Government and public sector security teams, and the contractors and systems integrators that serve them, are increasingly asked to describe their cyber workforce in a standard way: which roles they hold, what those roles need to know and do, and where the gaps sit. The reference point for that conversation in the United States is the NICE Framework, published by the National Institute of Standards and Technology (NIST).
Its comprehensiveness is both its value and its difficulty, since a team trying to align a training plan to it meets thousands of individual statements and dozens of roles before reaching an obvious starting point. This guide sets out what the framework is, how it is structured, and how a team planning training across roles can align to it and evidence the result.
In short:
- The NICE Framework (from the National Initiative for Cybersecurity Education, published by NIST as Special Publication 800-181 Revision 1) is a common language for describing cyber security work and the capabilities needed to perform it.
- It is built from Task, Knowledge, and Skill (TKS) statements, which combine into 42 Work Roles grouped under five Work Role Categories, alongside 11 Competency Areas, as of Components version 2.2.0 (April 2026).
- Knowledge and Skill statements describe what a person needs to know and be able to do, which is what hands-on training develops most directly. Task statements describe duties performed on the job, which tend to be assessed in the workplace rather than taught in a lab.
- Aligning training to the framework tends to follow one path: identify the Work Roles a team holds, pull the Knowledge and Skills those roles require, assign hands-on training that develops them, and validate the result with role-mapped assessment. Platforms such as TryHackMe map their content to frameworks like NICE for that purpose.
What is the NIST NICE Framework?
The NIST NICE Framework is the United States government's standard way to describe cyber security work and the knowledge and skills needed to perform it, published by NIST as Special Publication 800-181 Revision 1. NICE is the National Initiative for Cybersecurity Education, the NIST-led program that maintains the framework. Its purpose is communication: giving employers, educators, training providers and individuals a shared vocabulary for cyber roles, so that a job description, a course and an assessment can all refer to the same underlying work. It is a workforce framework, which is distinct from the NIST Cybersecurity Framework (CSF); CSF describes how an organization manages security risk, while NICE describes the people who do the work. NIST maintains the framework as a set of components updated on a rolling basis, and the current release is Components version 2.2.0, published April 2026, which supersedes earlier versions.
How is the NICE Framework structured?
The NICE Framework is built from Task, Knowledge, and Skill (TKS) statements, which are combined into Work Roles and Competency Areas, with the Work Roles grouped into five broad Work Role Categories. NIST defines the three building blocks plainly: a Task is an activity carried out to achieve an organizational objective, Knowledge is a set of concepts a person needs to understand, and a Skill is the capacity to perform an observable action. Work Roles group related TKS statements into an area of responsibility, and NIST notes that Work Roles are not the same as jobs, since a single job may span several roles. Competency Areas, of which there are 11 in the current release, cluster related Knowledge and Skills for domains such as operational technology security, supply chain security, cryptography and DevSecOps, and may be used alongside Work Roles or on their own.
As of Components version 2.2.0, the framework organizes 42 Work Roles into five categories, the most recent addition being a Cybersecurity Supply Chain Risk Management role under Oversight and Governance:
| Work Role Category | What it covers | Work Roles |
|---|---|---|
| Oversight and Governance | Leadership, management, direction and advocacy so the organization can manage cybersecurity risk and conduct cybersecurity work. | 17 |
| Design and Development | Research, design, development and testing of secure technology systems, including perimeter and cloud-based networks. | 9 |
| Implementation and Operation | Implementation, administration, configuration, operation and maintenance of technology systems for secure, effective performance. | 7 |
| Protection and Defense | Protecting against, identifying and analyzing risks to systems and networks, including investigation of cybersecurity events. | 7 |
| Investigation | Cybersecurity and cybercrime investigations, including the collection, management and analysis of digital evidence. | 2 |
Source: NIST NICE Framework Resource Center, Components v2.2.0 (April 2026).
What is the difference between Knowledge, Skills, and Tasks in the NICE Framework?
In the NICE Framework, Knowledge is what a person needs to understand, a Skill is what they need to be able to do, and a Task is a duty they perform on the job. The distinction matters when planning training, because the three are developed and measured differently. Knowledge and Skill statements describe capability that a person can build and demonstrate in a learning environment, which is what hands-on training is designed to develop. Task statements describe work performed in the context of an actual role and organization, for example determining procurement requirements or briefing leadership on risk, which tend to be assessed on the job rather than taught in a lab. NIST notes that assessment for Work Roles typically occurs at the Task level. For a team planning training, that means Knowledge and Skills are the most direct measure of what any hands-on program can develop, while Tasks are better understood as what a trained person then performs once in the role.
What is the difference between the NICE Framework and the NIST Cybersecurity Framework?
The NICE Framework describes the cyber security workforce, meaning the roles, knowledge and skills that carry out the work, while the NIST Cybersecurity Framework (CSF) describes how an organization manages and reduces cyber security risk; the two are complementary rather than alternatives. The CSF, currently at version 2.0, is organized around six Functions, Govern, Identify, Protect, Detect, Respond and Recover, expressed as outcomes an organization works toward rather than roles a person fills. The NICE Framework instead breaks the work itself into Task, Knowledge, and Skill statements grouped into Work Roles. Teams tend to use the two together: CSF to state the security outcomes the organization needs, and NICE to describe the roles and capabilities that deliver them. NIST publishes an official crosswalk mapping CSF Categories and Subcategories to NICE Work Roles, so an organization can connect a required outcome to the roles, and the training, that support it.
Why does the NICE Framework matter for government and public sector teams?
The NICE Framework matters for government and public sector teams because it is the common language United States federal, state and local government uses to define cyber roles, plan and assess its workforce, and set expectations for the hiring and training pipeline that supplies it. NIST lists the framework's intended uses for employers directly: conducting workforce assessments and identifying staffing gaps, writing more accurate position descriptions, improving recruitment, and building training and career pathways. For a public sector security lead, that translates into a practical need to describe a team's current capability, target capability and gaps in terms an assessor, a hiring pipeline and a training provider will all recognize. Vendors serving that market are often asked to describe their content against the same framework, so a training plan expressed in NICE terms tends to travel more easily through procurement and workforce reporting.
How do you align a team's cyber security training to the NICE Framework?
Aligning training to the NICE Framework tends to follow four steps: identify the Work Roles a team holds, pull the Knowledge and Skill statements those roles depend on, assign hands-on training that develops those statements, and validate the result with role-mapped assessment and records.
- Identify the in-scope Work Roles. Start from the roles a team holds or is hiring for, using the five Work Role Categories to place them. NIST publishes the full Work Role definitions and their associated TKS statements in the NICE Framework components.
- Pull the associated Knowledge and Skills. Each Work Role lists the Knowledge and Skill statements it depends on, and those statements become the concrete target for a training plan.
- Assign hands-on training that develops them. Knowledge and Skills build through practice in a realistic environment. TryHackMe's hands-on paths and modules are structured around that, and its Content Mapping feature maps learning content to the NIST framework, Job Qualification Requirements (JQRs), or a framework of a team's choice. For defensive roles, the SOC Level 1 path covers monitoring, alert triage and detection; for investigative roles, the Digital Forensics and Incident Response module covers evidence acquisition and analysis.
- Validate and record the result. Role-mapped assessment turns training into evidence a team can report. Role-mapped certifications validate capability at a defined level, and a management dashboard records who has demonstrated what across a team.
FAQ
What is the NIST NICE Framework?
The NIST NICE Framework is the United States government's standard taxonomy for describing cyber security work and the knowledge and skills needed to perform it, published by the National Institute of Standards and Technology as Special Publication 800-181 Revision 1 and maintained by the National Initiative for Cybersecurity Education. It provides a common language shared by employers, educators and training providers, built from Task, Knowledge, and Skill statements that combine into Work Roles and Competency Areas.
What are the five NICE Framework Work Role Categories?
The current NICE Framework groups its Work Roles into five categories: Oversight and Governance, Design and Development, Implementation and Operation, Protection and Defense, and Investigation. As of Components version 2.2.0 (April 2026) there are 42 Work Roles across the five categories, alongside 11 Competency Areas that cluster related Knowledge and Skills for domains such as operational technology, supply chain security, cryptography and DevSecOps.
What is the difference between Knowledge, Skills, and Tasks in the NICE Framework?
In the NICE Framework, Knowledge is a set of concepts a person needs to understand, a Skill is the capacity to perform an observable action, and a Task is an activity performed to achieve an organizational objective. Knowledge and Skills describe what a person needs to know and be able to do, which hands-on training develops directly. Tasks describe duties performed on the job, and NIST notes that assessment for Work Roles typically happens at the Task level.
How do you align and evidence cyber security training against the NICE Framework?
Aligning training to the NICE Framework starts by identifying the Work Roles a team holds, pulling the Knowledge and Skill statements those roles require, and assigning hands-on training that develops them, then validating the result with role-mapped assessment. On TryHackMe, the Content Mapping feature maps learning content to the NIST framework or Job Qualification Requirements, hands-on paths and modules build the underlying skills, and role-mapped certifications with a management dashboard produce records a team can report for assessments or audits.
How do government teams procure hands-on cyber security training?
Government teams can procure hands-on cyber security training through standard acquisition routes rather than bespoke contracts. TryHackMe is registered as a vendor in SAM.gov and sold as a commercial off-the-shelf (COTS) subscription, with purchase routes including a government purchase card for micro-purchases, a unit purchase order, DoD-approved federal resellers, and the Carahsoft (GSA/SEWP) contract vehicle for federal customers. Because it is browser-based, it requires no on-premise installation or dedicated infrastructure.
Is the NICE Framework the same as the NIST Cybersecurity Framework?
No. The NICE Framework (NIST Special Publication 800-181 Revision 1) describes the cyber security workforce through Work Roles and the Task, Knowledge, and Skill statements behind them. The NIST Cybersecurity Framework (CSF 2.0) describes how an organization manages cyber security risk, organized around six Functions: Govern, Identify, Protect, Detect, Respond and Recover. The two are complementary, and NIST publishes a crosswalk mapping CSF outcomes to NICE Work Roles.
The NICE Framework gives a team a defensible way to describe cyber roles, plan the training that develops them, and report capability in terms an assessor or hiring pipeline will recognize. Details on aligning and evidencing role-mapped, hands-on training across a team are available at TryHackMe for Business.


