The NICE Framework currently has five work role categories. If a training provider still shows you seven, including Cyberspace Effects and Cyberspace Intelligence, that page predates version 2.0.0.
The NICE Workforce Framework for Cybersecurity, built on NIST Special Publication 800-181 Revision 1, gives employers a common language for cyber work, and many federal and state job descriptions are written against it. Its components are Work Role Categories, Work Roles, Competency Areas, and Task, Knowledge and Skill (TKS) statements.
What are the current categories?
| Category | Code | What the work involves |
|---|---|---|
| Oversight and Governance | OG | Leadership, management, direction and advocacy so an organisation can manage cybersecurity risk |
| Design and Development | DD | Research, design, development and testing of secure technology systems |
| Implementation and Operation | IO | Implementation, administration, configuration, operation and maintenance of systems |
| Protection and Defense | PD | Protecting against, identifying and analysing risks to systems and networks |
| Investigation | IN | Cybersecurity and cybercrime investigations, including digital evidence |
Cyberspace Effects and Cyberspace Intelligence were removed from the NICE Framework in v2.0.0; that work now sits in the DoD Cyber Workforce Framework. The authoritative component catalogue is version 2.2.0.
How do we map training to it?
We build cohorts around the category a role sits in rather than around a vendor. For Protection and Defense that usually means Security+, CySA+ and CEH; for Implementation and Operation, the Microsoft, Cisco and VMware administration tracks; for Oversight and Governance, CISM and CISSP; for Design and Development, secure development and cloud architecture work. Ask us for a mapping against the specific work roles in your position descriptions.
Why does the framework version matter?
Because job descriptions, grant applications and workforce plans cite it. A workforce plan that references categories which no longer exist will not survive review. Check the version you are citing against the NIST page below before you submit anything.
Frequently asked questions
How many NICE Framework categories are there?
Five: Oversight and Governance, Design and Development, Implementation and Operation, Protection and Defense, and Investigation.
What happened to Cyberspace Effects and Cyberspace Intelligence?
They were removed from the NICE Framework in version 2.0.0. That work now sits in the DoD Cyber Workforce Framework.
What is the current NICE Framework version?
Version 2.2.0 is the authoritative component catalogue.
Is the NICE Framework the same as DoD 8140?
No, but they are related. DoD 8140 qualification uses the DoD Cyber Workforce Framework, which shares heritage with the NICE Framework.
Can you map our job descriptions to work roles?
Yes. Send us the position descriptions and we will come back with the categories, roles and a training path, with the 10% government discount applied.
Talk to us about your requirement
Government agencies and military personnel get a 10% discount on our training. Private group delivery is available on your dates, on site, at our Miami and Fort Lauderdale campuses or live online.
Official sources: NICE Framework current versions · Getting started with the NICE Framework
Written by The Academy. Last updated October 2026. This page summarises public federal guidance and is not legal or contractual advice — confirm requirements against the official sources above or with your security manager.
