Skip to main content
NIS 2

NIS 2 Directive Foundation

NIS 2 Directive Foundation. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBFoundation2 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Cybersecurity professionals seeking a structured understanding of NIS 2 Directive requirements and implementation strategies
  • IT managers and professionals who need to improve the security and resilience of critical systems in line with NIS 2
  • Government and regulatory officials responsible for enforcing or overseeing NIS 2 compliance
  • Compliance and risk professionals working in sectors affected by the NIS 2 Directive

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Professionals seeking an advanced or lead-level NIS 2 implementation course, as this is a foundation-level programme
  • Individuals whose organisations operate exclusively outside the scope of the NIS 2 Directive and who have no regulatory interest in it
  • Those looking for deep technical cybersecurity skills training rather than regulatory and framework knowledge
  • Experts already holding comprehensive knowledge of NIS 2 requirements who need only a brief refresher

What you'll be able to do

  • 1Explain the fundamental concepts, definitions, and objectives of the NIS 2 Directive
  • 2Interpret the main cybersecurity requirements that the NIS 2 Directive imposes on in-scope entities
  • 3Identify the practical approaches and techniques used to implement NIS 2 requirements within a cybersecurity programme
  • 4Distinguish between the obligations applicable to essential entities and important entities under NIS 2
  • 5Relate the NIS 2 Directive requirements to existing organisational security measures and identify alignment opportunities

Day by day

Day 1Introduction to Fundamental Concepts and Definitions of the NIS 2 Directive
  • Background and Purpose of the NIS 2 Directive

    This module explains the policy context, legislative history, and objectives that led to the adoption of the NIS 2 Directive across the European Union.

  • Scope, Entities, and Key Definitions

    Participants examine which sectors and entity types fall within the scope of NIS 2 and learn the key definitions that determine applicability and obligations.

  • Governance and Supervisory Framework

    This module introduces the supervisory authorities, national frameworks, and cooperation mechanisms that support NIS 2 enforcement across member states.

By end of day

  • Explain the purpose and legislative context of the NIS 2 Directive
  • Determine whether a given organisation or sector falls within the scope of NIS 2
  • Identify the key governance bodies and supervisory mechanisms established under the Directive
Day 2NIS 2 Directive Requirements for Implementing a Cybersecurity Programme
  • Cybersecurity Risk Management Requirements

    This module details the risk management measures that NIS 2 requires in-scope entities to implement, including policies, access controls, and supply chain security.

  • Incident Reporting and Response Obligations

    Participants learn the incident notification timelines, reporting obligations, and response requirements that NIS 2 imposes on essential and important entities.

  • Implementation Approaches and Techniques

    This module presents practical strategies for translating NIS 2 requirements into actionable cybersecurity programme components within an organisation.

By end of day

  • Map NIS 2 cybersecurity risk management requirements to practical organisational controls
  • Apply the correct incident reporting timelines and procedures required under NIS 2
  • Select implementation approaches that integrate NIS 2 requirements into an existing cybersecurity programme

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental concepts and definitions of NIS 2 Directive
  • Domain 2: NIS 2 Directive requirements
  • Certificate and examination fees are included in the price of the training course.
  • Training material containing over 200 pages of information and practical examples will be distributed.
  • An attestation of course completion worth 14 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free.

Educational Approach

  • This training course includes diverse educational content, including practical exercises, multiple-choice quizzes, and illustrative demonstrations of NIS 2 Directive requirements.
  • Participants are strongly encouraged to interact with one other, share ideas, and actively participate in discussions.
  • The quiz structure within the course closely mirrors that of the certificate exam, ensuring participants are well-prepared for the exam.

Buyers always ask

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

Which organisations are in scope for the NIS 2 Directive?+

NIS 2 applies to organisations classified as essential or important entities operating in sectors considered critical to the EU economy and society, such as energy, transport, health, digital infrastructure, and others defined in the Directive's annexes.

The course covers the scope definitions and entity classifications so that participants can determine whether their own organisation or clients fall within the Directive's requirements.

Is there a recommended level of prior knowledge for this course?+

No formal prerequisites are required, and the course is designed to be accessible to participants who are new to the NIS 2 Directive specifically.

Participants with some background in cybersecurity or information security will find it easier to contextualise the regulatory requirements. Those with no cybersecurity exposure at all may wish to review basic security concepts beforehand to get the most from the two days.

Does this foundation course prepare me to lead a NIS 2 implementation project?+

This course provides the conceptual and definitional foundation needed to understand what NIS 2 requires and how implementation approaches are structured. It is designed to build awareness and interpretive capability rather than comprehensive project management skills.

Professionals who need to lead full NIS 2 implementation programmes within their organisations would benefit from progressing to a more advanced course after completing this foundation level.

How does NIS 2 differ from the original NIS Directive?+

NIS 2 significantly broadens the scope of the original NIS Directive by bringing more sectors and entity types under its requirements, strengthening cybersecurity risk management obligations, introducing stricter incident reporting timelines, and increasing supervisory and enforcement powers.

The course addresses these updated requirements so that participants who may already be familiar with the original Directive can understand what has changed and what new obligations their organisations must meet.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.