The National Capabilities Assessment Framework 2.0 (NCAF 2.0) is a key EU instrument designed by ENISA to support Member States in assessing and strengthening their national cybersecurity capabilities. As a voluntary, flexible, and adaptable tool, it provides a structured methodology to evaluate maturity across 20 strategic objectives, enabling policymakers to identify gaps, set priorities, and drive evidence-based policymaking. NCAF 2.0 is fully aligned with the NIS2 Directive, serving as a practical support for the development and implementation of National Cybersecurity Strategies and preparation for Article 19 peer reviews. Based on Member States’ best practices and real-world implementation experiences, the NCAF 2.0 provides a structured assessment that enhances the collective cybersecurity posture of the Union, supporting the shared mission to build a resilient and digitally secure Europe
What are the benefits
What we evaluate
Cluster #1
This cluster assesses the capacity of Member States to raise awareness of cybersecurity risks and threats and to strengthen cyber-resilience and hygiene. It also evaluates their ability to continuously develop cybersecurity capabilities and enhance the overall level of knowledge and skills within this domain. Furthermore, it addresses improvements in incident preparedness and response as well as advancements in cybersecurity R&D.
Cluster #2
This cluster evaluates cooperation and information sharing between different stakeholders at both the national and international level (including as part of mutual assistance processes), recognising it as an important tool for better understanding and responding to a constantly changing threat environment. It also assesses the capacity of Member States to address and counter the cybercriminal activities.
Cluster #3
This cluster measures the capacity of Member States to establish effective governance and good practices in the cybersecurity domain. It considers various aspects of national cybersecurity governance, risk assessment and management, while supporting the development of crisis management and incident reporting mechanisms, and fostering trust in public services and digital identities.
Cluster #4
This cluster measures the capacity of Member States to establish the necessary regulatory and policy instruments to improve supply chain cybersecurity, promote active cyber protection, and to safeguard critical information infrastructure. It also assesses their capacity to create a policy framework for Coordinated Vulnerability Disclosure or a regulatory framework that balances security with privacy.
National Capabilities Assessment Framework 2.0
This report represents an updated version of ENISA's national capabilities assessment framework (NCAF). The framework aims to help Member States undertake a self-assessment of their level of maturity by assessing their National Cybersecurity Strategies objectives. This will help them enhance and build cybersecurity capabilities at both the strategic and the operational levels, thereby strengthening the collective cybersecurity posture across the EU.
-
Published
-
April 22, 2026
-
Language
-
English