We provide course about NIS2 Directive Foundation. The NIS2 Directive Foundation course gives participants a fundamental understanding of the NIS2 Directive and its core requirements for cybersecurity and operational resilience across essential and important entities in the EU.
Course description:
The course focuses on introducing the directive, explaining its structure, objectives and key provisions so that organisations and professionals can navigate compliance requirements and foundational practices. This foundational course is designed for those who need to understand what the NIS2 Directive entails and how it affects organisational cybersecurity and resilience obligations.
Through practical explanations, examples and discussions, participants will gain insight into core concepts such as risk management expectations, incident handling obligations, supply-chain resilience and governance requirements. The course prepares candidates for the NIS2 Directive Foundation certification exam and provides the basis for further compliance and implementation training.
Course objectives:
Upon completion of this course, participants will be able to:
• Understand the scope and purpose of the NIS2 Directive
• Identify key requirements and obligations placed on organisations
• Describe risk management and incident reporting expectations under NIS2
• Recognise governance and accountability structures required by the directive
• Prepare for the NIS2 Directive Foundation certification exam
Course outline:
Module 1 - Introduction to the NIS2 Directive:
• Participants are introduced to the background, context and objectives of the NIS2 Directive. This section explains why the directive was established and how it builds on previous legislation to support stronger cybersecurity and resilience in critical sectors.
Module 2 - Scope and applicability:
• This module focuses on the directive’s applicability criteria, including who is covered, how organisations are classified as essential or important, and what obligations are triggered by these classifications.
Module 3 - Core governance and risk management provisions:
• Participants explore the governance expectations under NIS2, including leadership responsibilities, accountability, risk management approaches and how risk practices interact with operational resilience requirements.
Module 4 - Incident handling and reporting obligations:
• This section covers requirements related to detecting, responding to and reporting cybersecurity incidents. Participants learn timelines, escalation practices and how to structure incident management processes that comply with the directive.
Module 5 - Supply-chain and third-party security expectations:
• Focus is placed on understanding NIS2’s expectations for supply-chain resilience, third-party oversight and contractual security obligations to strengthen organisational dependencies.
Module 6 - Certification exam preparation:
• The course concludes with guidance on the NIS2 Directive Foundation certification exam, including key topics and what to expect in the certification assessment.
Target audience:
This course is suitable for professionals and stakeholders across cybersecurity, risk, compliance, IT management and operational resilience who need to understand the fundamental principles and requirements of the NIS2 Directive.
Prerequisites:
• There are no formal prerequisites for this course
• A basic interest in cybersecurity, resilience and regulatory compliance is helpful
Language:
• English course material, norwegian speaking instructor
Certification:
The exam is will take place at the end of the course on onsite classroom courses