NIS 2 Directive
Understand the EU cybersecurity directive, who it covers and how to prepare.
NIS 2 Directive: what it is and why it matters
NIS 2 sets measures for a high common level of cybersecurity across the EU. As a rule it covers medium-sized and large entities in sectors of high criticality and other critical sectors, and it requires cybersecurity risk-management measures, incident reporting to national authorities and accountability of top management.
Because it is a directive, it reaches organisations through national law in each member state, so obligations can differ by country. A proposal to amend it was published in January 2026 and was not adopted law when this page was checked.
Built for the people who carry the work
- Compliance, legal and risk officers at organisations serving EU markets
- Security managers in energy, transport, health, digital infrastructure and other covered sectors
- Executives who carry accountability under the directive
- Consultants advising EU customers
What you will be able to do
- Work out whether an entity is likely essential, important or out of scope
- Explain risk-management measure expectations
- Describe incident reporting timelines
- Understand management accountability
- Plan an implementation roadmap and evidence set
Subject outline
- 01
Directive structure and scope
- 02
Essential and important entities
- 03
Risk-management measures
- 04
Incident reporting
- 05
Governance and management accountability
- 06
Supervision and penalties
- 07
National transposition
How it supports real work
Scoping which parts of a group fall under the directive
Mapping existing ISO/IEC 27001 controls to NIS 2 expectations
Preparing an incident reporting procedure that meets the timelines
Training, examination and certification are different steps
NIS 2 is a directive, so there is no certificate of NIS 2 compliance. PECB publishes a NIS 2 Directive Lead Implementer personal programme.
- PECB publishes the course as 5 days with the exam on day 5; its handbook describes 80 multiple-choice questions and a 70% pass mark.
- PECB sources differ on the exam question type, so we confirm the current position before you enrol.
- Organisations demonstrate compliance to their national authority, not through a personal certificate.
Certification bodies set and can change their own exam, eligibility and renewal rules. The details below are what the body publishes; we confirm the current position with you before you enrol.
Sources checked, October 2026: eur-lex.europa.eu · digital-strategy.ec.europa.eu
What is confirmed, and what people ask
Delivery information
Delivery details for this course have not been confirmed for publication, so none are listed here. Course length, schedule, language, delivery format and fees are confirmed per enquiry. Certification bodies set their own exam and eligibility rules, and we confirm the route to any certificate before you enrol.
Enquire About This CourseFrequently asked questions
Is there a NIS 2 certificate for organisations?
No. The directive is enforced by national authorities. Personal training programmes are separate.
What are the incident reporting timelines?
An early warning within 24 hours, an incident notification within 72 hours and a final report no later than one month after.
Does NIS 2 apply outside the EU?
It applies to covered entities providing services in the EU. Whether it reaches you depends on your services and national law, so take advice.
Is this legal advice?
No. This page is general information.
Related courses
Related Valtrenix services
Request course information
Tell us who the training is for and what you want to achieve. We reply with confirmed details only, including what is currently available for NIS 2 Directive.
- Individual and team training enquiries welcome
- No fees, dates or formats are published until confirmed
- We confirm the certification route before you enrol


