NICE Framework Work Role Categories
termsecuritygovernance & riskops culture
The five high-level groupings the NICE Framework uses to organise cybersecurity work: Oversight and Governance, Design and Development, Implementation and Operation, Protection and Defense, and Investigation.
Five, not seven, and that is the first thing to know because most articles and course outlines still say seven. The NICE Framework - the NICE Workforce Framework for Cybersecurity, published by NIST as SP 800-181 - exists to give cybersecurity work a common vocabulary, so that a job advert, a curriculum and a certification can all be describing the same thing. Its components are built from Task, Knowledge and Skill statements, the atoms of the system: a Task is work to be done, Knowledge and Skill are what somebody needs in order to do it. Work Roles group those statements into areas of responsibility, and the Work Role Categories group the roles. There are currently 42 Work Roles across the five categories, alongside 11 Competency Areas which sit on a separate axis and describe a learner's capability in a domain rather than a position in an organisation - among them AI Security, Cyber Resiliency, Operational Technology Security and Supply Chain Security. The most common misuse is to read a Work Role as a job title. It is not one. A Work Role is a bundle of responsibility that may appear in many differently titled jobs, and a single real job usually combines several: the person who administers your firewalls may hold parts of Implementation and Operation, Protection and Defense, and on a bad week Investigation. Mapping a vacancy to exactly one role is a sign the mapping is wrong. The version trap is worth spelling out. The components are versioned separately from the publication, so SP 800-181 Revision 1 dates from November 2020 while the components have moved several times since: v1.0.0 in March 2024 introduced the current category names and Competency Areas, v2.0.0 in March 2025 removed Cyberspace Effects and Cyberspace Intelligence entirely - those Work Roles now live in the DoD Cyber Workforce Framework, for harmonisation between the two - and v2.1.0 in December 2025 revised Cybercrime Investigation and the AI Security competency. Anything citing seven categories is describing the framework as it stood before March 2025, and anything citing Securely Provision, Operate and Maintain, or Collect and Operate is describing it as it stood before November 2020. If you are building a curriculum or mapping a team against it, check the current components release rather than the publication number, because the publication number has not changed while the content has.
Also known as: nice framework, nice workforce framework for cybersecurity, nist sp 800-181, work role categories, nice work roles
Sources
- NIST, NICE Framework Components change log - the authoritative record of which version changed what, and when
- NIST SP 800-181 Revision 1 (November 2020), and NIST IR 8355 on Competency Areas
- NICE Framework Components v2.0.0 Summary of Changes (March 2025)