The Relationship Between Cybersecurity and the NICE Framework
Cybersecurity is no longer a career path with a handful of clearly defined jobs. In 2026, professionals can specialize in areas such as cloud security, incident response, offensive AI security, DevSecOps, cryptography, supply chain security, and more. But with new cybersecurity specializations emerging, how do you find out which skills you need and how those skills align with employer requirements?
That’s where the NICE Workforce Framework for Cybersecurity, developed through the National Initiative for Cybersecurity Education (NICE) at the National Institute of Standards and Technology (NIST), becomes valuable. The NICE Framework provides a common language for describing cybersecurity work and the knowledge and skills you need to perform it. And in 2026, recent updates to the framework’s components make it particularly relevant to today’s cybersecurity professionals. But first…
What Is the NICE Framework for Cybersecurity?
The NICE Framework is essentially a workforce framework rather than a technical cybersecurity framework. It doesn’t tell you how to configure a firewall or respond to a ransomware attack. Instead, it helps describe the work cybersecurity professionals perform and the capabilities required to perform that work. At its foundation are Tasks, Knowledge, and Skills (TKS). These building blocks are used to describe Work Roles and Competency Areas.
NIST explains that the framework can support career discovery, education and training, hiring, and career development. It is intended for use by employers, students, job seekers, working professionals, educators, and training providers across public and private sectors.
Think of the NICE framework as a common language that defines what organizations need and what cybersecurity professionals can do.
Why Does the NICE Framework Matter to Cybersecurity Professionals in 2026?
The need for cybersecurity talent remains substantial in the United States. According to NIST’s CyberSeek data released in 2025, employers posted 514,359 cybersecurity job listings during the preceding 12 months, an increase of nearly 57,000 (12%) compared with the previous reporting period. Earlier data also identified a shortage of approximately 265,000 cybersecurity workers needed to meet U.S. workforce demands.
For professionals, these numbers underscore the reality that opportunities exist, but employers need people with the right capabilities, not simply those who can claim “cybersecurity” as a general skill. The NICE framework helps make these capabilities more explicit.
Understanding NICE’s Work Roles, Tasks, Knowledge, and Skills
One common misconception is that a NICE Work Role is simply another name for a job title. It isn’t. NIST defines a Work Role as a grouping of work for which an individual or team is responsible or accountable. A single job can encompass multiple Work Roles, while people with the same job title may perform very different cybersecurity work. The NICE framework connects these concepts through a straightforward structure:
For you as a cybersecurity professional, the above distinction can be extremely useful. Instead of asking “What job title should I pursue?”, ask “What cybersecurity work do I want to perform, and what knowledge and skills do I need to perform it effectively?” It’s a shift that makes your career planning much more strategic.
What's New in the NICE Framework in 2026?
This is where cybersecurity professionals should pay close attention. The underlying NICE Framework structure remains NIST SP 800-181 Rev. 1, published in November 2020. However, NIST maintains the framework’s components separately so they can be updated more frequently.
On April 28, 2026, NIST released NICE Framework Components v2.2.0. The update introduced a new Cybersecurity Supply Chain Risk Management (C-SCRM) Work Role and updated the Cryptography and DevSecOps Competency Areas. These changes are significant because they reflect areas that are increasingly important across modern cybersecurity environments. Let’s look at each one more closely:
1. Cybersecurity Supply Chain Risk Management (C-SCRM)
Organizations increasingly depend on vendors, cloud providers, software suppliers, contractors, and technology ecosystems. The new C-SCRM Work Role (OG-WRL-017) focuses on capabilities to identify, protect against, respond to, and advise others on cybersecurity risks arising from technology supply chains. NIST’s update includes 35 newly drafted Task, Knowledge, and Skill statements for this Work Role.
For professionals, this means supply chain security is becoming more than a niche specialization. Understanding third-party vendor risk, supplier security, technology dependencies, and software supply chain threats can significantly enhance your cybersecurity skill set.
2. Cryptography
Cryptography remains foundational to cybersecurity, from protecting communications and identities to securing sensitive data. The 2026 NICE update specifically expands the Cryptography Competency Area, reinforcing the importance of cryptographic knowledge and skills within the cybersecurity workforce.
Professionals working in cloud security, identity security, application security, data protection, digital forensics, or emerging technologies should therefore consider whether their cryptographic knowledge is sufficient for the work they intend to perform.
3. DevSecOps
Modern organizations increasingly integrate security into software engineering and deployment rather than treating security as a final checkpoint. This security-first approach is known as DevSecOps. The 2026 NICE update also expands the DevSecOps Competency Area, adding new Knowledge and Skill statements.
For cybersecurity professionals, this reinforces the value of understanding secure software development, automation, continuous integration and deployment, security testing, and collaboration between development, operations, and security teams.
The NICE Framework and the Future of Cybersecurity Careers
The biggest takeaway from the 2026 updates is that cybersecurity careers are becoming increasingly skills-based. You don’t necessarily need to fit neatly into one traditional job category.
The NICE Framework provides organizations with a way to describe the capabilities illustrated above. Simultaneously, the framework also provides professionals with a way to identify the knowledge and skills associated with different areas of cybersecurity work.
Important: The NICE framework is not intended to function as a rigid checklist. NIST describes it as a reference that organizations can adapt to their own workforce, education, training, and career-development needs.
How to Use the NICE Framework for Your Cybersecurity Career
You can turn the framework into a practical career-development tool. Start by identifying the cybersecurity Work Role or area of work that interests you. Then examine the associated Tasks, Knowledge, Skills, and Competency Areas. Next, compare those requirements with your current capabilities by asking yourself:
- “What do I already know?”
- “What can I already do?”
- “What are my skill gaps?”
- “What education, hands-on experience, or professional development could close these gaps?”
This approach can help you move beyond collecting credentials and toward developing capabilities that directly support your career goals. It also reinforces an important principle: cybersecurity education should connect theory with practical skills.
Why Continuous Learning is a Must for Cybersecurity Professionals
Cybersecurity doesn’t stand still, so neither should your skills and knowledge. The fact that NIST can update NICE Framework Components independently from the underlying framework structure demonstrates why cybersecurity professionals need to monitor workforce requirements as the field evolves. The 2026 addition of C-SCRM and expanded focus on cryptography and DevSecOps is a good example.
Professionals who developed their skills several years ago may now need to broaden their capabilities to remain competitive. That doesn’t necessarily mean starting from scratch, but rather identifying where your existing expertise intersects with emerging requirements and deliberately building from there.
ECCU is Where You Can Build Your Cybersecurity Career Around What Comes Next
The NICE Framework provides cybersecurity professionals with a clear way to connect career ambitions with real-world cybersecurity work and the skills needed to perform it. And as the 2026 updates to the framework demonstrate, the workforce is evolving toward capabilities in areas such as supply chain risk management, cryptography, DevSecOps, and other emerging cybersecurity domains.
At EC-Council University (ECCU), we believe cybersecurity education should not only prepare you for today’s job market but also for where the profession is headed next. Our advanced, career-focused online cybersecurity degrees and certification courses feature routinely updated coursework that aligns with NICE Framework requirements and guidelines. Through practical applied learning, curriculum designed around evolving cybersecurity demands, and a world-renowned faculty of industry experts, ECCU can help you develop the technical knowledge, strategic thinking, and real-world skills needed to advance your cybersecurity career. For more information:
Frequently Asked Questions About the NICE Cybersecurity Framework in 2026
What is the NICE Framework?
The NICE Workforce Framework for Cybersecurity is a NIST resource that provides a common language for describing cybersecurity work and the knowledge and skills required to perform that work. It is used in career development, education, training, hiring, and workforce planning.
What’s changed in the NICE Framework in 2026?
NIST released NICE Framework Components v2.2.0 on April 28, 2026. The update added a Cybersecurity Supply Chain Risk Management Work Role and updated the Cryptography and DevSecOps Competency Areas.
Is NICE the same as the NIST Cybersecurity Framework?
No. The NICE Framework focuses on the cybersecurity workforce, as in the work people perform and the knowledge and skills required to perform it. The NIST Cybersecurity Framework, by contrast, is designed to help organizations manage cybersecurity risk.
Can cybersecurity students use the NICE Framework?
Yes. NICE is specifically designed to support learners, including students and job seekers. Students can use Work Roles, Tasks, Knowledge, Skills, and Competency Areas to explore potential career paths and identify skills they need to develop.
Does the NICE Framework define cybersecurity proficiency levels?
Not directly. NIST notes that the NICE Framework itself does not establish proficiency levels. Organizations and other workforce development resources can use additional approaches to assess someone’s proficiency in specific capabilities.


