Introduction
This document is intended to be a comprehensive and self-contained guide for ECSC 2026 participants. The current version is a draft, subject to changes depending on feedback and possible organizational updates.
This document is based on the ECSC documentation including the Charter, the Rules, and the Code of Conduct, and all participants should be familiar with this documentation. Some parts of this document (e.g. communication rules, roles and structure of the document) are based on the Handbook for ECSC 2025 created by NASK - Państwowy Instytut Badawczy.
1.1. About ECSC
Section titled “1.1. About ECSC”The European Cybersecurity Challenge (ECSC) is an annual event happening at an international level that brings together the most promising talents in the cybersecurity sector. The competition acts as a unique platform dedicated to sharing knowledge, ideas and skills through practical tests on topics representing the state of the art of cybersecurity. During the event, teams from participating countries compete in a series of Capture-The-Flag format challenges over two days to determine the best prepared nation.
Originating in 2014, the event is coordinated by ENISA, the European Union Agency for Cybersecurity. Each year a different host country is responsible for the organization.
ECSC 2026 takes place in Bochum, Germany, from 12 to 16 October 2026. It is organised by Nachwuchsförderung IT-Sicherheit e.V. (NFITS) with the City of Bochum as host city partner and made possible together with our event partners and sponsors.
The event offers a unique opportunity for participants to interact with other young people from across all of Europe, as well as receive mentorship, broaden their skills and establish lasting connections in the cybersecurity field, benefiting their careers and becoming part of an extremely active community of young cybersecurity talents.
1.2. About the organizers
Section titled “1.2. About the organizers”1.2.1. ENISA
Section titled “1.2.1. ENISA”The European Union Agency for Cybersecurity, ENISA, is an institution whose main goal is to achieve a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, ENISA contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works to keep Europe’s society and citizens digitally secure.
1.2.2. Nachwuchsförderung IT-Sicherheit e.V.
Section titled “1.2.2. Nachwuchsförderung IT-Sicherheit e.V.”The Nachwuchsförderung IT-Sicherheit e.V. (NFITS) is a non-profit association whose main goal is to identify and promote young talent in the field of information security across Germany. Established to foster up-and-coming IT professionals, NFITS contributes to national cybersecurity education, enhances practical hacking and defense skills through nationwide competitions like the Cyber Security Challenge Germany, cooperates with government bodies, industry partners, and European institutions, and helps Germany prepare for the cyber challenges of tomorrow. Through knowledge transfer, competitive events, and community building, the Association works to secure society’s digital future by empowering the next generation of cybersecurity experts.