icon icon

NIS 2 – requirements, obligations and practical implementation in the organization

icon

Training process

Training needs analysis

If you have specific requirements regarding the training programme, we will carry out a training needs analysis for you. This will guide us on which aspects of the programme should receive greater emphasis, so that the training programme meets your specific needs.

What will you gain?

icon

Check if NIS 2 applies - You will learn how to determine whether your organisation falls under NIS 2, which sector it belongs to, and how size, dependencies and supply chain role affect qualification.

icon

Clear roles and accountability - You will understand what responsibilities sit with the board, managers and security leads, so you can assign tasks correctly and reduce the risk of governance and compliance gaps.

icon

Incident reporting readiness - You will learn how to identify reportable incidents and prepare notifications within the required 24-hour, 72-hour and one-month timelines while working effectively with the CSIRT.

icon

Practical Article 21 controls - You will see how to turn NIS 2 requirements into concrete measures covering risk analysis, access control, vulnerability management, backup, encryption and documentation.

icon

Audit and inspection preparation - You will learn which documents, procedures and evidence to prepare so you can handle compliance audits more smoothly, reduce findings and better support your security decisions.

icon

Stronger risk and asset management - You will learn how to build an asset register, assess risk and plan business continuity, making it easier to protect critical systems and set clear security priorities.

icon

Safer supplier management - You will explore ways to assess third-party risk, define key contractual clauses and monitor IT providers, helping you reduce vulnerabilities introduced through the supply chain.

icon

Action plan for your organisation - You will leave with a practical roadmap covering maturity assessment, policy updates, employee awareness, a readiness checklist and the next steps for structured NIS 2 implementation.

Training programme

1. Introduction to NIS 2

  • origin and purpose of the NIS 2 Directive,
  • the most important changes compared to the NIS Directive,
  • why did the EU introduce new requirements?
  • who does NIS 2 apply to – essential and important sectors,
  • criteria for company qualification (size, significance, connections).

2. Subject and sectoral scope

  • key sectors (essential entities) – examples,
  • important sectors (important entities) – examples,
  • micro and small enterprises – when are they subject to NIS 2?
  • subcontractors, supply chain and third-party risk.

3. Management board duties and personal liability

  • the role of the management board in oversight of cybersecurity,
  • the requirement to approve policies and security measures,
  • management board training – NIS 2 requirements,
  • criminal and financial liability of decision-makers,
  • delegation of duties and the role of the security officer.

4. Organizational and technical requirements (Art. 21)

  • overview of 10 areas of security measures required by NIS 2:
    • risk analysis and risk management policies,
    • handling of security incidents,
    • business continuity, backup, disaster recovery,
    • network and system security,
    • access control and multi-factor authentication,
    • vulnerability management,
    • supply chain oversight,
    • security of purchases and cooperation with suppliers,
    • encryption and data protection,
    • asset and documentation management.

5. Incident reporting

  • new reporting procedures:
    • initial notification within 24 hours,
    • interim report after 72 hours,
    • final report within 1 month,
  • scope of information required in notifications,
  • examples of incidents that are subject to reporting,
  • cooperation with CSIRT (national/systemic).

6. Audits and compliance inspections

  • what inspections look like after the implementation of NIS 2,
  • documentation required for the audit,
  • the role of internal and external auditors,
  • the most common irregularities found in companies.

7. Financial penalties and consequences of non-compliance

  • penalty thresholds:
    • €10 million / 2% of turnover for essential entities,
    • €7 million / 1.4% of turnover for important entities,
  • management liability,
  • operational and reputational consequences.

8. How to prepare an organization for NIS 2 – implementation plan

  • assessment of cybersecurity maturity,
  • review and update of internal policies,
  • implementation of appropriate technical measures,
  • building a cybersecurity team,
  • requirements regarding documentation and procedures,
  • internal communication plan and employee training,
  • NIS 2 readiness checklist.

9. Cooperation with suppliers and supply chain management

  • new obligations regarding third-party risk,
  • required provisions in contracts with IT suppliers,
  • monitoring of service providers and supplier audit,
  • examples of practical provisions and policies.

10. Practical workshops (optional)

  • risk analysis for a sample incident,
  • preparation of a response procedure,
  • development of an asset register,
  • preparation of a business continuity plan (BCP),
  • incident simulation and the reporting process,
  • assessment of internal compliance – checklists and templates.

11. Summary and recommendations for participants

  • the most important obligations,
  • the biggest pitfalls in implementing NIS 2,
  • how to maintain compliance after implementation,
  • recommended tools and practices.

What are the prerequisites for participating in the training?

icon

Cybersecurity fundamentals - You should understand basic cybersecurity terms such as incident, vulnerability, risk, backup, access control and business continuity before joining the training.

icon

Awareness of organisational processes - You should know the key processes in your organisation and understand which systems, services and suppliers support the most important business activities.

icon

Familiarity with policies and procedures - You should have some experience working with internal policies, procedures or formal requirements so you can relate the training content to your own environment.

icon

Basics of risk management - You should understand how threat identification, impact assessment and selection of safeguards work, even if you do not carry out full risk analyses yourself.