European Directive · NIS2

Cybersecurity as a Governance Obligation

Directive (EU) 2022/2555, which member states were required to transpose by 17 October 2024, substantially expands the scope and requirements of the original NIS Directive and establishes direct personal liability for management bodies.

NIS2 — Scope and Stakes

NIS2 replaces the 2016 NIS Directive and substantially broadens its scope of application. Where NIS1 covered seven sectors, NIS2 covers eighteen, divided between essential entities (Annex I: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, B2B ICT service management, public administration, space) and important entities (Annex II: postal services, waste management, chemicals, food production, manufacturing, digital providers, research).

Unlike NIS1, where scope resulted from self-identification by operators, NIS2 requires member states to establish and maintain a list of essential and important entities under their jurisdiction. This systematic identification obligation fundamentally changes the compliance dynamic for organisations in scope.

Governance · Management Body Liability

Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities pursuant to Article 21, oversee its implementation and can be held liable for infringements by the entities of the provisions of this Directive (NIS2 Directive, Art. 20(1)).

This provision represents a structural shift: cybersecurity is no longer a technical matter delegated to the IT department, but a governance obligation for which members of management bodies bear personal accountability. NIS2 training programmes address this managerial dimension explicitly — including the obligation under Article 20(2) for management body members to follow cybersecurity training.

Security Measures — Article 21

Article 21(2) of NIS2 defines ten categories of technical, operational and organisational measures that entities must implement in a manner proportionate to their risk exposure, size and the likelihood of incidents occurring.

Art. 21(2)(a)

Risk analysis and information system security policies

Framework for identifying, assessing and treating risks to network and information systems, with regular review cycles.

Art. 21(2)(b)

Incident handling

Processes for detecting, classifying and notifying significant incidents to competent authorities within harmonised timeframes.

Art. 21(2)(c)

Business continuity

Backup management, disaster recovery and crisis management — to maintain services in the event of a major disruption.

Art. 21(2)(d)

Supply chain security

Assessment of risks from direct suppliers and service providers, inclusion of security requirements in contracts.

Art. 21(2)(e)

Security in acquisition, development and maintenance

Security throughout the system and application lifecycle, vulnerability handling and coordinated vulnerability disclosure.

Art. 21(2)(f)

Effectiveness assessment policies and procedures

Policies and procedures for measuring and continuously improving the effectiveness of cybersecurity risk-management measures.

Art. 21(2)(g)

Cyber hygiene and cybersecurity training

Basic cyber hygiene practices and regular training for all staff, including management body members.

Art. 21(2)(h)

Cryptography and encryption policies

Policies on the use of cryptography and, where appropriate, encryption of data in transit and at rest.

Art. 21(2)(i)

Human resources security, access control and asset management

Personnel security, least-privilege access rights management, and inventory and classification of information assets.

Art. 21(2)(j)

Multi-factor authentication and secure communications

Implementation of MFA or continuous authentication, secured voice, video and text communications and emergency communication systems.

My Teaching Approach

NIS2 cannot be understood in isolation. Its operational application requires situating it within the surrounding normative and regulatory environment: the ISO standards on which its requirements draw, and the other European regulations that apply simultaneously to entities in scope.

NIS2 Directive · (EU) 2022/2555

European directive on the security of network and information systems — transposition deadline 17 October 2024

Reference ISO Standards

ISO/IEC 27001

ISMS — governance foundation, direct alignment with NIS2 requirements

ISO/IEC 27005

Information security risk management — Art. 21(2)(a)

ISO 22301

Business continuity management — Art. 21(2)(c)

ISO 31000

Generic risk management framework

European Regulatory Environment

DORA · (EU) 2022/2554

Lex specialis for the financial sector — financial entities subject to DORA are exempted from equivalent NIS2 obligations

Cyber Resilience Act (CRA)

Cybersecurity requirements for products with digital elements — interface with NIS2 obligations

National Transpositions and ENISA

ANSSI (France)

National cybersecurity agency, NIS2 transposition into French law

BSI (Germany)

NIS2UmsuCG — German transposition law

ENISA

EU Agency for Cybersecurity — implementation guidelines and threat landscape reports

NIS2 requires organisations to document their risk management decisions — not merely make them. Each measure under Article 21 must be justifiable against the entity's specific risk context. The capacity to reason and articulate, as much as to implement, is what NIS2 training programmes must develop.

Dominique Bourra · PECB Platinum Trainer

International Experience

Delivery Context

NIS2 training programmes serve two distinct audiences: cybersecurity and risk management professionals who need to acquire the competencies required for compliance implementation, and management body members who need to understand their obligations and personal liability under Article 20. This duality of audience is reflected in the structure and content of training programmes.

Training Formats

NIS2 training is available in classroom and remote formats, in French and English. All programmes systematically cover regulatory requirements analysis, their translation into operational procedures, and preparation for PECB certification examinations. Case studies are contextualised to participants' industry sectors to maximise transfer of learning.

NIS2 Certified Training · All PECB Levels
Foundation · Lead Implementer · In-house programmes

Request a programme