top of page

— NIS2 COMPLIANCE · 2026

NIS2 requires training.
Not just awareness.

NIS2 (EU 2022/2555) asks essential and important entities to prove real cybersecurity capability — trained people, tested response, and evidence to show for it. Here's where we help.

DIRECTIVE (EU) 2022/2555 · IN FORCE SINCE JANUARY 2023 

— THE NIS2 DIRECTIVE  · EU 2022/2555

What NIS2 requires of your organisation

In force since January 2023 (transposition due October 2024), it strengthens governance, risk-management and cybersecurity-capability obligations right across the EU — raising the bar from awareness to demonstrable, tested capability.

NIS2 Article 20 
Governance

Management bodies must approve and oversee risk-management measures — and follow training themselves to gain the knowledge to identify risks and judge whether controls actually work.

NIS2 Article 21 
Technical & operational measures

Cyber hygiene and training, incident handling, crisis management, vulnerability handling, supply-chain security — and assessing the effectiveness of all of it.

   

NIS2 is broad — governance, risk, supply chain, reporting. We don't sell you a policy binder. We close the part you can't buy off a shelf: people who can do the job, exercises that prove they can, and evidence an auditor will accept.

// SECTORS COVERED BY NIS2 IN THE EU

Energy · Transport · Banking · Health · Water · Digital infrastructure · ICT services · Public administration · Space · Postal services · Waste management · Chemicals · Food · Manufacturing · Digital suppliers · Research

Awareness training alone won't meet NIS2

NIS2 expects capability you can show — built, tested, and measured. That takes three things working together.

— HOW WE HELP

Three ways to build NIS2 capability

01 · Build it

Training 
  

Hands-on Cyberium Arena programs — from all-staff security awareness to expert incident response, forensics, security testing and OT/ICS. Participants run real commands and resolve real incidents, not multiple-choice tests.

Answers Art 21: cyber hygiene & training, incident handling, vulnerability handling

02 · Prove it

City & Guilds certifications

Selected programs carry City & Guilds Assured certification. Every credential is verifiable individually through its own City & Guilds URL — proof of competence you can hand to an auditor or customer.

 

Answers Art 21: verifiable evidence of competence

​

03 · Test & assess it

Specto+
   

Beyond training: Specto+ runs SOC drills for your responders and an AI-led tabletop for your leadership — each scored, each grounded in your real posture. Deployed inside your own network.

​

Answers Art 21 (assess effectiveness) + Art 20 (management training)

— NIS2 → PRACTICAL TRAINING

Every NIS2 requirement matched to a hands-on training program

Mapped from what each program actually teaches — not its title. 100% practical: real terminals, real malware, scenarios drawn from real attacks.

CYBERIUM ARENA PROGRAMS

NIS2 REQUIREMENT

XE100 Security Awareness

Security awareness — all staff

Article 21 — basic cyber hygiene & training (+ enabling MFA)

Cyber & secure-dev foundations

Article 21 — training; XE107 → secure development

NX224 AI Security

Detection & incident response

Article 21 — incident handling

NX215 Linux Forensics

NX216 Network Forensics

NX232 Malware Analysis

Digital forensics & evidence

Article 21 — incident handling / investigation

ZX305 Network Security

ZX331 Exploit Development

ZX327 Linux Offensive

Security testing & vulnerability handling

Article 21 — vulnerability handling & testing

CX401 Intro to ICS/SCADA

CX410 OT/ICS Security Assessment

OT / ICS security

Critical-infrastructure sectors (energy, water, transport…)

NX214 OSINT

​

Threat intelligence

Supports Article 21 — risk analysis

Shown above are the NIS2 requirements training can address. Governance-only measures (supply-chain, MFA, asset-management policy) sit outside training — we won't pretend otherwise.

— BEYOND TRAINING

Test your NIS2 readiness with Specto+

Training builds the skills; Specto+ tests them and proves readiness — the part NIS2 calls "assessing effectiveness," plus the leadership training Article 20 asks of management. It's our internal-network defence command centre, deployed as a virtual appliance inside your own environment.

Article 21 — assess effectiveness

SOC drills

Put your responders through a real incident — recon → analysis → response — and score how they did. Repeatable evidence that your defences actually work.

Article 20 — management training

Executive Readiness tabletop

An AI-guided crisis exercise for your leadership, grounded in your real posture, ending in a scored readiness report you can show an auditor.

And because Specto+ runs inside your own environment, your network data never leaves it — the evidence that proves your compliance stays under your control.

— ONGOING READINESS

Continuous NIS2 compliance — build, prove, drill, then drill again

Build.

Hands-on training builds real capability — from all-staff awareness to expert red-team.

Prove.

City & Guilds certifications evidence competence, individually verifiable.

Drill.

Run a Specto+ SOC drill or leadership tabletop — it scores how your team actually responds.

Repeat.

Run the same drill again after training. The change in score is the improvement — and your Article 21 "assess effectiveness" evidence. That's exactly what the drills are for.

— PREPARATION ASSESSMENT

Does your organisation meet
NIS2 training requirements?

Do your SOC analysts train with real incident scenarios?

   1.

When was the last practical cyber exercise completed by your team?

   2.

Can you provide verifiable evidence of your team's competence to an auditor or customer?

   3.

Do you currently have visibility into threats and malicious activity on your network?

   4.

Request a free NIS2 briefing

We will show you how your organisation can strengthen its readiness for NIS2-related requirements through practical training, verifiable certifications, and continuous capability improvement — using the same infrastructure trusted by CERT-IL, Microsoft, Israeli Police, and academies in 15+ countries.

Using the same infrastructure trusted by CERT-ILMicrosoftIsraeli Police, and academies in 15+ countries.

MSPs & IT consultancies

Co-sell NIS2 training alongside your compliance services. Add certified cyber training to your offer.

CO-SELL WITH US →

Training centers & academies

Deliver NIS2 training to your corporate clients. White-label Cyberium Arena and build a new revenue stream.

BECOME A PARTNER →

— OTHER PATHS

Not a CISO? There's a path for you too.

bottom of page