v1.1.0 · Open source, CC BY 4.0 · Built for the EU
Build and mature your cyber defence
A free, practitioner-written framework for anyone responsible for detecting and responding to cyber attacks in the European Union, whether you call it a SOC, a Cyber Defence Center, an IT-security team, or it is two people in IT. It sits between the standards and your organisation: NIST CSF 2.0 says what the security areas are, NIS2 says what you are obliged to do, and this framework says how to build and run the function that gets it done. Is this for me?
- No account
- Tools run in your browser
- Plain documents you own
6CSF functions
4Maturity levels
27National annexes
3Browser tools
What you get
Not just pages read once — working through OCDF produces a stack of concrete artefacts you take into your own documentation system and governance process:
Design
- CDC charter — mandate, scope and containment authority, signed before anything is bought. Template
- Target operating model — in-house, MSSP, hybrid or shared, with the staffing arithmetic behind it. Operating models
- Regulatory applicability profile — which of NIS2, GDPR, DORA, CRA and CER actually apply to you, and your national annex. Regulatory profile selector
Build
- Capability baseline — where you stand today, function by function, with evidence behind every score. Maturity self-assessment
- 90-day action plan — every gap with an owner and a due date. Start here
- Detection portfolio — use cases prioritised by your own threat profile, not a generic checklist. Detection-as-code
Run
- Annual operating calendar — the recurring work that keeps a CDC from decaying after go-live. Template
- Evidence register — what backs every maturity score, exportable as a spreadsheet for board reporting. Maturity self-assessment
The framework in one picture
Every capability in OCDF is described in three ways:
What6 functionsCover all six
How muchE · S · A tierYou choose
How wellL1–L4 maturityScored against set criteria
↺ Lessons learned in RECOVER feed the next round of IDENTIFY
Seen through the CIA triad and the regulatory layer (NIS2, GDPR, DORA, CRA, CER and 27 national annexes) · sized by tier (E · S · A) · scored by level (1–4) and recorded in an evidence register · built in the order people › process › technology.
Every function has the same parts: capabilities with IDs such as DE-2,
scored maturity criteria, EU regulatory hooks, and a table of the other
departments it depends on. Level 2 in every function is also the NIS2 floor:
it covers each measure the law requires, as mapped in the
NIS2 Article 21 crosswalk. OCDF on one page explains all
the terms in five minutes.
See OCDF in action
A fictional 2,500-person parcel company goes from fragmented security work to a structured, evidenced CDC: tier decision, operating model, signed charter, first 90 days with owners, a ten-detection portfolio and the first board report. Every step is in the worked example.
- 2,500 employees
- 14 sites, night operations
- NIS2 important entity
- Standard tier
- Hybrid operating model
Before
- Fragmented responsibilities
- No clear containment authority
- Reactive detection
- Undefined regulatory ownership
After
- Defined mandate and charter
- Chosen operating model
- Capability baseline and 90-day plan
- Maturity targets and evidence
Maturity after 12 weeks Level now Target
Is this for me?
If you are responsible for detecting and responding to cyber attacks, yes. You do not need a department called SOC or CDC: in this framework CDC names the function, not the size of the team. Every capability is tagged with the smallest tier that should implement it, so you can see what applies to you now and what can wait.
- 1–3 people doing IT security, often alongside other IT duties. Start with if you are the whole security function and the Essential tier, then the first 90 days, the IR plan template and the regulatory selector. Leave the deep dives for later.
- Building a dedicated security team, in-house, with a provider, or both. Follow the seven steps under Start building, with operating models for the staffing and budget case.
- Maturing an existing SOC or CDC. Begin with the maturity self-assessment, reusing any SOC-CMM, SIM3 or CIS assessment you already have, then running the CDC.
Where are you coming from?
-
IT security in a small team
One to three people, often with other IT duties too. The Essential tier, what to buy rather than build, and the four things you must own yourself.
-
CISO or executive
The 30-minute version: why a CDC, what NIS2 asks of management, staffing and cost drivers, what you can and cannot outsource, and the questions to ask your SOC.
-
SOC or CDC manager
Build and mature the function: the first 90 days in order, the operating model decision, the templates, and a maturity assessment that turns into an action plan.
-
Analyst or engineer
The operational detail: detection, detection-as-code, the CTI capability and the playbook templates.
-
Compliance or legal
NIS2, GDPR, DORA, CRA and CER mapped to CDC capabilities, national annexes for all 27 member states, and a selector that shows only the laws that apply to you.
Start building
Seven steps, each with the page or tool that does it. See them carried out for a fictional 2,500-person organisation in the worked example.
Design
- Choose your tier. Essential, Standard or Advanced decides how much of the framework applies to you. Implementation tiers Output: target tier
- Run the design workshops. Six workshops, one per function, surface your gaps and the decisions nobody has taken yet. Design navigator Output: design gaps logged as backlog items
- Adopt the charter. Mandate, scope and containment authority, signed before anything is bought. CDC charter Output: signed charter
- Decide the operating model. In-house, provider or hybrid, with the staffing arithmetic and a cost template. Operating models Output: target operating model and staffing numbers
Build
- Assess where you are. Score the maturity criteria and give every gap an owner and a due date. Maturity self-assessment Output: scored baseline and an owned action plan
- Work the first 90 days. The order of work, week by week, with exit criteria. Start here Output: day-90 exit criteria met
Run
- Set the operating rhythm. The recurring work that keeps a CDC from decaying, and a detection portfolio that grows from your threat profile. Annual calendar · Detection use case Output: annual calendar and a growing detection portfolio
The templates are plain documents to copy and adapt. The three browser tools run entirely in your browser: nothing you enter is sent anywhere. The whole framework is on GitHub under CC BY 4.0, also as a zip download.