GRC-04

NIS2 Principles and Obligations for IT Teams

1

day(s)

In House

On-site

Remote Session

Training center

Paris

Audience

Decision-makers

Fee

On request

PRESENTATION & TARGET AUDIENCE

Understand the framework. Deploy the measures that matter.

An IT team translates regulatory requirements into concrete measures, selects tools, prioritizes remediation, and manages the relationship with suppliers. Without a precise understanding of the NIS2 framework and the internal division of roles, compliance ends up relying on individual interpretation and blind spots, particularly in organizations where no dedicated CISO position exists.

This training is designed for CIOs and CISOs of entities subject to NIS2, and aims to give IT teams the reference points and methods needed to translate NIS2 into concrete day-to-day actions.

PREREQUISITES

No technical or theoretical prerequisites are needed to attend this training.

LEARNING OBJECTIVES

The overall pedagogical objective of this training is to explain the NIS2 regulatory framework to CIOs and CISOs and enable them to apply the methods and tools needed to translate it into concrete day-to-day actions.

By the end of this training, participants will be able to:

  • Identify the NIS2 regulatory framework and describe what it concretely changes for an IT team’s daily work.
  • Distinguish their own role from that of their counterparts within the compliance framework, including in the absence of a dedicated CISO, and apply a RACI grid to the main NIS2 obligations.
  • Apply a recognized risk analysis method (EBIOS RM, ISO 27005), linked to the 10 measures of Article 21 and the ReCyF framework, to a typical critical system.
  • Classify an incident according to defined criteria, and apply the notification procedure within the required deadlines.
  • Map critical suppliers and secure the contractual relationship binding them to the organization.
  • Assess and calibrate security measures according to the organization’s size, criticality and status (essential or important entity), based on the principle of proportionality.

TRAINING METHODS

This training alternates interactive presentations and practical workshops. The introductory module draws on key figures and recent cases to anchor the stakes before addressing the regulations. The following modules are based on hands-on exercises and a contrasting case study leading to a group discussion facilitated by the trainer.

ASSESSMENT METHOD

The effective mastery of all the learning objectives will be assessed through a quiz (summative assessment).

PROGRAMME

Sequence 1: Introduction to NIS2

  • Identify the scope of application of NIS2 (sectors and entities concerned), and distinguish the status of essential and important entity, as well as the cascading effect through client organizations.
  • Describe the main pillars of the text (governance, risk management, incident notification).

Sequence 2: Who owns what, positioning yourself within the chain of responsibility

  • Distinguish the division of roles between management, the security function, legal, business units and external providers.
  • Apply a RACI grid to the main NIS2 obligations to clarify who decides, who executes, and who validates.
  • Identify how to distribute the compliance workload in an organization without a dedicated CISO, without depending on a position that does not exist.

Sequence 3: Risk management framework

  • Explain the key principles of risk analysis (EBIOS RM, ISO 27005).
  • Link the 10 risk management measures of Article 21 to their breakdown into 20 concrete objectives within ANSSI’s ReCyF framework (common level for essential and important entities, reinforced level for essential entities).
  • Distinguish a mandatory security objective from a substitutable acceptable means of compliance, to avoid confusing what is required with what remains the organization’s choice.
  • Apply the method to map the risks of a typical critical system (hands-on exercise).

Sequence 4: Incident notification in practice

  • Differentiate the criteria used to classify an incident as significant.
  • Identify the deadlines to be met (early warning within 24h, notification within 72h, final report within 1 month) and each party’s role in the notification chain.
  • Apply the classification and notification procedure to a simulated case (workshop).

Sequence 5: Securing the supply chain

  • Apply a method for mapping suppliers and providers according to their criticality.
  • Identify the contractual clauses to include, and the requirements to cascade down to one’s own subcontractors.
  • Explain, based on the cascading effect, what a regulated client organization can require from a supplier not directly subject to NIS2.

Sequence 6: Sizing technical measures, the principle of proportionality

  • Explain the principle of proportionality within Article 21 and the ReCyF framework.
  • Apply a sizing grid for measures according to the organization’s size, criticality and status (essential or important entity).
  • Translate a technical measure into a risk/cost argument, and justify an investment request presentable to the executive committee.
  • Distinguish a disproportionate over-investment from a minimal setup that is insufficient given the risk profile.

Updated on 3 July 2026

Training Center

PARIS
121 rue d'Aguesseau (centre d'affaires Emergence)
92 100 Boulogne Billancourt

Registered under number: 11922630392.

Cybersecurity training, NIS2, DORA.

Meets NIS2 requirements

Article 21(2)(g) of NIS2 requires cyber hygiene training for all staff. For IT and security teams, that means operational skills mapped directly to compliance duties, not generic awareness content. This training delivers exactly that: risk analysis methodology, incident classification, supplier security and technical sizing, producing a certificate and quiz results usable as evidence during an audit.

A key component of a comprehensive solution :

  • Full NIS2 training programme : from executive training to organisation-wide staff awareness, including IT teams and phishing simulation campaigns.
  • Cyber crisis exercise : joint simulation with management and IT teams, to rehearse coordination under pressure
  • Third-party risk management : mapping your suppliers and providers, scoring their criticality, and securing your supply chain contractually.
  • CISO as a Service: ongoing strategic security guidance, without an in-house recruitment.