


Information and communication technology is one of Europe's most dynamic and most fragmented sectors. Every country, every company, every training provider has historically used different nomenclatures to describe the same professional competences. That fragmentation creates barriers to worker mobility and makes comparing qualifications difficult.
Two European frameworks address the problem with complementary approaches: the e-Competence Framework (e-CF) and the European Cybersecurity Skills Framework (ECSF).
The e-CF is not a product of the JRC or the European Commission, but of CEN (the European Committee for Standardization), the body that develops technical standards in Europe. Published as the European standard EN 16234-1, the e-CF defines 41 competences organised into 5 areas reflecting ICT business processes:
Each competence is described with proficiency levels from e-1 to e-5, aligned to the European Qualifications Framework (EQF) to support cross-border recognition of competences.
With the exponential growth of cyber threats, cybersecurity has become a critical sector marked by a dramatic shortage of qualified professionals in Europe. The ECSF, published by ENISA (the European Union Agency for Cybersecurity), defines 12 professional profiles in information security:
Among the profiles: Chief Information Security Officer, Cyber Incident Responder, Cyber Threat Intelligence Specialist, Cybersecurity Architect, Cybersecurity Auditor, Cybersecurity Educator, Cybersecurity Implementer, Cybersecurity Researcher, Cyber Legal Policy and Compliance Officer, Digital Forensics Investigator, Penetration Tester, Cybersecurity Risk Manager.
For each profile the ECSF describes the mission, tasks, competences, knowledge and skills required. This lets companies define precisely the roles they are recruiting for, training providers design targeted pathways, and professionals plan their own progression.
The e-CF and the ECSF do not overlap: they complete each other. The e-CF covers the whole ICT spectrum with a competence-based approach; the ECSF focuses on cybersecurity with a profile-based approach. An information security professional can use the ECSF to identify their profile and the e-CF to detail the associated technical competences.
Both frameworks connect to the wider system of European competences. The digital foundations come from DigComp, the training of ICT educators is supported by DigCompEdu, and the sector's research competences find their reference in ResearchComp.
Explore the ICT frameworks in the framework catalogue on ExplorerHub.

Many schools' training plans are the sum of whatever was on offer. DigCompEdu lets you build one the other way round: from measured needs to decisions.

A digital curriculum is not a list of tools to teach. It answers three questions: which competences, in which years, verified how. DigComp answers the first.

FinComp is written for adults, but it is the most solid reference available for building a school pathway. The key is not treating it as an applied maths syllabus.
Developed by IDCERT - Certification Body accredited by Accredia no. 02257
© 2026 IDCERT S.r.l. Società Benefit. All rights reserved.