NIS2 replaces the 2016 NIS Directive and substantially broadens its scope of application. Where NIS1 covered seven sectors, NIS2 covers eighteen, divided between essential entities (Annex I: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, B2B ICT service management, public administration, space) and important entities (Annex II: postal services, waste management, chemicals, food production, manufacturing, digital providers, research).
Unlike NIS1, where scope resulted from self-identification by operators, NIS2 requires member states to establish and maintain a list of essential and important entities under their jurisdiction. This systematic identification obligation fundamentally changes the compliance dynamic for organisations in scope.
Governance · Management Body Liability
Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities pursuant to Article 21, oversee its implementation and can be held liable for infringements by the entities of the provisions of this Directive (NIS2 Directive, Art. 20(1)).
This provision represents a structural shift: cybersecurity is no longer a technical matter delegated to the IT department, but a governance obligation for which members of management bodies bear personal accountability. NIS2 training programmes address this managerial dimension explicitly — including the obligation under Article 20(2) for management body members to follow cybersecurity training.
Article 21(2) of NIS2 defines ten categories of technical, operational and organisational measures that entities must implement in a manner proportionate to their risk exposure, size and the likelihood of incidents occurring.
Art. 21(2)(a)
Risk analysis and information system security policies
Framework for identifying, assessing and treating risks to network and information systems, with regular review cycles.
Art. 21(2)(b)
Incident handling
Processes for detecting, classifying and notifying significant incidents to competent authorities within harmonised timeframes.
Art. 21(2)(c)
Business continuity
Backup management, disaster recovery and crisis management — to maintain services in the event of a major disruption.
Art. 21(2)(d)
Supply chain security
Assessment of risks from direct suppliers and service providers, inclusion of security requirements in contracts.
Art. 21(2)(e)
Security in acquisition, development and maintenance
Security throughout the system and application lifecycle, vulnerability handling and coordinated vulnerability disclosure.
Art. 21(2)(f)
Effectiveness assessment policies and procedures
Policies and procedures for measuring and continuously improving the effectiveness of cybersecurity risk-management measures.
Art. 21(2)(g)
Cyber hygiene and cybersecurity training
Basic cyber hygiene practices and regular training for all staff, including management body members.
Art. 21(2)(h)
Cryptography and encryption policies
Policies on the use of cryptography and, where appropriate, encryption of data in transit and at rest.
Art. 21(2)(i)
Human resources security, access control and asset management
Personnel security, least-privilege access rights management, and inventory and classification of information assets.
Art. 21(2)(j)
Multi-factor authentication and secure communications
Implementation of MFA or continuous authentication, secured voice, video and text communications and emergency communication systems.
NIS2 cannot be understood in isolation. Its operational application requires situating it within the surrounding normative and regulatory environment: the ISO standards on which its requirements draw, and the other European regulations that apply simultaneously to entities in scope.
NIS2 Directive · (EU) 2022/2555
European directive on the security of network and information systems — transposition deadline 17 October 2024
Reference ISO Standards
ISO/IEC 27001
ISMS — governance foundation, direct alignment with NIS2 requirements
ISO/IEC 27005
Information security risk management — Art. 21(2)(a)
ISO 22301
Business continuity management — Art. 21(2)(c)
ISO 31000
Generic risk management framework
European Regulatory Environment
DORA · (EU) 2022/2554
Lex specialis for the financial sector — financial entities subject to DORA are exempted from equivalent NIS2 obligations
Cyber Resilience Act (CRA)
Cybersecurity requirements for products with digital elements — interface with NIS2 obligations
National Transpositions and ENISA
ANSSI (France)
National cybersecurity agency, NIS2 transposition into French law
BSI (Germany)
NIS2UmsuCG — German transposition law
ENISA
EU Agency for Cybersecurity — implementation guidelines and threat landscape reports
NIS2 requires organisations to document their risk management decisions — not merely make them. Each measure under Article 21 must be justifiable against the entity's specific risk context. The capacity to reason and articulate, as much as to implement, is what NIS2 training programmes must develop.
Delivery Context
NIS2 training programmes serve two distinct audiences: cybersecurity and risk management professionals who need to acquire the competencies required for compliance implementation, and management body members who need to understand their obligations and personal liability under Article 20. This duality of audience is reflected in the structure and content of training programmes.
Training Formats
NIS2 training is available in classroom and remote formats, in French and English. All programmes systematically cover regulatory requirements analysis, their translation into operational procedures, and preparation for PECB certification examinations. Case studies are contextualised to participants' industry sectors to maximise transfer of learning.