alignment with Teams) to drive international or regional beyond the EU’s CSIRTs the Task Force – national priorities and to innovation, share 1 cybersecurity Network? Computer Incident focus efforts on the most predictive threat cooperation Response Team, the impactful cooperation intelligence and frameworks? International Watch and frameworks? influence cross-border Warning Network, cybersecurity policies in Forum of Incident line with NIS2 Response and Security principles? Teams)? 5 Have you officially Do you foster the active Do you contribute to Do you conduct regular Have you developed 1 1 1 1 recognised the need to participation of national cybersecurity capacity- evaluations of the impact and funded any
- actively participate in experts or organisations building initiatives at the and effectiveness of international international in international international or regional international cybersecurity capacitycybersecurity capacity- cybersecurity capacity- levels (e.g. GFCE, cybersecurity capacity- building projects, building initiatives building programmes Global Cyber Alliance, building initiatives in particularly targeting EU targeting EU candidate (e.g. through EU EU CyberNet or which you participate, candidate countries or countries or strategic CyberNet)? Cooperative Cyber and adjust your level of strategic regions (e.g. regions (e.g. the Defence Centre of involvement on the basis Western Balkans or Western Balkans or Excellence training)? of the findings? Eastern Partnership)? Eastern Partnership )? 6 Do you have an initial 1 Are roles and 1 Do you actively 1 Do you regularly 1 Do you proactively lead, 1 plan and specific responsibilities for participate in evaluate your chair or initiate activities priority areas for engagement with cybersecurity-related engagement with within international engagement with international activities and initiatives international organisations or EU international organisations and EU led by international organisations and EU agencies, including organisations and EU agencies (e.g. ENISA, organisations and EU agencies (e.g. ENISA, leading investigations or agencies (e.g. ENISA, Europol’s EC3, the agencies (e.g. working Europol’s EC3, the proposing new Europol’s EC3, the EEAS, the ITU, the groups, cybercrime EEAS, the ITU, the initiatives, to drive EEAS, the International OECD, Interpol) clearly investigations, OECD, Interpol) and strategic priorities, Telecommunication established and have development of adjust your involvement innovation and cross- Union (ITU), the they been communicated standards and norms)? based on strategic border coordination in Organisation for to the competent priorities or lessons line with NIS2 Economic Co-operation authorities to ensure learned? requirements? and Development effective coordination (OECD), Interpol)? and compliance with NIS2 requirements? 7 Do you acknowledge 1 Do you regularly 1 Do you engage with 1 Are results of 1 Do you organise or 1 the value of participate in regional organisations international and contribute to the participating in international and (e.g. the EU, NATO) in European cybersecurity planning and execution international and European cybersecurity participating in exercises (e.g. Blue of international or European cybersecurity exercises, at least in an multinational OLEx, Locked Shields) European cybersecurity exercises (e.g. Cyber observer role? cybersecurity exercises? regularly assessed to exercises? Europe, Blue OLEx, identify areas for Locked Shields) for improvement in crossexchanging best border coordination and practices and operational readiness? enhancing cross-border cooperation? 8 Have you conducted 1 Have you identified 1 Is there a procedure in 1 Are your national 1 Do you actively 1 any assessment of the priority areas (e.g. digital place to take part in cybersecurity legislation participate in crossalignment of national evidence exchange, international discussions and policy frameworks border initiatives, cybersecurity laws and attribution, cybercrime to ensure the alignment regularly reviewed and frameworks and working policy frameworks with investigation) for of the national updated to ensure groups aimed at
- international standards, harmonising national cybersecurity legislation ongoing alignment with harmonising norms and best cybersecurity legislation and policy frameworks international cybersecurity norms and practices? and policy frameworks with international cybersecurity standards standards (e.g. the UN with international cybersecurity standards, and norms, while open-ended working cybersecurity standards norms and best supporting cross-border group on the security of and norms to facilitate practices? cooperation and and in the use of international compliance with NIS2 information and cooperation? governance communications requirements? technologies, the ITU)? 9 Have you formally 1 Have priority areas and 1 Is there a formal 1 Do you actively 1 Do you lead or actively 1 acknowledged the key national framework in place to participate in joint EU contribute to importance of stakeholders been implement tailored and diplomatic responses international developing norms of identified to support coordinated diplomatic and operational negotiations and responsible state national diplomatic measures, including measures as defined in discussions on the behaviour and efforts in the formulation attribution and restrictive the EU cyber diplomacy development of rules, confidence-building of a responsible state measures (sanctions), in toolbox? norms and principles for measures in behaviour framework in accordance with the EU responsible state cyberspace, in cyberspace? cyber diplomacy behaviour in alignment with EU and toolbox? cyberspace, their international applicability in cybersecurity international law and cooperation confidence-building frameworks? measures within regional and international organisations (e.g. the UN, OSCE)? 10 Do you officially or 1 Do your NCSS, sectoral 1 Do you participate in 1 Do you actively engage 1 Do you lead or actively 1 unofficially recognise policies or guidance EU-level initiatives in structured international coordinate international internet fragmentation documents embed promoting human rights, partnerships, including initiatives to strengthen as a challenge to the principles that safeguard fundamental freedoms with emerging and and implement the global, open and global, open and and a secure, open and developing countries multistakeholder model interoperable nature of interoperable internet, resilient internet, (e.g. in the Global South) for internet governance the internet? including our core ensuring inclusive and to promote a global, in global forums (e.g. the democratic values, affordable digital access open and secure UN Internet Governance fundamental freedoms (e.g. the cybersecurity cyberspace? Forum, the World Trade and human rights online? strategy for the Digital Organization, the Decade, the European Committee on Digital Internet Forum, the Economy Policy, the Connecting Europe GFCE), shaping norms, Facility (CEF Digital))? policies and cooperative frameworks to ensure a
- secure, open and interoperable internet?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 8 – Establish trusted a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 information-sharing objective in your (formally or informally) defined and documented mechanism to regularly mechanisms in place to mechanisms NCSS or do you plan intended results, guiding action plan that includes review and assess your ensure that the action to cover it in the next principles, or key specific activities with action plan to ensure that plan is monitored and edition? activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Has your NCSS 1 Have you created a 1 Do you have a formal 1 Have you optimised your 1 Is the national 1 acknowledged the policy or action plan that information-sharing information-sharing information-sharing strategic importance sets the scope and framework that aligns framework to distribute framework regularly of establishing trusted priorities for with EU law and national tasks among public and reviewed and adapted to information-sharing cybersecurity information security priorities, private stakeholders evolving cybersecurity mechanisms through sharing, identifies key ensuring structured (including strategic large- practices, while ensuring the development of stakeholders and coordination and scale private efficient distribution of robust partnerships establishes PPPs for compliance across stakeholders), ensuring a collected information between public and trusted information- relevant stakeholders high-quality, accurate among relevant public private stakeholders? sharing mechanisms? and incorporating and timely exchange of and private stakeholders national public–private information in line with through advanced data cooperation NIS2 requirements and processing technologies mechanisms? national cybersecurity such as AI or machine priorities? learning? 2 Does your NCSS 1 Does your national 1 Are essential and 1 Do you regularly 1 Do you regularly 1 actively promote and action plan include the important entities evaluate the integrate outcomes from raise awareness establishment and actively encouraged and performance and impact sectoral ISACs into about the existence support of sector-specific supported by national of established ISACs to national strategies and and development of cybersecurity authorities to participate review and adapt the operations while ISACs and PPPs as information-sharing in sectoral ISACs support provided to them collaborating with ISACs strategic tools for arrangements such as through regulatory, to optimise their and PPPs to ensure that pooling expertise and ISACs and PPPs through technical and financial cooperation and capacity their activities adapt to resources at the dedicated resources support to ISACs and for pooling expertise and evolving threats through provided to facilitate their PPPs to enable their resources? joint planning, cross-
- national and EU activities and enable strategic role as defined sector coordination and levels? pooling and sharing of in your NCSS? alignment with EU information and initiatives? resources? 3 Have you conducted 1 Are the roles, 1 Are there guidelines in 1 Do you regularly review 1 Do you maintain formal, 1 an assessment to responsibilities and place setting out the and update the cross-sectoral identify the need for access control measures type and level of responsibilities and agreements or protocols differentiated access clear and documented information that an entity access control that specify and levels among key for all relevant should be able to access procedures of periodically adjust stakeholder groups stakeholders, competent based on its maturity stakeholders institutional access to such as competent authorities, critical level, ensuring that it participating in shared cyber-threat and authorities, critical infrastructure operators, receives useful, relevant information sharing? -incident data, based on infrastructure law enforcement and and actionable evolving operational operators, law private sector actors? information? roles, legal mandates enforcement and and strategic priorities? private sector actors? 4 Do you recognise the 1 Are draft legal provisions 1 Are legal safeguards 1 Are legal safeguards 1 Do you maintain cross- 1 need to protect or policy measures in formally adopted and regularly reviewed and sectoral agreements or entities that voluntarily place that cover liability, documented, including updated in coordination national-level guidance share sensitive confidentiality and GDPR liability protections and with data protection that clarify legal cybersecurity compliance for voluntary confidentiality protocols authorities and protections and information, including information sharing? for entities sharing cybersecurity confidentiality standards basic confidentiality sensitive information stakeholders to ensure for voluntary information expectations? voluntarily? alignment with evolving sharing, and are these national and EU law? integrated with EU-level mechanisms (e.g. EUlevel ISACs, the CSIRTs Network, EU-Cyclone)? 5 Do you maintain any 1 Do you have a national 1 Do competent 1 Do you assess the 1 Do you regularly update 1 formal or informal cooperation framework authorities and private effectiveness and strategic cooperation cooperation channels focused on the security sector entities involved limitations of cooperation agreements or protocols between competent of critical infrastructure, in critical infrastructure frameworks in fostering with critical infrastructure authorities and private such as advisory boards, actively participate in the cooperation between operators that enable sector entities steering groups, forums cooperation framework? competent authorities joint threat analysis, responsible for critical or expert groups? and private sector coordinated response infrastructure (i.e. entities and use the planning and integration essential and findings to optimise with EU-level important entities processes? mechanisms (e.g. EUunder NIS2 and level ISACs, EUcritical entities under Cyclone, the CSIRTs the CER Directive)? Network)?
- 6 Does the NCSS 1 Have clear guidelines 1 Is information on cyber 1 When sharing sensitive 1 Do formal and regularly 1 establish roles and and conditions been threats, vulnerabilities national security reviewed protocols or responsibilities for documented for how and national security information (e.g. agreements exist that sharing essential different types of national status regularly intelligence or ensure secure, timely national cybersecurity cybersecurity information exchanged with private cybercrime findings), are and context-specific information with will be shared with sector entities, recipients selected based sharing of national relevant private relevant entities? particularly those on confidentiality and the security-related cyber entities? operating critical need-to-know principle? information with critical infrastructure? infrastructure entities? 7 Have you identified 1 Have you established a 1 Do you actively promote 1 Do you provide a 1 Do you regularly refine 1 benefits that could framework for private incentives for private sufficiently diverse set of the available incentives motivate private sector entities that sector entities to incentives (e.g. technical, to ensure that they entities to actively provides incentives – encourage their financial and intelligence- remain attractive and participate in wider such as early warnings, engagement in based) to engage a wider effective for target information-sharing official threat briefings information sharing? range of private sector private sector entities? initiatives? and participation in joint entities in informationexercises – for their sharing mechanisms? active involvement in information-sharing mechanisms? 8 Does your NCSS 1 Do you have 1 Does your information- 1 Do you have 1 Does your information- 1 contain strategic mechanisms in place to sharing framework mechanisms in place to sharing framework goals aimed at reach out to SMEs and include mechanisms ensure that SMEs and enable the dynamic supporting SMEs and small organisations to providing SMEs with small organisations can distribution of relevant small organisations in provide cybersecurity- access to certain levels effectively benefit from information across accessing nationwide relevant information, at of information? information sharing with sectors and entity types, or sectoral least on an ad hoc major organisations? ensuring that insights information-sharing basis? from more mature mechanisms in order entities are effectively to enhance collective shared with others? resilience? 9 Have you assessed 1 Does your NCSS 1 Have you established 1 Do you regularly 1 Do you use advanced 1 the availability of encourage integration of and operationalised, evaluate and refine the information-sharing tools secure voluntary inputs collected and through formal guidance effectiveness of your that combine real-time information-sharing centralised by a national from CSIRTs, information-sharing threat intelligence, AIplatforms with clear stakeholder from law cooperation platforms sources, procedures, driven analysis, and cross-sector enforcement, that enable real-time tools and platforms to secure cross-border responsibilities for intelligence, CSIRTs and and secure information ensure that they support exchange, that are stakeholders to be the private sector to build exchange among secure and coordinated regularly updated to stay incorporated into your a unified threat stakeholders? exchange through scalable, responsive to NCSS? landscape view? dedicated channels new threats, and able to among law enforcement, produce actionable
- CSIRTs and private insights for national and entities? EU-level decisionmaking? 10 Is the need to 1 Are there ongoing 1 Do you support expert 1 Are legal and 1 Do you maintain cross- 1 address legal, initiatives to reduce legal, exchange programmes, organisational sector and cross-border organisational and organisational or cultural joint exercises or frameworks regularly cooperation cultural barriers to barriers and thereby participation in events to reviewed and adapted in mechanisms that information sharing foster effective actively overcome consultation with cross- proactively address formally information sharing? cultural barriers and sector stakeholders to emerging legal and acknowledged in your foster information reduce barriers to organisational barriers, NCSS or policy sharing? information sharing? incorporating lessons documents? learned from joint exercises and EU-level collaboration?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 9 – Establish mutual a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 assistance objective in your (formally or informally) defined and documented mechanism to regularly mechanisms in place to processes NCSS or do you plan intended results, guiding action plan that includes review and assess your ensure that the action to cover it in the next principles, or key specific activities with action plan to ensure that plan is monitored and edition? activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Is there an initial 1 Have you identified key 1 Have you established 1 Do you have a 1 Are best practices in 1 awareness among national and cross- formal mutual mechanism to assess the cross-border supervisory national stakeholders border stakeholders assistance agreements effectiveness, efficiency and enforcement about the need for (including CSIRTs, law with other Member and consistency of cooperation mutual assistance in enforcement agencies States covering areas supervisory and continuously reviewed supervisory and and sectoral regulators) such as incident enforcement measures, and integrated into enforcement actions for cooperation in response, legal implemented under national processes? under NIS2? supervisory and proceedings and sharing mutual assistance enforcement measures of cybersecurity agreements? (including specialised capabilities? support and expertise)? 2 Has a preliminary 1 Are legal experts 1 Do you have any legal 1 Are mutual assistance 1 Are lessons learned 1 legal analysis been regularly consulted when mechanisms in place to activities related to from mutual assistance conducted to identify planning or conducting ensure that supervisory supervisory and activities regarding national provisions mutual assistance and enforcement enforcement regularly supervision and relevant to mutual activities related to measures under mutual evaluated for legal enforcement assistance under supervisory and assistance are in line compliance and updated systematically used to NIS2? enforcement measures? with national and EU accordingly? improve your legal law? framework and to enhance the timeliness and security of responses? 3 Are formal or informal 1 Have you designated a 1 Are secure and reliable 1 Are the single points of 1 Are lessons learned 1 points of contact single point of contact communication channels contact and from previous mutual
- established for mutual within your competent available for mutual communication channels assistance requests assistance with other authorities for the assistance among regularly tested for used to improve Member States? purpose of mutual competent authorities? reliability and operational communication and assistance coordination? efficiency? coordination capabilities? 4 Have you considered 1 Are standardised 1 Are procedures 1 Do you regularly review 1 Are mechanisms in 1 developing templates templates available for documented for the procedures and place to ensure that and protocols to submission and handling submitting, responding adapt them accordingly, mutual assistance facilitate mutual of mutual assistance to and documenting especially to ensure procedures remain assistance requests requests? mutual assistance proportionality, relevant in light of and their handling? requests? competence alignment technological and respect for developments, legal sovereignty? changes and evolving security directives? 5 Do you have any 1 Are initial procedures in 1 Have documented 1 Do you have a 1 Are existing cooperation 1 formal or informal place to facilitate regular guidelines been mechanism to support networks (e.g. the NIS2 cooperation practices consultation and developed to support cross-sectoral and cross- Cooperation Group) among competent information exchange consistent domain (e.g. civilian and and/or participation in authorities to consult, among competent implementation of defence) consultation specific programmes inform and support authorities for mutual mutual assistance and coordination in (e.g. staff exchange) each other in cross- assistance activities? processes and ensure cross-border supervisory used to consult, inform border supervisory clarity among competent and enforcement and support Member and enforcement authorities? actions? States in supervisory actions? and enforcement measures, contributing to a coordinated cybersecurity approach and strengthening mutual understanding? 6 Do you use the NIS2 1 Cooperation Group as a platform to discuss specific requests for mutual assistance to enhance cooperation at the EU level? 7 Have you reviewed 1 Do your competent 1 Do you have a process 1 Do competent authorities 1 Do you proactively use 1 existing best practices authorities have internal in place to request or have established EU resources (e.g. in supervisory and procedures or guidelines provide mutual processes to handle ENISA’s cybersecurity enforcement in place to request assistance through the specific cybersecurity support action) to measures to support mutual assistance from Cybersecurity requests, such as on-site strengthen cross-border national mutual Emergency Mechanism? inspections, off-site mutual assistance in
- assistance other Member States supervision or targeted supervisory and processes? under NIS2? security audits? enforcement activities? 8 Has your government 1 Are resources 1 Is proportionality taken 1 Are regular evaluations 1 Are lessons learned 1 informally or formally (personnel, budget or into account when conducted to ensure that from previous mutual recognised the need tools) currently allocated allocating resources sufficient and assistance activities to allocate sufficient to mutual assistance (personnel, budget or proportionate resources used to assess and resources to support activities? tools) for mutual (personnel, budget or adjust future resource effective mutual assistance activities? tools) are dedicated to allocations? assistance in mutual assistance supervisory and activities? enforcement actions under NIS2? 9 Are there any formal 1 Have you initiated joint 1 Are common 1 Do you monitor and 1 Are lessons learned and 1 or informal channels supervisory or inspection agreements or evaluate the best practices from joint for sharing information activities with other arrangements in place to effectiveness of joint supervisory actions, or coordinating Member States or conduct joint supervisory supervisory actions, inspections and audits inspections/audits with participated in early- actions, inspections or inspections and audits to actively shared in the other Member States stage coordinated audits, audits with other identify areas for NIS2 Cooperation Group under the NIS2 mutual as part of mutual Member States? improvement? or in other EU networks assistance assistance or to adapt national framework? cooperation efforts? processes? 10 Have you identified 1 Are clear conditions 1 Are clear conditions 1 If considering the refusal 1 If considering the refusal 1 potential situations in established under which established under which of a request, do you have of a request and upon which a request for a mutual assistance a mutual assistance processes to consult the the request of the mutual assistance request may be refused request may be refused other concerned concerned Member might be refused? due to a lack of if it concerns information competent authorities? States, are there competence or because or actions contrary to procedures in place to the request is national security, public consult the European disproportionate to the security or defence Commission and supervisory tasks of the interests? ENISA? competent authority?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 10 – Develop crisis a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 management objective in your NCSS or (formally or informally) defined and mechanism to regularly mechanisms in place to frameworks do you plan to cover it in intended results, guiding documented action plan review and assess your ensure that the action the next edition? principles, or key that includes specific action plan to ensure plan is monitored and activities in your action activities with clear that it is correctly dynamically adapted to plan that contribute to goals, timelines, and prioritized and evolving technological, achieving the objective allocated resources? optimized, including geopolitical and threat in an uncoordinated progress tracking, landscapes? way? performance evaluation, and identification of areas for improvement? 1 Has the need to establish 1 Have you proposed a 1 Is a dedicated cyber 1 Is the national cyber 1 Do you apply foresight 1 a national cyber crisis- national cyber crisis- crisis-management crisis-management techniques and management framework management framework framework established framework regularly integrated innovative been anchored in a outlining key processes, and integrated within reviewed and updated approaches to national strategic or stakeholder roles, your overall national based on stakeholders’ systematically update policy document? responsibilities and crisis-management feedback, lessons your national cyber accountability framework, including learned and international crisis-management structures? business continuity and best practices? framework, ensuring its disaster recovery effectiveness against aspects? emerging and future cyber threats? 2 Is there any formal or 1 Have draft plans, 1 Is cyber crisis 1 Is the integration of 1 Is the alignment 1 informal recognition that coordination guidelines management formally cyber crisis between cyber crisis cyber crisis response or working groups been defined and integrated management into the management and should be coordinated established to explore into the national crisis national crisis general crisis with national crisis- the alignment between governance framework governance framework management management structures? cyber crisis- with clear information regularly reviewed to continuously refined management and on roles and ensure that both through joint exercises, national crisis- responsibilities and systems stay aligned feedback loops and management coordination protocols, when changes occur? scenario-based mechanisms? planning involving
- including cross-border relevant national- and aspects? EU-level actors? 3 Were initial steps taken to 1 Are predefined incident 1 Do you have structured 1 Are incident response 1 Are incident response 1 introduce predefined response plans for processes to train and plans regularly plans dynamically response plans tailored to various threat scenarios coordinate relevant evaluated and enhanced updated based on different cybersecurity formally established and authorities and based on feedback from predictive insights and threat scenarios? regularly updated? stakeholders for relevant stakeholders lessons learned, effective implementation and international best ensuring continuous of incident response practices? improvement and plans? fostering innovation in cyber crisis management? 4 Is there a preliminary 1 Is there a structured 1 Is there a designated 1 Is there a systematic 1 Is there a flexible, 1 approach to selecting approach that ensures authority with a clear mechanism that ensures dynamic and forwardcompetent authorities for that competent legal mandate and with that competent looking mechanism that managing large-scale authorities are formally adequate and authorities regularly ensures that specialised cybersecurity incidents, nominated and sustainable human, review their legal resources are in place outlining roles and introduced to all relevant financial and technical mandate, resources and for continuous forward responsibilities for public stakeholders and resources, and have capabilities, to maintain planning, threat and private stakeholders actively engage in cyber clear roles and the full alignment of anticipation and and ensuring adequate crisis management with responsibilities been stakeholders with their adaptive planning, and resources for national national actors (e.g. formally established for roles and that roles and cyber crisis security, defence, civil- all stakeholders to responsibilities, through responsibilities are management? protection and law ensure structured and continuous evaluation regularly reviewed and enforcement agencies, efficient collaboration in and adjustment of optimised based on ministries), with the managing large-scale resource adequacy and evolving threats and necessary resources to cybersecurity incidents to guarantee effective lessons learned? fulfil their mandate? and crises? coordination and response during largescale cybersecurity incidents and crises? 5 Is there a common 1 Are cybersecurity crisis 1 Are sector-specific 1 Is there a multi-year 1 Are national 1 understanding among exercises and exercises, including cybersecurity exercise cybersecurity exercise stakeholders of the simulations covering the tabletop and live programme with scenarios and importance and value of strategic, operational simulations, regularly dedicated funding for procedures regularly conducting exercises to and technical levels held at the national design, planning and updated and test and improve national organised nationally, at and/or international execution, including harmonised with other cyber crisis-management least on an ad hoc levels to test crisis procedures to collect, Member States to capabilities? basis? management, assess review and implement reflect technological preparedness, identify feedback to meet advances, evolving gaps and validate participants’ needs? threats, global coordination protocols, developments and
- with documented integration into outcomes and European crisis stakeholder response mechanisms? involvement? 6 Do you acknowledge the 1 Do you participate in 1 Do you actively engage 1 Do you actively 1 Do you organise or 1 value of participating in cyber crisis- in EU-level, regional or encourage both public actively contribute to the EU-level, regional and management exercises international cyber crisis and private stakeholders organisation of tabletop international exercises at the EU level at least exercises? to participate in EU-level and live simulations at and simulations (e.g. in an observer role? cybersecurity the EU level to lead and Cyber Europe, Blue simulations to test and innovate cross-border OLEx, Locked Shields) optimise coordination cyber crisisfor sharing best practice protocols across sectors management and enhancing and borders? capabilities? cooperation across sectors and borders? 7 Is there an initial 1 Have procedures or 1 Are after-action and 1 Is there an established 1 Are lessons learned 1 recognition of the value of guidance been initiated evaluation reports lessons learned process from cyber crisis systematically gathering to document lessons systematically produced to systematically collect, exercises and reallessons learned from learned from cyber crisis following cyber crisis analyse and integrate world incidents exercises and real-world exercises and integrate exercises and incidents insights from cyber crisis systematically reviewed incidents to improve them into future to document outcomes exercises and incidents and integrated into national cyber crisis- planning efforts? and lessons learned? into national cyber crisis- national cyber crisismanagement management practices? management capabilities? frameworks through formal evaluation cycles and stakeholder consultations? 8 Is the importance of 1 Are frameworks being 1 Is there active 1 Are sector-specific cyber 1 Are insights from 1 sector-specific cyber developed to support engagement with sector crisis plans emerging threats and crisis planning or public– sector-specific cyber representatives, systematically updated technological private coordination crisis plans, aimed at including critical and integrated into the advancements acknowledged in national promoting preparedness operators not regulated broader national cyber systematically strategic documents? in critical sectors and under NIS2, through crisis plan, incorporating leveraged to strengthening public– regular meetings or feedback from both continuously enhance private coordination at forums to public and private sector-specific cyber the operational level? collaboratively develop stakeholders? crisis preparedness and and maintain cyber PPPs? crisis plans, ensuring ongoing coordination between competent authorities and private entities?
- 9 Is there any formal or 1 Are national guides or 1 Is there a structured 1 Are BRPs regularly 1 Are BRPs 1 informal expectation or draft initiatives available BRP framework in reviewed and updated systematically general awareness that to support critical, place, developed in based on lessons integrated into broader public entities and critical, essential and important consultation with learned from incidents national continuity and essential and important entities in developing relevant stakeholders, and exercises, with resilience planning, entities should maintain business recovery plans based on recognised national authorities ensuring adaptation continuity and recovery (BRPs), including reference models (e.g. providing tailored driven by forward capabilities in the case of references to ISO 22301, NIST guidance to different planning and crosscyber incidents? frameworks such as ISO special publication 800- types of entities? sectoral coordination? 22301, NIST special 34 or the COBIT publication 800-34 or framework), with the control objectives for specified procedures for information and related resumption and technology (COBIT) recovery? framework?
- NCSS # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R objective
- 11 – Secure a Do you cover the 1 Have you defined (formally or 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 digital objective in your NCSS or informally) intended results, defined and documented mechanism to regularly mechanisms in place to identity and do you plan to cover it in guiding principles, or key action plan that includes review and assess your ensure that the action build trust in the next edition? activities in your action plan specific activities with action plan to ensure that plan is monitored and digital public that contribute to achieving clear goals, timelines, it is correctly prioritized dynamically adapted to services the objective in an and allocated and optimized, including evolving technological, uncoordinated way? resources? progress tracking, geopolitical and threat performance evaluation, landscapes? and identification of areas for improvement? 1 Has a gap analysis been 1 Have strategic guidelines (e.g. 1 Are cybersecurity 1 Are cross-sectoral 1 Have strategic decisions 1 conducted to identify high-level policies, general policies consistently strategic coordination been taken to ensure specific requirements for principles or technical implemented and efforts in place to allow that digital public transforming public standards) been developed to supported by an continuous feedback, services are secure by administrations and digital ensure cybersecurity, established governance update mechanisms design, to foster a public services? efficiency, accessibility and framework across public and/or framework culture of innovation and compliance with EU standards administrations to formalisation to maintain cybersecurity in public for digital public services? enhance trust in digital the required level of administrations and to public services? cybersecurity ensure that digital public effectiveness and trust in services are driven by digital public services? continuous monitoring and predictive analytics (or similar techniques)? 2 Does your NCSS include 1 Do you have a strategy and/or 1 Are secure and reliable 1 Have you implemented 1 Do you participate in 1 requirements that outline guidelines to develop or digital identity solutions mutual recognition of e- peer reviews as part of high-level security and promote national digital developed with identification means with e-identification schemes, privacy measures to identity systems and trust participation from both other Member States? to maintain high levels of protect sensitive services (e.g. e-signatures, e- public stakeholders (e.g. security, privacy and information in national seals, e-registered delivery cybersecurity and NIS2 interoperability, adapting digital identity systems services, time stamping, supervision authorities, to new technological and ensure reliable website authentication) for the European developments and identification? citizens and businesses that Commission, ENSIA) emerging threats? are in line with European and and private international norms on stakeholders, in line with
- security, privacy-by-design guidelines to ensure and interoperability? effective cross-border interoperability and robust security and privacy protections? 3 Have you set out data 1 Are high-level policies, 1 Are national policies for 1 Are strategic 1 Are strategic decisions 1 security requirements for general principles or technical data security and coordination efforts in to enhance trust in digital public services in a standards in place to ensure protection implemented place across sectors to digital public services relevant strategic or policy the secure management of and operational across ensure data security in driven by continuous document? sensitive data exchanges in digital public services? digital public services? monitoring and forward digital public services? planning? 4 Have formal discussions or 1 Is there a structured 1 Are public trust surveys 1 Do you implement an 1 practice-sharing sessions approach in place to conducted to assess the adaptive approach to been conducted with key ensure transparent data impact of digital public enhancing data security stakeholders on transparent exchange practices service activities on in digital public data management in digital within digital public citizens’ trust? services? public services? services?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 12 – Establish a Do you cover the 1 Have you defined (formally 1 Do you have a 1 Do you have a formal 1 Do you have 1 national level risk- objective in your NCSS or informally) intended formally defined and mechanism to regularly mechanisms in place to assessment or do you plan to cover results, guiding principles, documented action review and assess your ensure that the action it in the next edition? or key activities in your plan that includes action plan to ensure that it plan is monitored and action plan that contribute specific activities with is correctly prioritized and dynamically adapted to to achieving the objective in clear goals, timelines, optimized, including evolving technological, an uncoordinated way? and allocated progress tracking, geopolitical and threat resources? performance evaluation, and landscapes? identification of areas for improvement? 1 Is there recognition that 1 Has a draft national 1 Is your national cyber 1 Does your national cyber 1 Is your national cyber 1 your NCSS should methodology for cyber risk risk assessment risk assessment risk assessment follow a assessment been methodology aligned methodology ensure framework flexible comprehensive, all- developed or piloted for with internationally coordinated identification enough to adapt to the hazards, risk-based priority sectors, such as recognised standards and management of risks to evolving cybersecurity approach to identifying those listed in Annexes I (e.g. ISO 31000, essential and important threat landscape? and managing and II to NIS2, or CER ISO/IEC 27005) or entities, while also cybersecurity risks? Directive critical entities? ENISA guidance? integrating with other Member States’ risk assessments and critical entity resilience assessments? 2 Has your national 1 Have you established 1 Do formal 1 Is there a structured process 1 Does your national asset 1 regulatory framework processes to ensure that all mechanisms exist to to regularly review and inventory deliver a incorporated relevant stakeholders coordinate asset update the list of relevant complete and detailed requirements for understand their roles and identification and risk entities and associated view of critical entities, identifying critical, responsibilities in identifying assessments across assets to remain aligned covering everything from essential and important these entities and their sectors as part of with the requirements of high-level services to entities? associated assets? your national NIS2 and the CER technical components? resilience and Directive? cybersecurity strategies? 3 Do you ensure that 1 Have procedures been 1 Is there a centralised 1 Is there a mechanism in 1 Are formal procedures in 1 stakeholders are aware established to regularly and regularly updated place to ensure that the place for cross-sectoral
- that the inventory of compile and update inventory of critical inventory of assets validation, inter-agency critical assets must be inventories of critical assets, assets managed by supporting critical, essential data sharing and continuously updated to including physical, digital the designated and important entities is integration of the asset maintain and hybrid systems, to competent authority? systematically updated? inventory into nationalcomprehensive support national cyber risk and EU-level resilience coverage in the assessments? planning processes? national cyber risk assessment? 4 Have you established 1 Do national initiatives or 1 Is the national cyber 1 Are formal mechanisms in 1 Do you actively 1 high-level requirements guidelines promote the use risk assessment place to ensure that cyber participate in the that mandate the use of of structured methodologies process based on risk assessments are development of scientific and or tools (e.g. threat scientific and regularly updated using scientifically and technological methods modelling, vulnerability technological validated scientific models, technologically (e.g. quantitative risk scanning) in cyber risk methodologies and sector-specific data and grounded cyber risk modelling, threat assessments? applied consistently coordinated cross-sector assessment processes simulations, AI-driven across all relevant approaches? and share best practices analytics) in cyber risk sectors? with other Member management? States? 5 Do relevant 1 Have you initiated 1 Are the results of 1 Are there formal 1 Is resource coordination 1 stakeholders programmes or planning cyber risk mechanisms to coordinate informed by real-time acknowledge that efforts to align resource assessments resources and authorities cyber threat intelligence national cyber risk coordination with cyber risk systematically used to across sectors based on to support flexible and assessment findings assessment findings? guide national cyber risk assessment agile responses to should guide strategic resource planning, outputs and performance evolving threats? resource coordination threat monitoring and indicators? to reduce the likelihood mitigation strategies? and impact of cyber incidents on critical entities, in line with NIS2 and the CER Directive? 6 Is there any informal or 1 Does your national cyber 1 Is there a formal 1 Are lessons learned from 1 Is your national cyber 1 formal procedure risk assessment framework feedback mechanism cyber incidents and risk assessment among national include formal mechanisms to ensure that cyber exercises systematically continuously updated stakeholders to ensure to collect and integrate risk assessments are integrated into national cyber with new inputs, that the evolving cyber lessons learned from cyber updated based on risk assessments through a including emerging threat landscape incidents and exercises? incident notifications, formal review process? threats and lessons informs updates to threat intelligence and learned from cyber national cyber risk lessons learned from incidents and exercises, assessments? exercises? to ensure an accurate reflection of your
- national cyber risk posture? 7 Do national authorities 1 Are there ongoing initiatives 1 Is the NCSS explicitly 1 Are formal mechanisms in 1 Are national cyber risk engage, even on an ad or documented efforts to based on a place to ensure ongoing assessments regularly 1 hoc basis, in activities systematically align national comprehensive cyber alignment between updated using scenario such as workshops or cybersecurity objectives risk assessment that cybersecurity strategy planning and simulations roundtables to align with national security incorporates national objectives and evolving that account for cybersecurity strategy priorities? security national security risks? geopolitical, objectives with national considerations? technological and hybrid security priorities? threat developments? 8 Are formal or informal 1 Have any formal or informal 1 Are cybersecurity 1 Are cybersecurity 1 Are up-to-date results of 1 practices used to methods been established priorities prioritisation decisions based national cyber risk identify key to prioritise key systematically derived on formal criteria and assessments cybersecurity cybersecurity challenges from national cyber performance indicators, and systematically made challenges through based on the outcomes of risk assessment coordinated across essential available to decisionnational-level cyber risk national cyber risk outcomes and and important entities, makers to support assessments? assessment? integrated into critical sectors and informed cybersecuritystrategic planning and competent authorities? related strategic resource allocation? decisions? 9 Do national 1 Have initial efforts or pilot 1 Are national cyber 1 Are cyber risk assessments 1 Are national cyber risk 1 stakeholders have a projects been launched to risk assessments embedded within national assessments common understanding assess interdependencies conducted regularly planning processes, continuously updated of the importance of and cascading effects and comprehensively, supported by cross-sector using advanced conducting periodic across critical sectors as addressing threats, collaboration and formal methodologies – such cyber risk assessments part of national cyber risk vulnerabilities, review cycles? as real-time data, that address threats, assessment practices? interdependencies simulations and strategic vulnerabilities and and cascading foresight – to anticipate impacts on critical effects? cascading impacts on sectors and essential critical entities, in entities? alignment with NIS2 and the CER Directive? 10 Have competent 1 Are all relevant 1 Are sector-specific 1 Are cyber risk assessments 1 Are sectoral cyber risk 1 authorities and priority stakeholders, including methodologies and formally coordinated across assessments sector entities begun critical entities, digital tools consistently sectors, ensuring data continuously updated collaborating to develop service providers and applied across priority sharing and integration into using real-time threat sector-specific SMEs, actively engaged in sectors, with the national threat landscape intelligence, predictive guidance for cyber risk national and sectoral cyber structured analysis? analytics and assessments under risk assessments to create participation from collaborative NIS2 and the CER a comprehensive threat critical entities, mechanisms with Directive? landscape? service providers and national and cross- SMEs? border stakeholders?
- 11 Has a plan been 1 Have training programmes, 1 Are tools, training and 1 Are capacity-building 1 Is capacity-building 1 drafted to provide tools, standardised templates or guidance measures integrated into continuously enhanced training and guidance sector-specific tools been systematically national cybersecurity through feedback to support relevant developed or initiated to provided to relevant planning and supported by mechanisms, innovation competent authorities enhance the capacity of competent authorities formal evaluation programmes and and critical, essential competent authorities and and critical, essential mechanisms and cross- lessons learned from and important entities critical, essential and and important entities sectoral coordination? cyber exercises and in conducting cyber risk important entities to conduct under national cyber incidents? assessments? consistent cyber risk oversight and quality assessments? assurance mechanisms? 12 Is there a high-level 1 Do you have a draft 1 Are structured 1 Are formal cooperation 1 Does the national 1 structure or framework that allocates mechanisms in place frameworks in place to framework include an organogram that makes responsibilities to national for coordinated cyber support joint cyber risk advanced tool that clear the roles of and cross-border risk assessments and assessments and enables relevant relevant competent stakeholders for cyber risk mitigation by relevant information sharing among competent authorities authorities and critical, assessment, incident competent authorities relevant competent and critical, essential essential and important handling and operational and critical, essential authorities and critical, and important entities to entities in conducting resilience? and important entities, essential and important conduct cyber risk cyber risk with roles and entities, with responsibilities assessments, aggregate assessments? responsibilities clearly operationalised through results and provide upestablished in formal agreements, joint to-date data for different national policy or protocols or inter-agency management levels, legal frameworks, coordination mechanisms? while ensuring that roles communicated to all and responsibilities are stakeholders and regularly reviewed and supported by shared updated in line with methodologies? evolving threats, lessons learned and strategic foresight? 13 Are there any formal or 1 Have you aligned cyber risk 1 Are cyber risk 1 Are formal mechanisms in 1 Are cyber risk 1 informal practices for assessment outcomes with assessment findings place to ensure that cyber assessment results using cyber risk updates to your NCSS and systematically risk assessment outcomes continuously used in assessment results in with strategic planning or integrated into your directly inform national processes driven by national cybersecurity resource allocation for strategic planning, strategic priorities, resource forward planning to planning and resource cybersecurity risk policy development allocation and the dynamically inform the allocation (Articles 18– management? and capability- development of NCSS and sectoral 20 of NIS2)? building cybersecurity capabilities? frameworks, support programmes? risk-informed resource allocation and enhance the operational resilience and
- cybersecurity capabilities of critical, essential and important entities?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 13 – Strengthening a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 national objective in your NCSS (formally or informally) defined and documented mechanism to regularly mechanisms in place to cybersecurity or do you plan to cover intended results, guiding action plan that includes review and assess your ensure that the action governance it in the next edition? principles, or key specific activities with action plan to ensure that plan is monitored and activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Has a national 1 Is a documented 1 Is a formal governance 1 Are governance 1 Is the governance 1 cybersecurity governance model in framework in place that structures routinely framework regularly governance structure place that clearly clearly sets out roles, reviewed, with updated to address been formally establishes roles, responsibilities and responsibilities aligned emerging risks and designated under the responsibilities, decision- interactions between all across ministries, stakeholders and to Cyber Solidarity Act, making processes and key stakeholders and agencies and sectors integrate foresight NIS2 or another legal coordination organisations? through binding capabilities? cybersecurity mechanisms and mechanisms? framework, with an allocates roles and identified lead authority responsibilities to responsible for competent authorities coordination across (e.g. national competent sectors? authorities, national cybersecurity certification authorities, NCCs), CSIRTs and relevant sectoral stakeholders? 2 1 Are coordination 1 Are there formal 1 Is collaboration 1 Are coordination 1 mechanisms under coordination frameworks institutionalised through mechanisms flexible and development (e.g. draft in place enabling joint activities, incident scalable, adapting to memorandums of structured collaboration exercises or shared new threats, understanding, informal among CSIRTs, single platforms with technologies and crosscommunication points of contact and harmonised procedures? border challenges channels)? competent authorities as
- defined in Article 13 of through continuous NIS2? improvement?
- 3 Are there basic 1 Is there an action plan 1 Is NCSS implementation 1 Are planning and 1 Is the strategy 1 planning structures or with timelines and roles managed through a implementation activities implementation at least ad hoc working to support structured central governance body coordinated through continuously monitored, groups overseeing implementation of the with oversight, cross-sector platforms evaluated and optimised NCSS implementation? NCSS? monitoring and reporting and aligned with national using strategic foresight functions? digital policies? and data-driven performance indicators? 4 Are cybersecurity and 1 Are initial efforts in place 1 Are coordination 1 Are dialogue 1 Is coordination driven by 1 sectoral authorities to build bridges between structures operational, mechanisms formalised integrated national risk aware of the need to cybersecurity bodies and ensuring that and aligned with sectoral assessments and collaborate on risk and sector-specific cybersecurity is crisis management or reviewed in light of joint threat management? authorities (e.g. critical embedded in sectoral operational continuity simulations or infrastructure)? regulatory frameworks protocols? multisector threat (e.g. covering transport intelligence? or energy), as per Article 13(4) of NIS2? 5 Have you identified the 1 Have any ad hoc, pilot or 1 Are regular, structured 1 Are the results of 1 Are assessments 1 need to periodically preliminary capability capability assessments capability assessments forward-looking, assess capabilities of assessments been conducted across used to shape national benchmarking against national cybersecurity conducted across national cybersecurity training, staffing and best practices and authorities across relevant national authorities, including the resourcing policies feeding into long-term human, technical and cybersecurity authorities identification and across national resilience and workforce financial dimensions? (e.g. the national prioritisation of capability cybersecurity development planning? cybersecurity certification gaps? authorities? authority for the peerreview exercise)? 6 Are supervisory 1 Have initial steps been 1 Are supervisory tasks 1 Are supervisory tasks 1 Are evaluation practices 1 activities (e.g. taken to explore ways to evaluated across evaluated across sectors (e.g. feedback loops, inspections, review and assess the sectors through through structured peer reviews, crossenforcement actions, performance of structured reviews or reviews or audits, even if sectoral assessments) guidance issuance) supervisory authorities audits, even if limited in limited in scope or regularly refined to systematically recorded based on recorded scope or frequency? frequency? enhance the and tracked? supervisory activities? effectiveness of supervisory authorities over time? 7 Have you started to 1 Is a draft or partial list of 1 Is there a central 1 Is the inventory 1 Is the stakeholder 1 identify national stakeholders maintained inventory of integrated with national landscape dynamically stakeholders and by any coordinating body stakeholders and crisis response planning updated based on policy authorities relevant to or authority? authorities, updated and used to manage shifts, incidents or
- cybersecurity periodically and used for stakeholder engagement innovation ecosystems governance? coordination and and task allocation? to ensure full inclusion? communications?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 14 - Establish a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 cybersecurity risk- objective in your NCSS (formally or informally) defined and documented mechanism to regularly mechanisms in place to management or do you plan to cover intended results, guiding action plan that includes review and assess your ensure that the action measures it in the next edition? principles, or key specific activities with action plan to ensure that plan is monitored and activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Have you established 1 Are there documented 1 Are cybersecurity 1 Are cybersecurity 1 Are adaptive security 1 any general sector-specific guidelines requirements for controls for operational models or threatcybersecurity or templates for essential essential and important and service-delivery informed architectures in requirements for and important entities on entities formally systems systematically place to ensure the essential and important implementing integrated into national monitored, assessed and ongoing protection of entities to protect their cybersecurity protections regulations or enforced across sectors, operational and serviceoperational and for operational and compliance with coordination delivery systems, service-delivery service-delivery frameworks? mechanisms in place? adjusted in near real systems? systems? time? 2 Is there a general 1 Do incident response 1 Are the incident 1 Are lessons learned from 1 Are predictive analytics 1 expectation that procedures and business response plans of critical past incidents integrated or simulations used to essential and important continuity plans exist for entities aligned with into improved preventive anticipate and reduce entities will report and essential and important national cyber crisis- and mitigation measures the potential impact of respond to incidents, entities, with minimal management plans? nationally? incidents across even if they are not implementation or sectors? fully formalised? testing? 3 Have you formulated 1 Do you support national 1 Do essential and 1 Are essential and 1 Are dynamic 1 any high-level initiatives that encourage important entities take important entities assessments used to recommendations for the adoption of into account recognised required to align with continuously validate essential and important cybersecurity tools (e.g. cybersecurity recognised cybersecurity whether technologies in entities to use state-of- zero-trust strategies, frameworks that frameworks that use by essential and the-art cybersecurity endpoint detection and incorporate state-of-the- incorporate state-of-the- important entities remain technologies and response, and security art measures? art measures? state-of-the-art in light of practices? information and event evolving threats?
- management) by essential and important entities? 4 Are basic risk 1 Do you support essential 1 Are risk assessments 1 Do you conduct sector- 1 Is there an established, 1 assessment templates and important entities in used as the basis for wide risk exposure data-driven approach to or models available for conducting formal cyber selecting and analyses and share them dynamically adjusting entities to evaluate risk assessments tailored implementing security with essential and risk-management cyber threats? to their sector? controls? important entities to measures based on support harmonised threat intelligence and responses? exposure trends? 5 Does the overall risk 1 Do you tailor guidance to 1 Are regulatory 1 Are impact-based risk 1 Is a differentiated and 1 management approach distinguish between requirements risk based assessments used to predictive regulatory consider or plan to requirements for SMEs and scaled according to prioritise regulatory focus approach applied based consider the different and large entities in the size and systemic and resource allocation on impact potential, sizes of essential and terms of expected relevance of each to higher-risk essential business model important entities in controls? essential and important and important entities? evolution and entity designing risk- entity? scale? management measures? 6 Are any EU or 1 Are national regulations 1 Do national 1 Are public–private 1 Are regulatory 1 international or procurement practices cybersecurity audits or dialogues used to adapt frameworks continuously cybersecurity encouraging voluntary reports assess both the regulatory guidance updated to reflect both standards or norms use of EU/international implementation of based on industry cost-effective practices (e.g. ISO/IEC 27001, standards (e.g. standards and the cost- feedback regarding and emerging global the Cybersecurity Act, European effectiveness of security feasibility and cost– standards? open-source initiatives) standardisation measures? benefit alignment? referenced in national organisations)? guidance without mandatory enforcement? 7 Are there mechanisms 1 Do you recommend 1 Have you established a 1 Are feedback loops in 1 Are forward-looking 1 available for entities to maturity models or gap national framework to place between regulators technologies (e.g. AI for self-assess and analysis tools to evaluate and improve and entities to refine risk modelling) used to improve their own essential and important the relevance and practices and policies inform continuous cybersecurity posture? entities for periodic self- practicability of based on real-world adaptation and evaluation? cybersecurity measures outcomes? improvement in required from essential cybersecurity and important entities? measures? 8 Have you proposed 1 Do you provide baseline 1 Have you established 1 Have you established 1 Do you continuously 1 comprehensive non- guidance for the technical, operational different requirements monitor emerging binding implementation of and organisational based on system technologies and recommendations for technical, operational requirements for sensitivity, sector or evolving threat
- essential and important and organisational essential and important threat exposure and landscapes to adapt and entities to comply with measures by essential entities in alignment with harmonised them with optimise minimum the risk-management and important entities to European and requirements set up in cybersecurity requirements set out in comply with the risk- international standards other sectoral regulations requirements, thereby Article 21 of NIS2? management and best practices? (e.g. DORA)? enhancing the resilience requirements set out in of essential and Article 21 of NIS2? important entities against future threats? 9 Have you conducted 1 Have relevant 1 Do you enforce 1 Is there a process in 1 Do you actively consult 1 consultations with stakeholders been obligatory requirements place for regularly with other Member representatives of identified and formally for digital service reviewing and updating States with the aim essential and important tasked with controlling providers as outlined in the baseline being to harmonise entities and relevant whether baseline Commission cybersecurity measures baseline cybersecurity sectoral associations to cybersecurity measures Implementing for essential and measures, leverage best incorporate their inputs are properly applied by Regulation (EU) important entities? practice and anticipate into the baseline essential and important 2024/2690 on emerging challenges? cybersecurity entities? cybersecurity riskrequirements? management measures under Directive (EU) 2022/2555?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 15 – Establish a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 incident reporting objective in your NCSS (formally or informally) defined and documented mechanism to regularly mechanisms in place to mechanisms or do you plan to cover intended results, guiding action plan that includes review and assess your ensure that the action it in the next edition? principles, or key specific activities with action plan to ensure that plan is monitored and activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Have preliminary 1 Has a legal framework 1 Are standardised 1 Are mandatory incident- 1 Does the legal reporting 1 reporting procedures been adopted to regulate reporting templates (e.g. reporting mechanisms framework include been drafted to support voluntary structured the non-mandatory (e.g. procedures and innovative mechanisms structured voluntary incident reporting, reporting templates templates) regularly for secure tracking and incident reporting under covering non-significant developed by the NIS2 evaluated and audited to verification of incident NIS2, including incidents, cyber threats Cooperation Group) improve data quality, reports, enhancing templates for reporting and near misses? available for essential incorporating insights transparency and incidents, cyber threats and important entities to from NIS2 peer reviews, reliability through and near misses? support prompt and best practice guides and lessons learned? structured mandatory technological incident notification? developments? 2 Do you organise 1 Have you developed 1 Have you deployed a 1 Do you regularly review 1 Have you implemented 1 consultations with sector-specific centralised reporting and update templates advanced analytical sector representatives instructions to guide platform offering and instructions based tools (e.g. algorithms, to develop and refine entities to comply with standardised templates on industry feedback to data platforms) to reporting templates, incident-reporting for submitting cross- improve reporting improve data quality and leveraging the support requirements? border impact practices including cross- support real-time and updates provided assessments and for border reporting assessment of crossby the NIS2 essential and important procedures and data border impacts? Cooperation Group’s entities to submit quality? working session on accurate and compliant incident reporting? incident notifications? 3 Are requirements for 1 Are there channels 1 Do you have a secure, 1 Are incident reporting 1 Do incident reporting 1 tools to facilitate allowing essential and centralised platform that tools regularly evaluated tools use automated incident reporting being important entities and allows entities to submit and audited to improve technologies, such as
- collected from other entities to submit incident notifications in a data quality, machine learning, to important and essential information about structured way, within incorporating insights refine reports submitted entities? significant incidents to the time frames from stakeholders (e.g. to CSIRTs, supporting competent authorities established by NIS2 and important and essential data validation and within the required time providing your CSIRTs entities, CSIRTs) and analysis for efficient frames or under with real-time alerts for best practices (e.g. from incident management voluntary incident individual incidents? NIS2 peer reviews or and strategic response reporting? guidance)? planning? 4 Have definitions and 1 Is there a set of clear 1 Have you incorporated 1 Do you regularly review 1 Have you used 1 criteria been criteria specifying the NIS2 definition of a threat assessments and advanced data analytics established to identify thresholds for severity ‘significant’ incident (i.e. stakeholder feedback to technologies to ‘significant’ incidents, and scope, particularly any incident causing or refine the criteria for continuously refine including factors such for digital infrastructure, capable of causing identifying significant incident classification as geographical ICT service management severe operational incidents, in line with parameters and support spread, duration, and digital providers, to disruption, financial loss evolving industry timely, informed impact severity and classify incidents as or considerable material standards and best decision-making? cross-border ‘significant’, including or non-material damage) practices? relevance? considerations of impact, into your national duration and cross- frameworks to ensure border implications? consistent assessment and notification procedures by entities? 5 Have you conducted 1 Have you developed and 1 Do you actively 1 Are your guidelines and 1 Have you deployed 1 initial training sessions made easily accessible participate in public and training programmes advanced educational for relevant entities to guidelines to support sector-specific events to regularly assessed and tools (e.g. interactive eclarify responsibilities relevant entities in raise awareness among updated based on learning platforms) that regarding mandatory meeting their reporting relevant entities about feedback from relevant incorporate new and voluntary reporting obligations? mandatory and voluntary entities? compliance and of incidents? incident reporting reporting requirements? obligations? 6 Have you conducted 1 Have you developed and 1 Have you developed 1 Do you regularly refine 1 Do you use advanced 1 workshops to help made accessible clear and consistent criteria for assessing techniques, such as entities assess and flag practical guidelines to criteria for entities to cross-sectoral and cross- predictive analytics, to incidents with potential help relevant entities assess and report cross- border impacts based on support dynamic cross-sectoral or cross- assess and report sectoral or cross-border feedback from reporting assessments of crossborder impact? potential cross-sectoral impacts in incident entities? border impacts in or cross-border impacts notifications? incident reporting? in incident notifications? 7 Have you engaged in 1 Have national CSIRTs 1 Have you implemented 1 Are the competencies of 1 Do designated CSIRTs 1 consultations with and sectoral authorities a centralised sectoral authorities and competent national CSIRTs and been formally tasked communication system regularly reviewed, and authorities use adaptive sectoral competent with receiving and linking CSIRTs and are new relevant technologies (e.g.
- authorities to identify processing incident sectoral competent authorities identified to dynamic data the stakeholders who notifications and authorities with maintain an up-to-date monitoring) to improve will be responsible for providing stakeholder standardised procedures and effective stakeholder the responsiveness to receiving and consultations? for incident reporting network? incident reports? processing incident and processing? notifications and for stakeholder consultations? 8 Have you established 1 Have procedures and 1 Do you use 1 Do you regularly 1 Do you use automation 1 basic communication standard operating standardised evaluate and update and real-time analytics channels and protocols been adopted communication communication protocols tools to enhance rapid, coordination between to set out communication protocols and shared between competent efficient information competent authorities responsibilities and platforms to enable authorities and CSIRTs exchange and incident and CSIRTs to comply ensure rapid, efficient, timely and incorporating feedback routing between with reporting coordinated sharing of structured exchange of mechanisms to assess competent authorities obligations under cybersecurity incident cybersecurity incident incident report quality and CSIRTs? relevant legislation reports between CSIRTs information among and adapt to evolving (e.g. the GDPR, and competent competent authorities, operational and DORA)? authorities? CSIRTs and regulators? technological developments? 9 Have you assessed all 1 Have you established 1 Have structured 1 Do you regularly review 1 Do you use predictive 1 potential counterparts and documented protocols and and optimise the analytics, automation or of your national single processes ensuring communication processes and tools similar technologies to point of contact and the efficient information flows platforms been used by the single point enhance the single point expected information between the national implemented to ensure of contact to improve its of contact’s efficiency in flows to set up single point of contact that the single point of ability to handle and disseminating incident processes for receiving and other relevant contact can manage and disseminate incident information and and disseminating stakeholders (e.g. distribute incident data information? coordinating response incident information CSIRTs, sectoral accurately and in a efforts? promptly and competent authorities, timely manner? accurately? ENISA, the European Commission)? 10 Has the development 1 Have guidelines been 1 Do you use 1 Do you regularly 1 Do you use adaptive 1 of protocols for timely developed to coordinate standardised procedures evaluate and update technologies to support information sharing information flows and communication information-sharing real-time information with single points of between single points of tools to enable the protocols with the single sharing and contact during cross- contact during cross- seamless exchange of point of contact to collaboration, enhancing border or cross-sector border or cross-sector incident data between improve its effectiveness the single point of incidents been incidents? single points of contact in cross-border and contact’s ability to initiated? during cross-border and cross-sector incident manage cross-sector cross-sector incidents? coordination? and cross-border incidents effectively?
- 11 Is there an ongoing 1 Have guidelines been 1 Are data analysis and 1 Are data aggregation and 1 Are adaptive data 1 initiative aimed at using developed for compiling aggregation systems in analysis processes analytics platforms in aggregated incident and analysing incident place to support cross- regularly reviewed and place that use machine data to enhance data to identify trends sectoral risk optimised to align with learning to generate national situational that inform national assessments and inform national cybersecurity real-time insights into awareness, sectoral cybersecurity planning? national cybersecurity and resilience emerging threats and risk assessments and planning? objectives? support strategic strategic planning? decision-making? 12 Are single points of 1 Have guidelines been 1 Do you submit reports to 1 Are lessons learned from 1 Is there a data-driven 1 contact and national developed to assist CIRAS on a regular past incidents integrated regulatory approach that authorities aware of the relevant national entities basis, at least every into future reporting and utilises insights from Cybersecurity Incident in understanding and three months, to response strategies, with CIRAS to inform national Reporting and Analysis effectively utilising maintain consistent and feedback loops cybersecurity policies System (CIRAS) and CIRAS for incident up-to-date incident established to and strategies? its capabilities for reporting? tracking? continuously improve facilitating structured CIRAS utilisation? incident reporting and analysis?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 16 – Balance a Do you cover the 1 Have you defined (formally or 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 security with objective in your informally) intended results, defined and documented mechanism to regularly mechanisms in place to privacy NCSS or do you plan guiding principles, or key action plan that includes review and assess your ensure that the action to cover it in the next activities in your action plan that specific activities with action plan to ensure that plan is monitored and edition? contribute to achieving the clear goals, timelines, it is correctly prioritized dynamically adapted to objective in an uncoordinated and allocated and optimized, including evolving technological, way? resources? progress tracking, geopolitical and threat performance evaluation, landscapes? and identification of areas for improvement? 1 Have you considered 1 Have steps been taken to draft 1 Has your NCSS 1 Do you regularly update 1 Does the NCSS include 1 incorporating the EU’s guidelines, policies or strategies incorporated EU data your NCSS to reflect all dynamic strategies to regulatory measures within your NCSS that protection laws and of the changes to the adaptively integrate data and privacy-by-design incorporate initial measures of applicable national data relevant regulatory tools protection principles, and data protection privacy-by-design and privacy- protection legislation to provided by the EU guided by regulatory principles into your by-default principles using EU ensure that through collaborative advancements, NCSS? regulatory tools? cybersecurity actions frameworks with stakeholder input and respect privacy rights stakeholders to emerging threats and and include safeguards systematically implement technologies? such as data GDPR/LED data minimisation and access protection principles? controls? 2 Have you considered 1 Are initial measures to 1 Are privacy-by-design 1 Do you conduct regular 1 Are adaptive measures, 1 integrating privacy- incorporate privacy-by-design and data protection reviews of cybersecurity such as real-time by-design, privacy-by- and privacy-by-default principles fully integrated frameworks to ensure privacy impact default and data principles in your cybersecurity into the standard ongoing compliance with assessments and protection principles frameworks under way, even if operating procedures of data protection automated compliance into your limited in scale? all cybersecurity regulations, refining checks, implemented to cybersecurity frameworks? processes based on continually improve initiatives? emerging threats and privacy and data technologies? protection integration in
- your cybersecurity frameworks? 3 Does your NCSS 1 Have initial frameworks been 1 Are regular joint working 1 Are coordination 1 Are adaptive 1 include plans to set created to coordinate group meetings in place processes between collaboration tools in up coordination cybersecurity and data within the NCSS to national cybersecurity place, such as real-time structures, such as protection authorities in line with ensure that authorities and data data-sharing platforms, joint working groups, NIS2 and GDPR/LED cybersecurity measures protection authorities implemented within joint between requirements? comply with the systematically evaluated working groups to cybersecurity and GDPR/LED and and refined within your continuously enhance data protection applicable national data NCSS to enhance the efficiency, authorities? protection legislation? alignment and ensure responsiveness and compliance with NIS2, alignment of the GDPR/LED and cybersecurity and data applicable national data protection initiatives? protection legislation? 4 Have you conducted 1 Have you identified key national 1 Are structured 1 Do you regularly assess 1 Are technical and 1 studies or analyses to stakeholders to contribute to the frameworks in place and optimise frameworks organisational measures identify areas for enhancement of the protection within your NCSS to to ensure the consistent (e.g. encrypted logging, improvement in of citizens’ privacy within ensure that privacy is prioritisation of privacy anonymised threat protecting citizens’ cybersecurity? consistently prioritised within national intelligence sharing, privacy rights? across all cybersecurity cybersecurity efforts? privacy-compliant measures and activities? monitoring) systematically promoted and integrated into cybersecurity practices and frameworks? 5 Is there an initial effort 1 Have you piloted any national- 1 Are national-level 1 Is there an established 1 Is your country 1 under way to develop level guidance or frameworks to guidance documents process to systematically positioning itself as a guidance or support privacy-compliant and frameworks actively integrate lessons learned leader in EU forums and frameworks to cybersecurity implementation? published and from domestic and discussions on good support the disseminated to support international privacy- practices in developing implementation of privacy-compliant focused cybersecurity and distributing privacy-respectful cybersecurity initiatives into national guidance supporting cybersecurity implementation? frameworks? GDPR-/LED-compliant solutions? cybersecurity solutions? 6 Have you considered 1 Have you started to promote 1 Are technical and 1 Are certifications (e.g. 1 Are innovative solutions, 1 the importance of policies that encourage public organisational measures ISO/IEC 27701:2019) such as real-time data adopting technical and private entities to adopt actively adopted to meet promoted within a formal protection and adaptive and organisational technical and organisational both privacy and cross-sectoral framework compliance monitoring, measures that measures that align with EU cybersecurity standards that incorporates employed to address the balance privacy and cybersecurity (e.g. anonymised threat performance monitoring continuously optimise between privacy and requirements such as intelligence sharing)? the balance between
- cybersecurity encryption and privacy- and regular feedback privacy and requirements? compliant monitoring? loops? cybersecurity? 7 Have you discussed 1 Have initial requirements been 1 Have you incorporated 1 Are DPIA practices 1 Are adaptive 1 with relevant established to conduct DPIAs the DPIAs as an integral regularly reviewed and technologies deployed stakeholders (e.g. law for evaluating personal data part of the NCSS enhanced through to support DPIA enforcement processing risks within development process, stakeholder consultations processes and enhance agencies, data cybersecurity policies? ensuring compliance to ensure alignment with their effectiveness in protection agencies) and risk mitigation in current data protection managing evolving the incorporation of data handling? requirements? personal data protection data protection risks? impact assessments (DPIAs) as a standard practice for assessing data protection risks in cybersecurity initiatives? 8 Have initial oversight 1 Has a responsible stakeholder 1 Are oversight 1 Are sector-specific 1 Do you have 1 mechanisms been been designated to oversee mechanisms established cybersecurity policies mechanisms in place to considered to assess and assess the impact of and functioning to and standards monitor the latest the impact of national national cybersecurity practices regularly assess and systematically reviewed technological cybersecurity and legal frameworks on address the impact of and updated to ensure developments in order to practices and legal privacy and data protection? national cybersecurity the integration of privacy adapt relevant privacy frameworks on practices and legal and data protection and data protection privacy and data frameworks on privacy considerations, guidelines and legal protection? and data protection? incorporating obligations? stakeholders’ feedback and best practices? 9 Have you taken initial 1 Have you identified key national 1 Are policies in place for 1 Are PET initiatives 1 Is the participation in 1 steps to support R & stakeholders for R & D efforts the adoption of PETs for continuously evaluated, and the promotion of D or the adoption of on the topic of PETs? public and private incorporating PET R & D driven by privacy-enhancing sectors? stakeholders’ feedback continuous innovation, technologies (PETs), to improve and support leveraging emerging such as frameworks and technologies and anonymisation adoption? strategic foresight to techniques and anticipate future needs secure multi-party and proactively advance computation in the solutions? public and private sectors? 10 Is there an initial plan 1 Have initial strategies been 1 Are privacy and data 1 Are sector-specific 1 Are advanced 1 to introduce developed to incorporate protection cybersecurity policies technologies, such as
- preliminary privacy- privacy and data protection considerations fully regularly reviewed and adaptive solutions with focused frameworks measures into cybersecurity integrated into sector- optimised, incorporating real-time monitoring, into cybersecurity standards for sectors managing specific cybersecurity audits and stakeholder deployed to enhance policies for sectors particularly sensitive personal policies to ensure feedback loops, to privacy and data handling sensitive data (special categories of data consistent embedding ensure effective protection integration personal data, such per the GDPR), in alignment across cybersecurity integration of privacy and across sector-specific as health, finance and with the GDPR/LED and measures? data protection? cybersecurity initiatives? identity data? applicable national legislation?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 17 – Improve the a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 cybersecurity of the objective in your NCSS (formally or informally) defined and documented mechanism to regularly mechanisms in place to supply chain or do you plan to cover intended results, guiding action plan that includes review and assess your ensure that the action it in the next edition? principles, or key specific activities with action plan to ensure that plan is monitored and activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Do you have any 1 Have you developed an 1 Have you performed a 1 Is the supplier risk 1 Do you proactively use 1 informal or formal plans initial framework or draft national-level risk assessment framework real-time intelligence, to evaluate supplier risk criteria to assess the risk assessment (services, regularly updated and EU warnings and and consider criteria for profile of ICT suppliers, technologies and used in national emerging threat the assessment of including geopolitical, products) based on a procurement policies and indicators to adapt the critical and high-risk legal, sector-specific and formal framework for regulations to restrict or supplier evaluation ICT suppliers? cybersecurity-related evaluating high-risk exclude high-risk framework, enforce factors? suppliers, and are suppliers from critical ICT responsive restrictions essential and important supply chains, based on and mandate entities required to national and EU- cybersecurity-related assess suppliers coordinated risk procurement accordingly, with assessments? requirements to mitigate national guidance and evolving supply chain oversight in place? risks? 2 Have you begun to 1 Have you created initial 1 Are policies on strategic 1 Have you 1 Do you dynamically 1 assess strategic policies or frameworks to dependency and institutionalised regular monitor and respond to dependencies in ICT support multi-vendor supplier diversification reviews of supplier strategic dependency supply chains or strategies and formally adopted and diversification and risks by adapting explored the feasibility considered thresholds for supported by operational strategic dependency supplier diversification of developing a supplier diversification mechanisms (e.g. risks, including applying policies (e.g. national-level multi- based on factors such as thresholds, criteria or specific thresholds (e.g. nearshoring, dual vendor strategy? market share or incentives), and are > 50 % market share or sourcing), promoting geopolitical risks? critical entities engaged geopolitical exposure) multi-vendor resilience and established across entities and
- in applying these collaboration with entities incentivising innovation measures? for implementing and redundancy? mitigation strategies? 3 Have you performed a 1 Are initial guidelines or 1 Have you published 1 Are supply chain security 1 Do you actively 1 study on cybersecurity draft baseline security national guidance for requirements embedded contribute to and align good practices for requirements for supply supply chain security? across sectors and with international and supply chain chains under harmonised with EU- EU efforts on supply management that is development based on wide and international chain cyber resilience? used by procurement in European or international standards (e.g. ISO/IEC various industry standards? 27001)? segments and/or in the public sector? 4 Have you informally or 1 Do you 1 Do you have national 1 Are supplier compliance 1 Is the implementation of 1 officially acknowledged encourage/enforce any requirements or and effectiveness risk measures by the importance of requirements, pilots or incentives for critical monitored systematically suppliers regularly ensuring that critical sectoral efforts to suppliers to apply through audits and reviewed and adjusted suppliers implement promote baseline cybersecurity risk reports? based on evolving supply chain risk cybersecurity measures measures? threats and sector measures? for critical suppliers? needs? 5 Have you identified the 1 Are initial public 1 Is there comprehensive, 1 Is public guidance for 1 Is public guidance for 1 need for public guidance materials or regularly updated public SMEs co-developed or SMEs continuously guidance on supply awareness campaigns guidance tailored to validated with refined based on chain risk management targeting SMEs being SMEs on managing stakeholders and linked emerging risks, SMEs’ for SMEs? developed or supply chain to sector-specific or EU- feedback and lessons disseminated? cybersecurity risks? level guidance? learned from incidents and audits? 6 Do you actively 1 1 participate in the design and implementation of the EU cybersecurity certification framework and the development and/or maintenance of EU cybersecurity certification schemes for ICT digital products, services and processes, as established in the Cybersecurity Act (e.g. participation in the European Cybersecurity Certification Group,
- promotion of technical standards and procedures for ICT product/service security)? 7 Have you initiated 1 Have you engaged 1 Is there structured 1 Do you contribute to EU- 1 Have you established 1 discussions on relevant stakeholders at cooperation and data level risk assessments to continuous collaboration identified ICT supply EU-level forums in ICT sharing across agencies promote inter-agency with EU-level forums chain risks at EU-level supply chain risk and national and cross-sector and programmes to forums? assessment through mechanisms (e.g. collaboration on ICT strengthen ICT supply shared lessons learned? covering cybersecurity, supply chain security? chain risk mitigation and procurement and critical awareness? infrastructure) to coordinate risk assessments and ICT supply chain incident collection and analysis, in line with Article 29 of NIS2? 8 Have you recognised 1 Have you started adding 1 Do you consistently 1 Have you aligned 1 Do you lead or co-lead 1 the need for secure ICT basic cybersecurity apply cybersecurity rules national procurement EU-wide initiatives to supply chains and requirements to ICT in procurement policies with EU strengthen supply chain begun identifying ways procurement processes processes, support recommendations and security, drive innovation to include cybersecurity and engaged with EU SMEs in doing so and promoted secure and update strategies in public procurement supply chain initiatives? cooperate with EU solutions across all based on new threats? processes? programmes in order to sectors? achieve them? 9 Have you 1 Have you started 1 Do you ensure regular 1 Have you established 1 Do you lead or co-lead 1 acknowledged the participating in representation in formal mechanisms to initiatives to shape relevance of standards, standardisation and relevant standardisation maintain and contribute international certification certification and certification activities at and certification bodies, to certification schemes and standards policies, secure-by-design the EU or international integrate vulnerability and vulnerability proactively coordinate principles for ICT levels, and initiated information into national assessments, while vulnerability information supply chain security coordination efforts supply chain risk supporting sharing between and begun identifying among market processes and promote multistakeholder stakeholders or foster relevant forums and surveillance, industry open standards and collaboration to apply innovation in secure-bystakeholders? and researchers on secure-by-design open standards and design practices, vulnerability practices across ensure coherence with promoting them as a discussions? sectors? EU frameworks? national norm for ICT procurement and supply chain resilience?
- 10 Is there a national 1 Is the directory 1 directory of critical dynamically maintained suppliers used to inform using real-time updates, policy decisions, risk stakeholder inputs and assessments and threat intelligence incident response feeds? coordination? 11 Do you plan or pilot 1 Do you perform 1 Do you have national 1 Do you integrate testing 1 Do you continuously 1 structured testing structured testing (e.g. frameworks that (e.g. stress testing, improve the structured activities (e.g. stress stress testing, regularly conduct sandboxes) into the testing activities (e.g. testing, sandboxes) sandboxes) to validate structured testing procurement, certification stress testing, specifically targeting the resilience and activities (e.g. stress or operational life cycle sandboxes) based on critical sectors or security of supply chain testing, sandboxes) with of critical systems and feedback, simulations, suppliers? and ICT relevant entities and test results into national emerging risks and products/services? document lessons preparedness plans and international learned? supply chain policies? collaboration?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 18 – Protect critical a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 sectors objective in your (formally or informally) defined and documented mechanism to regularly mechanisms in place to NCSS or do you plan intended results, guiding action plan that includes review and assess your ensure that the action to cover it in the next principles, or key specific activities with action plan to ensure that plan is monitored and edition? activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Have initial steps been 1 Has a comprehensive 1 Is global governance 1 Are there any 1 Does the classification 1 taken to establish an inventory and (stakeholders’ roles and established mechanisms framework incorporate inventory and classification of essential responsibilities) clearly to regularly update and emerging data analytics classification system and important entities established to ensure refine the inventory and and technologies to for essential and and critical assets been the consistent classification system, enhance the important entities and completed to identify application of protective ensuring that it stays understanding and critical assets in line those that have a measures across aligned with national protection of essential with Annexes I and II significant impact on essential and important security needs and and important entities to NIS2 (e.g. national security and entities and high-priority priorities? and critical assets? identifying additional public safety? assets? sectors and defining classification or setting up a registration mechanism)? 2 Have you started the 1 Are there collaborative 1 Are these collaborative 1 Is there regular 1 Do these collaborative 1 creation of mechanisms in place, platforms operational, evaluation and structures employ collaborative platforms such as PPPs and with active participation improvement of these advanced between competent working groups on from both competent collaborative communication tools authorities and private critical information authorities and private mechanisms to ensure and strategies to sector operators, infrastructure protection, entities to enhance that they effectively proactively manage laying the foundation to engage stakeholders? security efforts within address the shared risks, leveraging realfor formal essential and important security needs of time data and insights cooperation? entities? essential and important for increased resilience? entities?
- 3 Have you identified 1 Have sector-specific 1 Have sector-specific 1 Are sector-specific 1 Do you use foresight 1 the unique security policies and guidelines security policies, security policies and methodologies such as needs of essential and been developed to baselines and guidelines baselines regularly predictive analytics and important entities as ensure the availability, been implemented reviewed and updated to threat intelligence to defined in Annexes I integrity and across essential and address evolving regularly update sectorand II to NIS2? confidentiality of services important entities, with cybersecurity needs and specific security policies, in essential and monitoring and risks? anticipating emerging important entities? governance in place? risks and technological changes? 4 Is there informal or 0 Have specific action 0 Are protective measures 0 Are cross-sector 0 Are comprehensive 0 official recognition plans been established for undersea collaboration frameworks strategies in place that within your NCSS of to address the communications cables in place (e.g. involving leverage global insights the importance of cybersecurity needs of implemented and digital infrastructure, and best practices to protecting undersea undersea integrated into broader transport and public continuously adapt and communications communications cables, digital resilience administration) to support enhance cybersecurity cables as critical in line with sector- strategies? regular reviews of and measures for the public components of global specific guidelines? joint efforts to protect core of the internet, digital infrastructure undersea particularly undersea and connectivity? communications cables communications cables? as essential components of global connectivity? 5 Has the protection of 1 Have specific measures 1 Are comprehensive 1 Are performance 1 Are predictive analytics 1 foundational internet been established to protective measures for monitoring mechanisms and collaborative infrastructure (e.g. the protect foundational foundational in place to regularly platforms used to domain name system, internet infrastructure infrastructure elements assess and update dynamically refine border gateway through coordinated developed and protection strategies for protection measures for protocol routing, efforts involving relevant systematically foundational internet foundational internet internet exchange sectors and cross-border implemented across infrastructure? infrastructure, fostering points and time cooperation? relevant sectors, proactive resilience synchronisation supported by strategies against services) been governance frameworks emerging threats? incorporated into the coordinating NCSS? cybersecurity and physical resilience efforts?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 19 – Establish a a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 Coordinated objective in your (formally or informally) defined and documented mechanism to regularly mechanisms in place to Vulnerability NCSS or do you plan intended results, guiding action plan that includes review and assess your ensure that the action Disclosure (CVD) to cover it in the next principles, or key specific activities with action plan to ensure that plan is monitored and policy edition? activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Have you taken the 1 Does your national CVD 1 Does your national CVD 1 Has your national CVD 1 Are processes in place 1 first steps to establish approach designate a policy include a implementation included to adapt the national a national CVD policy coordinating authority structured process for awareness campaigns to CVD policy to emerging and supporting (e.g. a CSIRT) and reporting vulnerabilities, reach NIS2 entities threats and legislative framework? establish its role and provide mechanisms for and/or incentives to changes? responsibilities as disclosure (including foster collaboration regards vulnerability anonymous options) and among stakeholders and reports? specify timelines for researchers? response and remediation that balance urgency, transparency and cybersecurity? 2 Do you recognise the 1 Have you published 1 Does your national CVD 1 Do you regularly review 1 Are there processes in 1 need to adopt guidelines for policy include provisions and improve protective place to predict and protective measures to cybersecurity for limited liability or measures or guidelines address upcoming legal prevent the researchers, including ‘safe harbour’ for that prevent the implications (stemming prosecution of acceptable and cybersecurity prosecution of from new regulations or cybersecurity unacceptable researchers acting in cybersecurity new technologies) researchers acting in vulnerability discovery good faith? researchers in order to affecting cybersecurity good faith? methods? optimise their researchers and CVD effectiveness? policies? 3 Have you identified 1 Do you provide 1 Have you adopted tools 1 Have you implemented 1 Do you regularly monitor 1 suitable technical tools guidelines for submitting (e.g. dedicated secure feedback mechanisms to the latest technology for secure and trusted vulnerability reports in a portals, validation improve the advancements and trusted and secure way systems) to facilitate cybersecurity and assess how they could
- handling of (e.g. through a specific trusted and secure reliability of tools used for contribute to improving vulnerability reports? portal)? vulnerability disclosure handling vulnerability your CVD tools and with adequate reports? processes? anonymity and data protection mechanisms? 4 Have you framed 1 Do you promote the 1 Do you offer incentives 1 Do you promote CVD 1 Have you participated in 1 general conditions to adoption of CVD policies (e.g. financial rewards, practices among public international or EU-level promote safe and or bug bounty recognition) to and private researchers initiatives to encourage responsible programmes by essential encourage cybersecurity with the support of cybersecurity vulnerability research? and important entities? researchers to research programmes researchers to engage participate in CVD (e.g. Horizon Europe, the in CVD programmes activities? digital Europe (e.g. the European programme)? Commission’s free and open-source software auditing project)? 5 Are you planning to 1 Do you encourage 1 Does your competent 1 Does your competent 1 Do you actively support 1 actively consult with private sector entities authority or team (e.g. authority or team (e.g. or lead a broader the European (e.g. suppliers of network your CSIRT) actively your CSIRT) actively dialogue in EU and Vulnerability and information systems contribute to the cooperate with other international forums Database? or manufacturers) and European Vulnerability Member States’ (e.g. the CSIRTs cybersecurity Database? competent authorities or Network, the NIS2 researchers to share teams on CVD through Cooperation Group) on information in the official EU channels (e.g. vulnerability handling European Vulnerability the CSIRTs Network)? and management good Database? practices and/or share and improve protective measures for cybersecurity researchers?
- NCSS objective # Level 1 R Level 2 R Level 3 R Level 4 R Level 5 R
- 20 – Promote active a Do you cover the 1 Have you defined 1 Do you have a formally 1 Do you have a formal 1 Do you have 1 cyber protection objective in your (formally or informally) defined and documented mechanism to regularly mechanisms in place to NCSS or do you plan intended results, guiding action plan that includes review and assess your ensure that the action to cover it in the next principles, or key specific activities with action plan to ensure that plan is monitored and edition? activities in your action clear goals, timelines, it is correctly prioritized dynamically adapted to plan that contribute to and allocated and optimized, including evolving technological, achieving the objective in resources? progress tracking, geopolitical and threat an uncoordinated way? performance evaluation, landscapes? and identification of areas for improvement? 1 Are there unofficial or 1 Have you identified key 1 Have ACP policies been 1 Are ACP policies 1 Are ACP policies 1 formal efforts to stakeholders from the adopted under your regularly evaluated and continuously updated to promote ACP as part public and private NCSS and integrated optimised to ensure address emerging of a broader defensive sectors and civil society into a broader national alignment with a broader threats and strategy? to be involved in or defensive strategy? national defensive cybersecurity trends and benefit from ACP under strategy? integrated into the your NCSS? broader national defensive strategy? 2 Do you recognise the 1 Do you have any policy 1 Have you established 1 Do your sectoral SOCs 1 Do you promote threat 1 need for sectoral on establishing sectoral operational sectoral actively exchange threat information sharing and security operations SOC to support entities SOCs with clear roles intelligence information good practice sharing centres (SOCs) to across your country? and responsibilities and with other national between SOCs, enhance threat secure communication stakeholders (e.g. enabling cross-sector detection and incident channels for sharing national CSIRTs) to and cross-border response capabilities threat intelligence improve awareness and collaboration? across critical sectors among essential and incident response? in your country? important entities? 3 Do key public 1 Are safeguards in place 1 Are real-time 1 Is information sharing 1 Are analytics and 1 administration entities to support informed and detection/monitoring tailored to the cyber detections dynamically implement basic responsible capabilities (e.g. posture and the size/type adjusted using monitoring/alerting implementation and use intrusion detection of stakeholders (e.g. intelligence-driven capabilities (e.g. logs, of ACP? systems, security SMEs, large entities, models and continuous basic intrusion information and event public administration purple-team exercises to management, SOCs) entities) to ensure proactively anticipate
- detection systems) for operational across relevance and avoid and respond to critical networks? critical sectors, information overload? emerging cyber threats? supported by clear incident response playbooks? 4 Are there awareness- 1 Have you identified 1 Is there a national 1 Are mechanisms in place 1 Is there a mechanism for 1 raising initiatives to target entities to offer programme for to ensure that ACP tools continuously integrating inform stakeholders free ACP tools and identifying, acquiring, and services are novel or emerging ACP about the benefits and services (e.g. self- customising and regularly updated and tools and services, use of ACP tools and service checks, detection operating ACP tools and optimised in response to including enhanced services? tools, takedown services and making operational feedback? threat intelligence services)? them available to sharing, into routine relevant stakeholders? cybersecurity operations across sectors? 5 Are formal or informal 1 Are formal mechanisms 1 Is a national threat 1 Are threat intelligence 1 Have national initiatives 1 procedures and being developed or intelligence platform sharing procedures and been launched to foster communication piloted to support (e.g. an MISP or arrangements regularly communities of trust channels (e.g. mailing structured and trusted OpenCTI platform) assessed, updated and among stakeholders and lists, ad hoc alerts) in threat intelligence operational and used by optimised based on to promote voluntary, place to facilitate exchange among key stakeholders to stakeholder feedback secure and optionally threat intelligence stakeholders? enable unified and and operational needs? anonymous threat sharing among public structured information intelligence sharing (e.g. and private sharing? anonymous sharing stakeholders? platforms)?