Skip to content

v1.1.0 · Open source, CC BY 4.0 · Built for the EU

Build and mature your Cyber Defence Center

A free, practitioner-written framework for Security Operations Centers and Cyber Defence Centers in the European Union. It sits between the standards and your organisation: NIST CSF 2.0 says what the security areas are, NIS2 says what you are obliged to do, and this framework says how to build and run the CDC that gets it done.

  • No account
  • Tools run in your browser
  • Plain documents you own

6CSF functions

4Maturity levels

27National annexes

3Browser tools

What you get

Not just pages read once — working through OCDF produces a stack of concrete artefacts you take into your own documentation system and governance process:

Design

  • CDC charter — mandate, scope and containment authority, signed before anything is bought. Template
  • Target operating model — in-house, MSSP, hybrid or shared, with the staffing arithmetic behind it. Operating models
  • Regulatory applicability profile — which of NIS2, GDPR, DORA, CRA and CER actually apply to you, and your national annex. Regulatory profile selector

Build

  • Capability baseline — where you stand today, function by function, with evidence behind every score. Maturity self-assessment
  • 90-day action plan — every gap with an owner and a due date. Start here
  • Detection portfolio — use cases prioritised by your own threat profile, not a generic checklist. Detection-as-code

Run

  • Annual operating calendar — the recurring work that keeps a CDC from decaying after go-live. Template
  • Evidence register — what backs every maturity score, exportable as a spreadsheet for board reporting. Maturity self-assessment

The framework in one picture

Every capability in OCDF is described in three ways:

What6 functionsCover all six

How muchE · S · A tierYou choose

How wellL1–L4 maturityScored against set criteria

↺ Lessons learned in RECOVER feed the next round of IDENTIFY

Seen through the CIA triad and the regulatory layer (NIS2, GDPR, DORA, CRA, CER and 27 national annexes) · sized by tier (E · S · A) · scored by level (1–4) and recorded in an evidence register · built in the order people › process › technology.

Every function has the same parts: capabilities with IDs such as DE-2, maturity criteria per level, EU regulatory hooks, and a table of the other departments it depends on. OCDF on one page explains all the terms in five minutes.

See OCDF in action

A fictional 2,500-person parcel company goes from fragmented security work to a structured, evidenced CDC: tier decision, operating model, signed charter, first 90 days with owners, a ten-detection portfolio and the first board report. Every step is in the worked example.

  • 2,500 employees
  • 14 sites, night operations
  • NIS2 important entity
  • Standard tier
  • Hybrid operating model

Before

  • Fragmented responsibilities
  • No clear containment authority
  • Reactive detection
  • Undefined regulatory ownership

After

  • Defined mandate and charter
  • Chosen operating model
  • Capability baseline and 90-day plan
  • Maturity targets and evidence

Explore the worked example →

Where are you coming from?

  • CISO or executive


    The 30-minute version: why a CDC, what NIS2 asks of management, staffing and cost drivers, what you can and cannot outsource, and the questions to ask your SOC.

    Executive guide →

  • SOC or CDC manager


    Build and mature the function: the first 90 days in order, the operating model decision, the templates, and a maturity assessment that turns into an action plan.

    Start building →

  • Analyst or engineer


    The operational detail: detection, detection-as-code, the CTI capability and the IR playbooks.

    Running the CDC →

  • Compliance or legal


    NIS2, GDPR, DORA, CRA and CER mapped to CDC capabilities, national annexes for all 27 member states, and a selector that shows only the laws that apply to you.

    EU regulatory landscape →

Start building

Seven steps, each with the page or tool that does it. See them carried out for a fictional 2,500-person organisation in the worked example.

Design

  1. Choose your tier. Essential, Standard or Advanced decides how much of the framework applies to you. Implementation tiers Output: target tier
  2. Run the design workshops. Six workshops, one per function, surface your gaps and the decisions nobody has taken yet. Design navigator Output: design gaps logged as backlog items
  3. Adopt the charter. Mandate, scope and containment authority, signed before anything is bought. CDC charter Output: signed charter
  4. Decide the operating model. In-house, provider or hybrid, with the staffing arithmetic and a cost template. Operating models Output: target operating model and staffing numbers

Build

  1. Assess where you are. Score the maturity criteria and give every gap an owner and a due date. Maturity self-assessment Output: scored baseline and an owned action plan
  2. Work the first 90 days. The order of work, week by week, with exit criteria. Start here Output: day-90 exit criteria met

Run

  1. Set the operating rhythm. The recurring work that keeps a CDC from decaying, and a detection portfolio that grows from your threat profile. Annual calendar · Detection use case Output: annual calendar and a growing detection portfolio

The templates are plain documents to copy and adapt. The three browser tools run entirely in your browser: nothing you enter is sent anywhere. The whole framework is on GitHub under CC BY 4.0, also as a zip download.

Version 1.1.0, released 23 September 2026 (changelog) · maintained by Frederik B. Krogsgaard, former Senior Manager at the Norlys Cyber Defence Center. An independent, practitioner-led project. Each national annex states when it was last reviewed and how confident that review is; see why you can, and cannot, rely on this framework.

Scope: enterprise IT — endpoints, servers, identity, cloud and SaaS. Not designed for OT/ICS, telco core networks or classified environments (why); running critical infrastructure, see the IT/OT boundary (an OT profile is on the roadmap). Orientation only, not legal advice.