EU Governance & Compliance Trainings
Implement your Cybersecurity and operational resilience towards Europe’s evolving regulatory landscape
European organizations are facing a rapidly changing regulatory environment. Cybersecurity, operational resilience, data protection and artificial intelligence are no longer separate compliance topics. They are increasingly part of a broader governance responsibility that affects management, risk, technology and day-to-day operations.
Frameworks such as NIS2, DORA, GDPR and the EU AI Act establish requirements for how organizations manage digital risks, protect information, respond to incidents and demonstrate accountability.
We offer a country specific practical course (stand-alone or nice add-on) implementing these in
- the Netherlands via the Cyberbeveiligingswet (Cbw) requirements
- Belgium via CyFun®
Whether you need to understand the fundamentals, lead an implementation or prepare your organization for new regulatory obligations, our training programs help bridge the gap between regulation and practice.
NIS Institute offers practical and certification-oriented training to help professionals understand these requirements and translate them into effective governance, controls and processes.
NIS2 Directive
Strengthening cybersecurity across the European Union
The NIS2 Directive establishes a common framework for improving cybersecurity and resilience across essential and important sectors within the European Union.
Compared with its predecessor, NIS2 significantly expands the number of organizations within scope and places greater emphasis on risk management, incident reporting, supply-chain security and management accountability.
Organizations need more than technical security measures. Compliance requires a structured approach involving governance, policies, risk management, business continuity, incident handling and continuous improvement.
NIS2 Directive Foundation
The NIS2 Directive Foundation training provides an introduction to the key concepts, requirements and principles of NIS2.
Participants develop an understanding of the regulatory framework, cybersecurity risk-management requirements and the responsibilities organizations face under the directive.
This training is particularly suitable for professionals who need a solid understanding of NIS2 without immediately taking responsibility for a complete implementation.
NIS2 Directive Lead Implementer
The NIS2 Directive Lead Implementer training takes the next step.
It prepares professionals to support organizations in planning, implementing, managing, monitoring and maintaining a cybersecurity program aligned with NIS2 requirements.
The training is particularly relevant for cybersecurity professionals, compliance and risk managers, consultants and professionals responsible for implementing NIS2 within their organization.
DORA
Building digital operational resilience in the financial sector
The Digital Operational Resilience Act (DORA) establishes a harmonized European framework for managing ICT and operational resilience risks within the financial sector.
DORA addresses areas such as ICT risk management, incident management and reporting, digital operational resilience testing and risks associated with third-party ICT providers.
The objective goes beyond preventing cyber incidents. Financial organizations must be able to demonstrate that they can withstand, respond to and recover from ICT-related disruptions.
DORA Foundation
The DORA Foundation training introduces participants to the fundamental concepts and requirements of the Digital Operational Resilience Act.
It provides a structured understanding of DORA and its implications for financial organizations and professionals involved in ICT, risk, security, compliance and operational resilience.
DORA Lead Manager
The DORA Lead Manager training is aimed at professionals responsible for helping organizations establish and manage a structured approach to DORA compliance.
Participants develop the knowledge and competencies required to integrate digital operational resilience into governance, risk-management and compliance activities.
EU AI Act
Preparing for the next generation of AI governance
Artificial intelligence introduces enormous opportunities, but also new questions surrounding risk, accountability, transparency, data and human oversight.
The EU AI Act establishes a risk-based regulatory framework for artificial intelligence in the European Union. Obligations depend on factors including the type of AI system, its risk classification and the role an organization has within the AI value chain.
For organizations, this means AI governance is becoming a formal compliance responsibility.
Organizations need to know which AI systems they use, understand how those systems are classified, assign responsibilities and establish appropriate controls for areas such as risk management, data governance, documentation, transparency and human oversight.
Certified EU AI Governance Professional — Coming Soon
The upcoming PECB Certified EU AI Governance Professional training is designed for professionals responsible for navigating the European regulatory framework for artificial intelligence.
The program addresses the EU AI Act together with relevant EU Data Act requirements and focuses on translating regulatory obligations into practical governance.
Participants will learn how to determine applicability and roles, classify AI systems according to risk, establish governance structures, manage AI-related risks and maintain appropriate documentation and oversight throughout the AI lifecycle.
This training will be particularly relevant for governance, risk and compliance professionals, AI professionals, privacy and legal professionals, information security specialists, consultants and managers responsible for the responsible adoption of AI.
Coming soon at NIS Institute.
Country specific practical
Dutch Cyberbeveiligingswet (Cbw)
From the European NIS2 Directive to Dutch legislation: For organizations in the Netherlands, understanding NIS2 also means understanding its implementation in Dutch legislation. The Cyberbeveiligingswet (Cbw) translates the requirements of the NIS2 Directive into the Dutch regulatory environment. The legislation introduces cybersecurity obligations for thousands of Dutch organizations and places explicit responsibilities on management.
Cyberbeveiligingswet training
NIS Institute’s practical Cyberbeveiligingswet training focuses specifically on the Dutch situation.
Rather than approaching NIS2 only from a European or theoretical perspective, participants work with the requirements they encounter within the Netherlands.
The training addresses topics such as:
- determining whether an organization falls within scope;
- classification of essential and important entities;
- translating the duty of care into practical measures;
- incident-reporting requirements;
- responsibilities of the management body;
- cybersecurity governance and risk management;
- and developing an implementation roadmap.
This makes the training particularly valuable for executives and board members, CISOs and ISOs, risk and compliance professionals, legal professionals, IT and OT managers, internal auditors, consultants and professionals responsible for NIS2 or Cbw implementation.
CyberFundamentals Framework (CyFun®)
From NIS2 requirements to practical cybersecurity measures in Belgium
For organizations in Belgium, the CyberFundamentals Framework (CyFun®) provides a practical and structured approach to implementing cybersecurity measures and strengthening digital resilience.
The framework was developed by the Centre for Cybersecurity Belgium (CCB) and helps organizations translate NIS2 requirements into concrete controls, technical and organizational measures, maturity levels, and demonstrable evidence. CyFun® uses different assurance levels, including Basic, Important, and Essential, allowing organizations to align measures with their risk profile and specific context.
CyberFundamentals (CyFun®) Framework Training
NIS Institute’s practical CyberFundamentals (CyFun®) Framework Training is designed for professionals who already have a general understanding of NIS2 and are ready to take the next step: how do we translate these requirements into concrete measures and demonstrable compliance?
During the training, participants learn how the CyFun® Framework is structured, how to determine the appropriate assurance level, and how controls can be translated into concrete technical and organizational measures. The training also covers self-assessments, maturity scoring, documentation and evidence, conformity assessments, and the development of a practical implementation roadmap.
The training therefore provides a practical complement to the PECB NIS2 Directive Foundation and NIS2 Directive Lead Implementer trainings. While these trainings focus on understanding and implementing NIS2, the CyFun® training demonstrates how organizations can operationalize these requirements within the Belgian context and provide evidence of their implementation.
The training is particularly relevant for NIS2 Lead Implementers, CISOs and Information Security Officers, risk and compliance professionals, consultants, auditors, and other professionals involved in the implementation, assessment, or monitoring of cybersecurity measures.
GDPR
Protecting personal data and demonstrating accountability
The General Data Protection Regulation (GDPR) remains one of the foundations of European digital governance.
Organizations processing personal data must be able to demonstrate that personal information is processed lawfully, transparently and securely. GDPR therefore reaches far beyond privacy statements and consent mechanisms.
Effective data protection requires governance, clearly defined responsibilities, risk assessment, appropriate technical and organizational measures and ongoing monitoring of compliance.
GDPR Foundation
The GDPR Foundation training introduces participants to the fundamental principles and requirements of European data protection.
It is suitable for professionals who work with personal data or who need to understand how GDPR affects their organization.
Certified Data Protection Officer
For professionals with greater responsibility for privacy and compliance, the Certified Data Protection Officer training provides the knowledge needed to support, advise and monitor organizations regarding GDPR compliance.
It is particularly relevant for Data Protection Officers, privacy professionals, compliance professionals, legal professionals and consultants.
One regulatory landscape. Multiple responsibilities.
NIS2, DORA, GDPR, the EU AI Act and national implementations such as the Dutch Cyberbeveiligingswet or CyberFundamentals address different risks, sectors and technologies. But they increasingly share common principles.
Governance. Accountability. Risk management. Resilience. Transparency. Documentation. Continuous improvement.
Organizations therefore benefit from looking beyond individual regulations.
Cybersecurity cannot be managed independently from operational resilience. Privacy increasingly intersects with artificial intelligence. AI governance depends on data governance. And across these frameworks, management is expected to understand risks and demonstrate that appropriate controls are in place.
Developing the right knowledge and competencies is therefore becoming an essential part of modern governance.
Build your EU governance expertise
NIS Institute provides training for professionals who need to understand, implement and manage European regulatory requirements.



