| Measure | Value |
|---|---|
| Organizing units (work roles plus competency areas) | 53 |
| Work roles | 42 |
| Competency areas (second grouping axis, v2.2.0) | 11 |
| Strict elements (numbered statements) | 2,211 |
| Subpoints (parsed enumeration lists) | 14 |
| Examples (Clarification-statement scaffolding) | 0 |
| With-examples elements | 2,225 |
| Elements per organizing unit, strict | 41.7 |
| Elements per organizing unit, with-examples | 42.0 |
| Elements per work role, strict | 44.4 |
| Elements per work role, with-examples | 44.7 |
NICE Framework v2
Workforce Framework for Cybersecurity (NIST SP 800-181r1)
At a glance
| Steward | NIST (National Initiative for Cybersecurity Careers and Studies) |
| Canonical page | NICE Framework Resource Center |
| Version | 2.2.0 |
| Released | 2026-04-28 |
| Source format | NIST Cybersecurity and Privacy Reference Tool (CPRT) JSON export |
| License | A US Government work, not subject to copyright in the United States under 17 U.S.C. 105. NIST reserves foreign rights and grants them back royalty-free worldwide, including derivative works |
framework_summary slug |
nice-v2 |
Structure in cybed: terms
Counts
Two denominators sit in that table and they answer different questions. The cross-framework density chart uses organizing units, which for NICE v2.2.0 means the 42 work roles plus the 11 competency areas. The per-role figures hold the competency areas out of both numerator and denominator. Competency areas are a second grouping axis over the same knowledge and skill catalog rather than an additional set of roles.
NICE’s strict and with-examples counts are identical. The framework encodes detail entirely in numbered statements, so the ingestion has no prose-embedded clarifications or annex examples to lift into separate cybed:Example nodes.
Provenance
Source
NIST’s CPRT JSON export. Retrieval URL and reference checksum live in the package’s provenance.yml.
Ingestion
scripts/010-ingest-nice.R parses the CPRT structure into the cybed schema. Stage the JSON file at data/raw/nice/cprt-export.json per docs/framework-data-sources.md.
License
A work of the United States Government, not subject to copyright in the United States under 17 U.S.C. 105. NIST reserves foreign rights and grants them back, giving the public a non-exclusive, perpetual, paid-up, royalty-free, worldwide right to reprint the work in all formats and in derivative works. Attribute NIST as the source and do not imply NIST endorsement. The package does not bundle the source JSON. Users stage it locally.
Caveats
- DCWF aligns to NICE and shares element identifiers across the two frameworks. Summing element counts across NICE and DCWF will double-count shared identifiers. Filter on
framework_slugwhen summing. - The ingested data reflects the CPRT export retrieved at ingestion time. Re-run the ingestion script against a newer export to pick up subsequent NICE versions.
- A small number of work roles carry a disproportionate share of element coverage. See the top NICE work roles query.