How CCDL1 and CCDL2 Align with ENISA's European Cybersecurity Skills Framework (ECSF)

CT
CyberDefenders Team
Share this post:
How CCDL1 and CCDL2 align with the ENISA ECSF: Cyber Incident Responder, Digital Forensics Investigator and Cyber Threat Intelligence Specialist profiles

CCDL1 and CCDL2 both map most strongly to two ECSF role profiles: Cyber Incident Responder and Digital Forensics Investigator. CCDL1 covers 81.6% of the Cyber Incident Responder profile, the one ENISA itself also calls SOC Analyst. CCDL2 raises that to 89.5% and adds much stronger coverage of threat intelligence work.

We scored the live content of both courses against every key skill and key knowledge item in three ECSF profiles. Here is what we found and what it means for teams hiring in Europe.

Quick answer

ECSF role profile CCDL1 CCDL2 Fit
Cyber Incident Responder 81.6% 89.5% Primary
Digital Forensics Investigator 77.8% 77.8% Primary
Cyber Threat Intelligence Specialist 60.9% 78.3% Adjacent for CCDL1, secondary for CCDL2

Coverage means the share of a profile's key skills and key knowledge items that the course content covers, with partial coverage counted as half.

What is the ECSF?

The European Cybersecurity Skills Framework (ECSF) is the EU's shared description of cybersecurity jobs. ENISA, the EU Agency for Cybersecurity, presented it in September 2022 as "an open European tool to establish a common understanding of cybersecurity professional role profiles."

The ECSF defines 12 role profiles, from Chief Information Security Officer to Penetration Tester. Each profile lists:

  • Main tasks: what the person is responsible for.
  • Key skills: what they must be able to do.
  • Key knowledge: what they must understand.

Why it matters now: NIS2

The NIS2 Directive puts cybersecurity duties on essential and important organisations across the EU, including detecting, handling and reporting incidents. In June 2025, ENISA published a guide that maps NIS2 obligations to ECSF role profiles.

That guide gives the Cyber Incident Responder the job of identifying and analysing security events and preparing the incident reports NIS2 requires. It also names the Digital Forensics Investigator and Cyber Threat Intelligence Specialist for incident reporting work. Those are the three profiles where CCDL1 and CCDL2 line up.

How we mapped CCDL1 and CCDL2 to the ECSF

  1. We reviewed the live courses. We used the current published versions as of October 4, 2026: CCDL1 V2, with six modules and 42 labs, and CCDL2 V1, with eleven subject modules, nearly 400 lessons and 41 labs.
  2. We chose three ECSF profiles. Cyber Incident Responder and Digital Forensics Investigator are the main matches. Cyber Threat Intelligence Specialist is a secondary match. We screened the other nine profiles but did not score them, because they describe different work such as governance, architecture or penetration testing.
  3. We listed every key skill and key knowledge item from ENISA's ECSF Role Profiles: 19 for Cyber Incident Responder, 18 for Digital Forensics Investigator and 23 for Cyber Threat Intelligence Specialist. The profiles' main tasks were not scored.
  4. We scored each item. Full (1 point) means substantial, explicit instruction. Partial (half a point) means limited depth or only part of the item. Not evidenced (0) means we found no substantive support in the course content. A lesson title or a passing mention does not count as full coverage.
  5. We added it up. Coverage = (full + 0.5 x partial) / total items, for each profile. Every item counts once and equally.

Each profile is scored on its own, so the percentages should not be added into one overall ECSF score. They show how much of each profile the course content covers. They are not learner proficiency or job readiness, and ENISA has not reviewed or approved them.

The items neither course covers sit mostly outside a technical course: knowledge of the cybersecurity certification landscape, criminal investigation procedures, responsible disclosure procedures, and spotting non-cyber events, such as geopolitical events, that have cyber implications.

CCDL1: built for the SOC analyst profile

CCDL1 covers 81.6% of the Cyber Incident Responder profile (15.5 of 19 items). ENISA lists "Security Operation Analyst (SOC Analyst)" as one of this profile's alternative titles, and that is the job CCDL1 trains for.

Its labs cover network, endpoint, Active Directory and Azure investigations, log analysis in Splunk and KQL, alert triage, containment, escalation and handover to the next team. Items it covers fully include:

  • "Collect, analyse and correlate cyber threat information originating from multiple sources," in the SIEM threat hunting labs
  • "Manage and analyse log files," from log collection to correlation in Splunk
  • "Communicate, present and report to relevant stakeholders," in the SOC Decision Method module
  • "Secure Operation Centres (SOCs) operation," through the full triage, escalation, containment and documentation cycle

Digital Forensics Investigator: 77.8%

CCDL1 covers 14 of 18 items. Its DFIR module teaches evidence acquisition, integrity and chain of custody, the NIST SP 800-86 forensic process, registry, file system and memory analysis, and timeline reconstruction. Its phishing module adds malicious document analysis with tools such as oletools.

Cyber Threat Intelligence Specialist: 60.9%

CCDL1 covers 14 of 23 items, an adjacent fit. It teaches ATT&CK and TTP analysis, APT detection scenarios and multi-source correlation. Its focus is using threat intelligence during investigations, not running the full intelligence production lifecycle.

CCDL2: built for incident response, forensics and threat hunting

CCDL2 covers 89.5% of the Cyber Incident Responder profile (17 of 19 items), 77.8% of the Digital Forensics Investigator profile and 78.3% of the Cyber Threat Intelligence Specialist profile.

Cyber Incident Responder: 89.5%

CCDL2 adds the full response side. Its incident response module covers the NIST incident response lifecycle, the IR plan, team roles and responsibilities, containment and recovery, internal and external communication, and detailed incident reports. It fully covers items such as "Incident handling standards, methodologies and frameworks" and "Computer Security Incident Response Teams (CSIRTs) operation."

Digital Forensics Investigator: 77.8%

CCDL2 covers 14 of 18 items through its evidence collection, disk, memory and network forensics, and malware analysis modules. It teaches integrity-preserving acquisition, evidence correlation and reasoned investigation reports. It fully covers "Develop and communicate, detailed and reasoned investigation reports" and "Malware analysis tools."

Cyber Threat Intelligence Specialist: 78.3%

CCDL2 covers 18 of 23 items, a secondary fit. Its threat hunting module teaches intelligence-driven hunting, including an APT29 case, actor and campaign analysis, and technical threat modelling with MITRE ATT&CK. Its malware module adds programming fundamentals through VBA analysis. It fully covers "Identify threat actors TTPs and campaigns" and "Model threats, actors and TTPs."

CCDL1 vs CCDL2 at a glance

ECSF role profile CCDL1 CCDL2
Cyber Incident Responder (also called SOC Analyst) 81.6% 89.5%
Digital Forensics Investigator 77.8% 77.8%
Cyber Threat Intelligence Specialist 60.9% 78.3%

Source: CyberDefenders mapping of live CCDL1 V2 and CCDL2 V1 content against ENISA ECSF role profiles, 60 items, October 4, 2026. Partial coverage counts as half.

CCDL2 scores higher on Cyber Incident Responder and much higher on threat intelligence. Both courses score 77.8% on Digital Forensics Investigator, but for different reasons: CCDL2 goes further on investigation reports, while CCDL1 teaches the NIST SP 800-86 forensic framework explicitly.

How EU employers can use this mapping

If you hire security staff in Europe, the ECSF gives you a shared vocabulary, and this mapping links it to a credential you can name in a job post.

  • Hiring a SOC analyst? Use the ECSF Cyber Incident Responder profile as your role description, and list "CCDL1 or equivalent."
  • Hiring an incident responder or forensic analyst? List CCDL2 against the Cyber Incident Responder and Digital Forensics Investigator profiles.
  • Building a threat hunting team? CCDL2's coverage of the Cyber Threat Intelligence Specialist profile makes it the better fit for intelligence-driven hunting roles.
  • Preparing for NIS2? Use the ENISA NIS2 mapping to see which profiles your obligations need, then use the coverage figures here to plan training.

Frequently asked questions

Which ECSF role profile does CCDL1 match?

CCDL1 matches the Cyber Incident Responder profile, which ENISA also calls Security Operation Analyst (SOC Analyst), with 81.6% coverage. It also covers 77.8% of the Digital Forensics Investigator profile.

Which ECSF profiles does CCDL2 match?

CCDL2 matches the Cyber Incident Responder profile (89.5%) and the Digital Forensics Investigator profile (77.8%). It also covers 78.3% of the Cyber Threat Intelligence Specialist profile.

Why do CCDL1 and CCDL2 have the same Digital Forensics Investigator score?

Each item counts equally, and the two courses earn their points in different places. CCDL2 covers investigation reports more fully, while CCDL1 covers forensic standards more fully through NIST SP 800-86. The total is the same; the strengths are not.

Does ENISA approve or certify training?

No. ENISA publishes the ECSF as a reference, but it does not approve or endorse courses. "Aligned with the ECSF" means a course has been mapped against the published role profiles, as we did here.

How does the ECSF relate to NIS2?

NIS2 sets cybersecurity duties for many EU organisations. ENISA's June 2025 guide links those duties to ECSF role profiles, so teams can see which roles they need. Incident detection and reporting duties map to the Cyber Incident Responder profile.

How is the ECSF different from the NICE Framework?

The NICE Framework is the US equivalent, published by NIST. NICE breaks each role into 100 to 200 detailed statements, while each ECSF profile has about 20 key skills and knowledge items. CCDL1 and CCDL2 map to both.

Can I get the full mapping?

Yes. The full mapping lists every ECSF item, its score for each course, the lesson or lab that supports it and the reasoning. Request it using the link below.

Build a team that matches the profiles you hire for

CCDL1 and CCDL2 train the work behind three ECSF profiles, and the mapping shows it item by item.

Hiring in the US as well? Read our companion article on how CCDL1 and CCDL2 align with the NICE Framework.

Tags:soc trainingDFIRSOC analyststhreat intelligencedigital forensicsincident responseCCDL1CCDL2