Tech careers

Tech careers / Skills

The ACS skills framework

How ACS aligns member benchmarking with established frameworks — SFIA 9, the NIST NICE Workforce Framework for Cybersecurity and the ACM/IEEE computing curricula — and how these map to membership grades and certifications.

Why computing needs a shared skills language

Job titles in computing are inconsistent across employers: one company's 'senior engineer' does the work of another's 'principal architect'. This makes it hard for individuals to benchmark themselves, for employers to write accurate job descriptions, and for professional bodies to certify competence consistently. Skills frameworks solve this by describing capability in terms of what a person can actually do and at what level of responsibility, independent of any job title.

ACS does not publish a proprietary taxonomy from scratch. It aligns membership grading, certification requirements and CPD guidance to three widely used, independently maintained frameworks: the Skills Framework for the Information Age (SFIA), now in its ninth version; the NIST Workforce Framework for Cybersecurity, known as the NICE Framework and defined in NIST Special Publication 800-181 Revision 1; and the computing curricula guidelines jointly produced by ACM and the IEEE Computer Society. Using established frameworks keeps ACS credentials portable and internationally recognizable.

SFIA 9 and the seven levels of responsibility

SFIA, first published in 2000 and maintained by the SFIA Foundation, describes digital and computing work through a matrix of skills organized into categories covering strategy and architecture, change and transformation, development and implementation, delivery and operation, people and skills, and relationships and engagement — each rated against seven levels of responsibility. SFIA 9, released in 2024, expanded coverage of emerging areas including data ethics, artificial intelligence and sustainability.

The seven levels run from Level 1 (Follow) to Level 7 (Set strategy, inspire, mobilize), with each level defined by generic attributes covering autonomy, influence, complexity, business skills and knowledge, independent of any particular technical skill. A Level 3 practitioner typically works under general direction on moderately complex tasks; a Level 5 practitioner takes accountability for a significant area of work; a Level 7 practitioner sets strategic direction at the highest level of an organization.

  • Level 1 — Follow: works under close supervision on simple, well-defined tasks
  • Level 2 — Assist: performs varied tasks under routine direction with limited autonomy
  • Level 3 — Apply: exercises autonomy within defined parameters on moderately complex work
  • Level 4 — Enable: influences a significant part of the organization and offers specialist advice
  • Level 5 — Ensure/Advise: holds broad accountability and defines policy within a technical or business area
  • Level 6 — Initiate/Influence: has organization-wide influence and makes decisions critical to success
  • Level 7 — Set strategy/Inspire: shapes organizational strategy and sets direction for the field

The NIST NICE Workforce Framework for Cybersecurity

For members whose practice sits primarily in cybersecurity, ACS points to the NICE Framework, maintained by the National Institute of Standards and Technology and published as SP 800-181 Revision 1 in November 2020. NICE organizes cybersecurity work into work role categories, work roles, competency areas and the underlying task, knowledge and skill statements needed to perform each role, replacing the more rigid category and specialty-area structure of the 2017 model.

The value of NICE is precision: rather than a generic 'security engineer' title, NICE lets a member and an employer agree exactly which tasks, knowledge areas and skills a role covers, drawn from a shared national reference vocabulary maintained by a federal standards body. This is particularly useful for candidates preparing for the ACS Certified Security Practitioner (CSEC) credential, since scope and evidence can cite specific NICE work roles.

ACM/IEEE computing curricula

Where SFIA and NICE describe workplace competence, the ACM/IEEE Computer Society joint curricula guidelines describe academic preparation. These volumes, covering computer science, software engineering, information technology, information systems, cybersecurity and data science, are periodically revised by joint task forces and used by the large majority of accredited US computing degree programs to design coursework.

ACS uses the curricula as a reference point when evaluating academic qualifications for membership grade eligibility and when advising students on which degree emphasis matches their intended specialization. A transcript mapped against the relevant curriculum volume gives ACS assessors a consistent, defensible way to judge whether formal education has covered the foundational knowledge a grade expects, alongside the practical evidence provided by SFIA or NICE mapping.

How to benchmark yourself

Start with SFIA if your role is general-purpose technology work: list the SFIA skills that best describe your day-to-day responsibilities, then read the level descriptors to identify where your autonomy, complexity of work and influence currently sit. Most practitioners operate at different levels across different skills — Level 4 in a core technical skill but Level 2 in a skill they are newly learning — and that unevenness is normal, useful diagnostic information.

If your work is cybersecurity-specific, cross-reference the NICE work role closest to your actual duties and compare its task, knowledge and skill statements against your current capability. Gaps identified this way translate directly into a CPD plan, since NICE statements are granular enough to point to specific learning needs rather than vague categories.

Repeat the exercise annually alongside a performance review or CPD planning cycle, and keep a dated record of where you assessed yourself. Progress against SFIA levels or NICE work-role coverage over several years is itself strong evidence of professional growth and a useful input to a membership upgrade or certification application.

Mapping to ACS membership grades and certifications

ACS membership grades correspond broadly to SFIA levels of responsibility, giving members and employers a consistent way to interpret a grade. Student and Associate membership generally align with SFIA Levels 1–2, full Professional membership with Levels 3–4, and Fellow with Levels 5–7, though assessors also weigh breadth of skill and professional conduct, not level alone.

The flagship credential, the Certified Computing Professional (CCP), is pitched at practitioners typically operating at SFIA Level 4 or above who can demonstrate accountable, specialist-level work across a defined technical domain. The Certified Security Practitioner (CSEC) draws its scope definitions primarily from NICE work roles in security and governance. The Certified AI Assurance Practitioner (CAIA) maps to SFIA skills across data ethics, artificial intelligence and machine learning, and the Certified Data Engineering Professional (CDEP) to skills in data management, architecture and engineering — so every ACS certification traces back to an externally maintained, independently verifiable framework.