How CCDL1 and CCDL2 Align with the NICE Framework

CCDL1 lines up most closely with the NICE Framework's Defensive Cybersecurity and Incident Response work roles, the core of SOC analyst work. CCDL2 lines up most closely with Incident Response and Digital Forensics, and covers 82.1% of the Incident Response role.
We checked the live content of both courses against every task, knowledge and skill statement NICE lists for four work roles. Here is what we found, how we scored it, and what it means if you are hiring or building a career in a SOC.
Quick answer
| NICE work role | CCDL1 | CCDL2 |
|---|---|---|
| Defensive Cybersecurity (PD-WRL-001) | 64.4% | 76.8% |
| Incident Response (PD-WRL-003) | 71.2% | 82.1% |
| Digital Forensics (PD-WRL-002) | 70.7% | 77.9% |
| Digital Evidence Analysis (IN-WRL-002) | 70.1% | 76.1% |
Primary fit: CCDL1 for Defensive Cybersecurity and Incident Response; CCDL2 for Incident Response and Digital Forensics.
Coverage means the share of a role's official NICE task, knowledge and skill statements that the live course content covers, with partial coverage counted as half.
What is the NICE Framework?
The NICE Framework is the US government's common language for cybersecurity jobs. It is run by the National Initiative for Cybersecurity Education (NICE) at NIST, and published as NIST SP 800-181.
It breaks cybersecurity work into work roles, such as Incident Response or Digital Forensics. Each role comes with a list of:
- Tasks: the work the person actually does, like "perform cyber defense incident triage."
- Knowledge statements: what they need to understand, like "knowledge of intrusion detection tools and techniques."
- Skills: what they need to be able to do, like "skill in performing log file analysis."
Together these are called TKS statements. The current version is v2.2.0, released by NIST on April 28, 2026.
Why it matters when you hire or get hired
US federal agencies, defense contractors and a growing number of private employers write job descriptions around NICE work roles. The US Department of Defense also builds its own workforce framework on the same foundation. So when a training program maps cleanly to a NICE role, a hiring manager can see quickly what a candidate has practiced.
One naming note: NICE renamed its roles in 2024 to describe the function, not the job title. The role many people still call "Cyber Defense Analyst" is now Defensive Cybersecurity (PD-WRL-001). The DoD still uses "Cyber Defense Analyst (511)" for the same work, as SANS notes.
How we mapped CCDL1 and CCDL2 to NICE
We did not stop at "this course is about incident response, so it fits." We went line by line.
- We reviewed the live courses. We used the current published versions as of October 4, 2026: CCDL1 V2 and CCDL2 V1. We read the actual lesson and lab text, not just syllabus headings, and left out draft content.
- We picked four work roles. Defensive Cybersecurity and Incident Response describe core SOC and response work. Digital Forensics covers incident-focused forensic work. Digital Evidence Analysis adds broader evidence-handling, legal and laboratory duties. We also screened Threat Analysis, Vulnerability Analysis and Cybercrime Investigation, but did not score them.
- We pulled every official statement for each role from NIST's NICE Framework v2.2.0 data: 205 for Defensive Cybersecurity, 106 for Incident Response, 181 for Digital Forensics and 174 for Digital Evidence Analysis.
- We scored each one. Covered (1 point) means specific course instruction or an exercise directly addresses the statement. Partially covered (half a point) means only a narrower part or an introductory treatment. Not covered (0) means the published course text does not show enough evidence. A passing mention, or a tool's capabilities alone, does not earn credit.
- We added it up. Coverage = (covered + 0.5 x partially covered) / all official statements for the role. Each statement counts once and equally.
Each role is scored on its own, so the percentages should not be added into one NICE score. Roles share many statements, so a course can score well on a role it is not built for; percentages alone do not decide which role a course fits. These percentages describe documented course content. They are not exam coverage, learner proficiency, job readiness or a DoD 8140 qualification, and NIST has not reviewed or approved them.
What neither course covers sits mostly outside a technical course: systems and software engineering, enterprise architecture, hardware reverse engineering, and courtroom work such as preparing materials for legal proceedings or acting as a liaison to prosecutors.
CCDL1: built for the SOC analyst role
CCDL1's primary fit is Defensive Cybersecurity (64.4%) and Incident Response (71.2%), the two NICE roles closest to day-to-day SOC analyst work: watching alerts, deciding what is real, containing it and handing it over cleanly.
The course has six modules: phishing and email security, network and endpoint detection (including Active Directory), SIEM with Splunk, DFIR, cloud security in Azure, and a SOC decision method that takes an alert from triage to handover.
NICE tasks CCDL1 covers
- Validate intrusion detection system alerts (T1387) and construct network tool signatures (T1406), in the IDS rule labs
- Distinguish between benign and potentially malicious activity (T1348), in the Azure sign-in triage lab
- Perform cyber defense incident triage (T1250) and determine its scope, urgency and impact (T1252)
- Escalate incidents (T1242) and produce incident findings reports (T1332), in the SOC Decision Method module
- Perform forensically sound image collection (T1256)
Where CCDL1 scores highest
Skills are CCDL1's strongest area. It covers 80.3% of the Defensive Cybersecurity skills list and 78.3% of the Incident Response skills list, such as packet analysis, log analysis, event correlation and detecting intrusions.
CCDL1 also scores 70.7% on Digital Forensics and 70.1% on Digital Evidence Analysis, through its DFIR module on evidence acquisition, registry, file system, memory and timeline analysis. That is a strong foundation, but these are secondary fits. CCDL2 is where forensics becomes a main focus.
CCDL2: built for incident response and digital forensics
CCDL2's primary fit is Incident Response (82.1%) and Digital Forensics (77.9%). It also covers 76.8% of Defensive Cybersecurity and 76.1% of Digital Evidence Analysis as secondary fits.
The live course has eleven subject modules: SOC fundamentals, incident response, email perimeter defense, evidence collection, disk forensics, memory forensics, network forensics, threat hunting, malware analysis, Active Directory attack and defense, and an advanced threat scenario. The exam is a 48-hour practical in a browser-based lab.
NICE tasks CCDL2 covers
- Track and document incidents from first detection to final resolution (T1315, T1316)
- Produce incident findings reports (T1332) and prepare after action reviews (T1485)
- Create forensically sound duplicates of evidence (T1120) and prepare media for imaging (T1282)
- Perform Windows registry analysis (T0397) and mount a drive image (T1382)
- Perform file and registry monitoring on running systems (T1487), in dynamic malware analysis
- Construct cyber defense network tool signatures (T1406), with custom Suricata rules
Where CCDL2 scores highest
CCDL2 covers 89.7% of the Incident Response task list and 89.1% of its skills. Its skills coverage is also high for Defensive Cybersecurity (90.8%) and Digital Evidence Analysis (90.0%).
CCDL2 also overlaps with Threat Analysis through intelligence-driven threat hunting. That role is mostly intelligence planning, collection and briefing work, which is a different job, so we screened it rather than scoring it.
CCDL1 vs CCDL2 at a glance
| NICE work role | CCDL1 | CCDL2 |
|---|---|---|
| Incident Response (PD-WRL-003) | 71.2% | 82.1% |
| Digital Forensics (PD-WRL-002) | 70.7% | 77.9% |
| Defensive Cybersecurity (PD-WRL-001) | 64.4% | 76.8% |
| Digital Evidence Analysis (IN-WRL-002) | 70.1% | 76.1% |
Source: CyberDefenders mapping of live CCDL1 V2 and CCDL2 V1 content against NICE Framework v2.2.0, 666 TKS statements, October 4, 2026. Partial coverage counts as half.
CCDL2 covers more of every role. The biggest jumps are in Defensive Cybersecurity (+12.4 points) and Incident Response (+10.9 points). CCDL1 is the entry point; CCDL2 adds the depth for investigation and forensics work.
How employers can use this mapping
If you hire for SOC or incident response roles, the mapping gives you a shortcut from a NICE-based job description to a credential you can ask for.
- Writing a job post for a SOC analyst? List "CCDL1 or equivalent" next to the Defensive Cybersecurity (PD-WRL-001) and Incident Response (PD-WRL-003) duties.
- Hiring an incident responder or forensic analyst? List CCDL2 against the Incident Response (PD-WRL-003) and Digital Forensics (PD-WRL-002) duties.
- Building a training plan for your team? Use the coverage numbers to see which NICE statements the course handles and which ones need other training.
- Working with US government or defense clients? Map your staff's training to the NICE roles your contract names. Both certifications are listed in the NICCS training catalog run by CISA.
Frequently asked questions
Is CCDL1 aligned with the NICE Framework?
Yes. CCDL1 aligns most closely with the NICE Defensive Cybersecurity (PD-WRL-001) and Incident Response (PD-WRL-003) work roles, covering 64.4% and 71.2% of their official task, knowledge and skill statements.
Which NICE work roles does CCDL2 map to?
CCDL2 maps mainly to Incident Response (PD-WRL-003), with 82.1% coverage, and Digital Forensics (PD-WRL-002), with 77.9% coverage. It also covers 76.8% of Defensive Cybersecurity and 76.1% of Digital Evidence Analysis.
Why does CCDL1 score higher on Digital Forensics than on Defensive Cybersecurity?
The roles differ in size and content. Defensive Cybersecurity has 124 knowledge statements, many of them on topics such as architecture, engineering and law that sit outside a SOC course. A percentage shows how much of a role's list the course covers, not which job the course is built for.
Is "Cyber Defense Analyst" the same as Defensive Cybersecurity?
Yes, they describe the same work. NICE renamed its roles in 2024, and "Cyber Defense Analyst" became Defensive Cybersecurity (PD-WRL-001). The US Department of Defense still uses Cyber Defense Analyst, role 511.
Does NIST approve or certify training courses?
No. NIST publishes the NICE Framework but does not approve or endorse certifications. "Aligned with NICE" means a course has been mapped against the framework's published roles and statements, as we did here.
Should I take CCDL1 or CCDL2 first?
Start with CCDL1 if you are new to SOC work or moving into a Tier 1 or Tier 2 analyst job. Go to CCDL2 when you want to lead investigations, run forensics or hunt threats.
Can I see the full mapping?
Yes. The full mapping lists every NICE statement, its score for each course, the lesson or lab that supports it and the reasoning. Ask for a copy using the link below.
Train for the role, not just the badge
CCDL1 and CCDL2 are built around the work SOC analysts, incident responders and forensic analysts do every day, and the NICE mapping shows it statement by statement.
- For analysts: Start CCDL1 to build SOC skills, or move up to CCDL2 to lead investigations.
- For security teams: Talk to us about enterprise training mapped to the NICE roles you hire for, and request the full mapping file.
For teams that hire in Europe as well, read our companion article on how CCDL1 and CCDL2 align with the ENISA European Cybersecurity Skills Framework (ECSF).