v1.1.0 · Open source, CC BY 4.0 · Built for the EU
Build and mature your Cyber Defence Center
A free, practitioner-written framework for Security Operations Centers and Cyber Defence Centers in the European Union. It sits between the standards and your organisation: NIST CSF 2.0 says what the security areas are, NIS2 says what you are obliged to do, and this framework says how to build and run the CDC that gets it done.
- No account
- Tools run in your browser
- Plain documents you own
6CSF functions
4Maturity levels
27National annexes
3Browser tools
What you get
Not just pages read once — working through OCDF produces a stack of concrete artefacts you take into your own documentation system and governance process:
Design
- CDC charter — mandate, scope and containment authority, signed before anything is bought. Template
- Target operating model — in-house, MSSP, hybrid or shared, with the staffing arithmetic behind it. Operating models
- Regulatory applicability profile — which of NIS2, GDPR, DORA, CRA and CER actually apply to you, and your national annex. Regulatory profile selector
Build
- Capability baseline — where you stand today, function by function, with evidence behind every score. Maturity self-assessment
- 90-day action plan — every gap with an owner and a due date. Start here
- Detection portfolio — use cases prioritised by your own threat profile, not a generic checklist. Detection-as-code
Run
- Annual operating calendar — the recurring work that keeps a CDC from decaying after go-live. Template
- Evidence register — what backs every maturity score, exportable as a spreadsheet for board reporting. Maturity self-assessment
The framework in one picture
Every capability in OCDF is described in three ways:
What6 functionsCover all six
How muchE · S · A tierYou choose
How wellL1–L4 maturityScored against set criteria
↺ Lessons learned in RECOVER feed the next round of IDENTIFY
Seen through the CIA triad and the regulatory layer (NIS2, GDPR, DORA, CRA, CER and 27 national annexes) · sized by tier (E · S · A) · scored by level (1–4) and recorded in an evidence register · built in the order people › process › technology.
Every function has the same parts: capabilities with IDs such as DE-2,
maturity criteria per level, EU regulatory hooks, and a table of the other
departments it depends on. OCDF on one page explains all
the terms in five minutes.
See OCDF in action
A fictional 2,500-person parcel company goes from fragmented security work to a structured, evidenced CDC: tier decision, operating model, signed charter, first 90 days with owners, a ten-detection portfolio and the first board report. Every step is in the worked example.
- 2,500 employees
- 14 sites, night operations
- NIS2 important entity
- Standard tier
- Hybrid operating model
Before
- Fragmented responsibilities
- No clear containment authority
- Reactive detection
- Undefined regulatory ownership
After
- Defined mandate and charter
- Chosen operating model
- Capability baseline and 90-day plan
- Maturity targets and evidence
Maturity after 12 weeks Level now Target
Where are you coming from?
-
CISO or executive
The 30-minute version: why a CDC, what NIS2 asks of management, staffing and cost drivers, what you can and cannot outsource, and the questions to ask your SOC.
-
SOC or CDC manager
Build and mature the function: the first 90 days in order, the operating model decision, the templates, and a maturity assessment that turns into an action plan.
-
Analyst or engineer
The operational detail: detection, detection-as-code, the CTI capability and the IR playbooks.
-
Compliance or legal
NIS2, GDPR, DORA, CRA and CER mapped to CDC capabilities, national annexes for all 27 member states, and a selector that shows only the laws that apply to you.
Start building
Seven steps, each with the page or tool that does it. See them carried out for a fictional 2,500-person organisation in the worked example.
Design
- Choose your tier. Essential, Standard or Advanced decides how much of the framework applies to you. Implementation tiers Output: target tier
- Run the design workshops. Six workshops, one per function, surface your gaps and the decisions nobody has taken yet. Design navigator Output: design gaps logged as backlog items
- Adopt the charter. Mandate, scope and containment authority, signed before anything is bought. CDC charter Output: signed charter
- Decide the operating model. In-house, provider or hybrid, with the staffing arithmetic and a cost template. Operating models Output: target operating model and staffing numbers
Build
- Assess where you are. Score the maturity criteria and give every gap an owner and a due date. Maturity self-assessment Output: scored baseline and an owned action plan
- Work the first 90 days. The order of work, week by week, with exit criteria. Start here Output: day-90 exit criteria met
Run
- Set the operating rhythm. The recurring work that keeps a CDC from decaying, and a detection portfolio that grows from your threat profile. Annual calendar · Detection use case Output: annual calendar and a growing detection portfolio
The templates are plain documents to copy and adapt. The three browser tools run entirely in your browser: nothing you enter is sent anywhere. The whole framework is on GitHub under CC BY 4.0, also as a zip download.