MANAGING NIS2: BRIDGING THE CYBERSECURITY GAP TO COMPLIANCE.
Certified NIS2 (CNIS2)
Find one of the main NIS2 products here
The NIS2 standards
The Van Haren Group, is the publisher and professional certification provider for CNIS2. We facilitate organizations and individuals in their learning and application of NIS2 professionals.
Take the next step with NIS2
Article 20 requires to be trained in cybersecurity decision-making, including those executing the program and those liable for the organization’s compliance
Related standards
NIS2 Training for Management Bodies
Under the NIS2 Directive, “we left cybersecurity to IT” is no longer an answer. Article 20 of Directive (EU) 2022/2555 puts approval of cybersecurity risk management measures in the hands of the management body, holds its members liable for infringements, and requires them to follow training. Not the security team. The board.
This two-day NIS2 training gives management bodies the understanding they need to make defensible cybersecurity decisions. It includes a structured NIS2 gap assessment, so you leave knowing exactly where your organization stands, and it prepares you for the Certified NIS2 Professional (CNIS2) exam.
Why NIS2 Training Is an Obligation, Not an Option
NIS2 replaced the original NIS Directive to lift the cybersecurity baseline across the European Union. It widens the scope to thousands of essential and important entities, sets ten mandatory risk management measures in Article 21, and starts a strict incident reporting clock in Article 23: an early warning within 24 hours, a full notification within 72 hours, and a final report within one month.
Supervisory authorities can impose administrative fines of at least 10 million euro or 2% of global annual turnover for essential entities, and 7 million euro or 1.4% for important entities. Whichever is higher.
Article 20(2) closes the loop. Members of management bodies are required to follow training so they can identify risks and assess cybersecurity risk management practices and the impact of those practices on the services the entity provides. This course is built for exactly that obligation. If you want the short version first, watch NIS2 in 3 minutes.
Who Should Attend This NIS2 Training
The course is written for the people the Directive names and the people who carry the work:
- Board members, directors, and executives of essential and important entities
- Managers who are liable for the organization’s NIS2 compliance status
- Program and project leads running the cybersecurity compliance program
- Risk, legal, and compliance officers who advise the management body
- Public bodies and institutions that fall in scope through national law
NIS2 reaches organizations through national legislation, such as the Cyberbeveiligingswet in the Netherlands. The training covers the Directive itself, which is the source every national implementation is built on.
What You Will Learn
- The purpose and intent of the NIS2 Directive from the perspective of the European Union
- Which organizations fall under the scope of Directive (EU) 2022/2555, and why
- The obligations in Articles 20 and 21, translated into decisions a board can actually make
- How supervision, enforcement, and management liability work in practice
- Incident reporting duties and the deadlines attached to them
- The real compliance status of your own organization, measured through the included gap assessment
- The concrete steps between where you are today and where NIS2 requires you to be
NIS2 Course Content
Day 1: NIS2 Foundations
- Background of the European Union cybersecurity programs
- Outline and structure of the Directive
- Core security concepts
- Public bodies and institutions
- Obligations for essential and important entities
- Supervision and enforcement
- Roles and responsibilities
Day 2: The NIS2 Gap Assessment
- How the gap assessment works
- Building the cybersecurity program
- Cybersecurity training and awareness
- Risk management
- Policies
- Resilience and continuity planning
- Organizational controls
- Technical controls
The full topic breakdown and weighting is published in the Certified NIS2 exam syllabus.
Certification: Certified NIS2 Professional (CNIS2)
The training prepares you for the Certified NIS2 Professional (CNIS2) certification, issued by the EU Organisational Compliance Institute.
- 60 multiple choice questions
- 60 minutes
- Pass mark 65%
- Closed book, online proctored
- Available in English and Dutch
Prerequisites
None. The training requires no technical background. Basic business acumen and a normal user’s understanding of the digital world are enough to follow the course, complete the gap assessment, and sit the exam.
Course Materials and Related Publications
Every attendee receives the NIS2 Professional (CNIS2) Courseware, revised edition, written by Michiel Benda. Trainers and buying committees can request a viewing copy.
The course builds on The NIS2 Navigator’s Handbook: Bridging the Cybersecurity Gap, which unpacks 46 articles, 144 provisions, and more than 140 references to other documents in language a management team can use. It includes the GAP assessment tool in several languages, so the work continues after the classroom.
How to Follow This NIS2 Training
The course is delivered by accredited CNIS2 training providers across Europe. If a classroom schedule does not fit, the Certified NIS2 (CNIS2) eLearning covers the same material at your own pace.
Running a program for a full management team? Request a quote for in company delivery. Training organizations that want to deliver CNIS2 themselves start with the CNIS2 Train the Trainer webinar.
Want to see what the gap assessment produces in practice? Read the NIS2 case study.
Recommended Follow-Up Training
Attendees who want deeper implementation guidance can continue with managerial or technical security training on information security management and governance, risk management, cloud security, secure development, and threat intelligence. The most common next steps are ISO 27001 for the management system, BIO CBP for Dutch government organizations, the ISM method for service management, and ITAM for asset control.
Frequently Asked Questions About NIS2 Training
Is NIS2 training mandatory for management?
Yes. Article 20(2) of Directive (EU) 2022/2555 requires members of the management bodies of essential and important entities to follow training. The same article encourages entities to offer comparable training to their employees on a regular basis.
Do I need a technical background to follow this NIS2 course?
No. The training is written for decision makers. Every technical concept is explained in business terms, and the gap assessment is filled in from a management perspective.
How long is the NIS2 training?
Two days. Day one covers the Directive and the obligations it creates. Day two is spent on the gap assessment and what to do with the result.
What is a NIS2 gap assessment?
A structured comparison between the measures your organization has in place today and the measures NIS2 requires. The output is a clear picture of the gap, which is the starting point for any credible compliance roadmap. The tool is included in the training and in The NIS2 Navigator’s Handbook.
Does NIS2 apply to my organization?
NIS2 covers essential and important entities in sectors including energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, public administration, space, postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research. Size thresholds and national transposition determine the final answer. Day one of the training walks you through the scoping logic so you can decide with confidence.
Who in the organization is liable under NIS2?
The management body. Article 20 makes it responsible for approving the cybersecurity risk management measures and overseeing their implementation, and it can be held liable for infringements. Delegating the work does not transfer the accountability.
What certification do I get after the NIS2 training?
The Certified NIS2 Professional (CNIS2) certificate, issued by the EU Organisational Compliance Institute after a 60 minute exam of 60 multiple choice questions with a 65% pass mark.