The European Union Agency for Cybersecurity (ENISA) has published version 2.0 of its national capabilities assessment framework (NCAF), designed to support EU Member States in assessing the maturity of their national cybersecurity strategies (NCSSs) in line with the evolving threat landscape and EU legislation, including the EU Network and Information Security Directive 2 (NIS2). The framework enables Member States to carry out a voluntary self-assessment of cybersecurity capabilities at both the strategic and operational levels, using a five-level maturity model ranging from foundation to advanced, across 20 strategic objectives grouped into capacity-building and awareness, cooperation and collaboration, cybersecurity governance, and regulatory and policy frameworks. The framework sets out a structured methodology, including indicators and a scoring mechanism based on maturity levels and coverage ratios, to help identify gaps, support capability building and track progress over time. It is intended to support long-term strategic planning, preparation for NIS2 peer reviews and transparency.