Course : Implementing, governing and certifying an NIS 2 project

Achieving NIS v2 compliance successfully

Seminar - 2d - 14h00 - Ref. NIS
Price : 1850 € E.T.

Implementing, governing and certifying an NIS 2 project

Achieving NIS v2 compliance successfully



The aim of the NIS 1 (Network and Information System 1) directive was to develop cybersecurity throughout the European Union, to mitigate threats to networks and information systems used to provide essential services in key sectors, and to guarantee the continuity of these services in the event of incidents. In so doing, it contributes to the security of the Union and the smooth functioning of its economy and society. The NIS 2 directive is part of a reinforced and necessary continuity in the face of an expanding cyberthreat landscape and the emergence of new challenges.


INTER
IN-HOUSE
CUSTOM

Seminar in person or remote class
Disponible en anglais, à la demande

Ref. NIS
  2d - 14h00
1850 € E.T.




The aim of the NIS 1 (Network and Information System 1) directive was to develop cybersecurity throughout the European Union, to mitigate threats to networks and information systems used to provide essential services in key sectors, and to guarantee the continuity of these services in the event of incidents. In so doing, it contributes to the security of the Union and the smooth functioning of its economy and society. The NIS 2 directive is part of a reinforced and necessary continuity in the face of an expanding cyberthreat landscape and the emergence of new challenges.


Teaching objectives
At the end of the training, the participant will be able to:
Understanding cyber risk issues and European responses
Integrate the security reference framework defined by the French government for the NIS directive
Understanding the changes between NIS 1 and NIS 2
Learn how to implement and deploy them through case studies
Understanding the ANSSI certification process
Evaluate project implementation costs

Intended audience
CISOs and security advisors, security architects, IT directors and managers, IT engineers, project managers (MOE, MOA), security auditors and IT regulatory lawyers.

Prerequisites
Basic knowledge of cybersecurity or knowledge equivalent to that acquired in the BYR and SSI seminars.

Course schedule

1
Introduction: the challenges of European cybersecurity

  • Sensitive data: cyber theft, espionage, sabotage...
  • New Cold War East/West, USA/China, West/Russia.
  • Organized hackers, the role of intelligence agencies.
  • APT (Advanced Persistent Threat), ransomware, targeted risks.
  • The approach to cyberthreats: towards a "cyber Schengen"?

2
The essentials for CISOs

  • For whom: essential and important entities, new eligibility and exclusion criteria.
  • For which ecosystems? New business sectors and ESNs.
  • Which rules? Of the 23 rules of NIS 1 plus "what it lacked".
  • When? From 2024 to 2026...
  • How can we help? With a controlled governance and certification process.
  • What penalties? Graduated on sales, based on the example of the RGPD.

3
Safety measures

  • NIS governance, protection, defense and resilience rules 1.
  • Risk analysis and information systems security policies.
  • Incident management.
  • Business continuity and recovery, crisis management.
  • Supply chain security.
  • Security in the acquisition, development and maintenance of networks and information systems.
  • Assessing the effectiveness of cybersecurity risk management measures.
  • Basic cyber hygiene practices and cyber security training.
  • Policies and procedures for the use of cryptography and, where applicable, encryption.
  • Human resources security, access control policies and asset management.
  • The use of multi-factor or continuous authentication solutions.

4
Compliance project management

  • From gap analysis to compliance.
  • Governance by risk: relevance of EBIOS RM in an NIS project.
  • Repetition of existing security measures, and NIS 1 rules where applicable.
  • The ANSSI certification process adapted to the NIS 2 directive.
  • NIS 2 project milestones and resources.

5
Conclusion: on the road to certification

  • Strong ISO 27K inspiration: link with ISO 27001 and new ISO 27002:2022 best practices.
  • Consistent cyber-resilience: link with DORA and CER directives and regulations.
  • French transposition: the parallel evolution of the LPM and OIV.
  • Differentiated state controls (ex ante or ex post regulation).
  • A penalty process comparable to the RGPD, the rules for the graduation of fines.
  • The security of its ecosystem and critical stakeholders.


Customer reviews
4,1 / 5
Customer reviews are based on end-of-course evaluations. The score is calculated from all evaluations within the past year. Only reviews with a textual comment are displayed.
CYRIL R.
16/06/26
4 / 5

A very good session, though there was some repetition between the first and second days. I would have liked to have gone into more depth and/or covered the operational implementation of NIS 2 in greater detail.
STÉPHANE A.
16/06/26
4 / 5

We’re focusing almost entirely on the NIS2 framework, its ReCyF reference framework, and the contribution of ISO 27001 and 27002 in meeting the requirements. Given that the title mentions ‘Implementing and Governing’, I was actually expecting a few additional points – or else the title needs changing ;) The course description is, however, fairly accurate.
THIBAUD R.
26/03/26
4 / 5

A lot of theory, but few practical examples; there’s a lack of real-life scenarios. The trainers are very knowledgeable about their subject, which is good, but perhaps they should take a moment now and then to interact a little more with the trainees.



Publication date : 02/17/2025



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.

Dates and locations
Select your location or opt for the remote class then choose your date.
Remote class

Dernières places
Date garantie en présentiel ou à distance
Session garantie

REMOTE CLASS
2026 : 1 Oct., 8 Dec.

2027 : 15 June, 15 June, 21 Sep., 21 Sep., 16 Dec., 16 Dec.

PARIS LA DÉFENSE
2026 : 1 Oct., 8 Dec.

2027 : 15 June, 21 Sep., 16 Dec.



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.