
— NIS2 COMPLIANCE · 2026
NIS2 requires training.
Not just awareness.
NIS2 (EU 2022/2555) asks essential and important entities to prove real cybersecurity capability — trained people, tested response, and evidence to show for it. Here's where we help.
DIRECTIVE (EU) 2022/2555 · IN FORCE SINCE JANUARY 2023
— THE NIS2 DIRECTIVE · EU 2022/2555
What NIS2 requires of your organisation
In force since January 2023 (transposition due October 2024), it strengthens governance, risk-management and cybersecurity-capability obligations right across the EU — raising the bar from awareness to demonstrable, tested capability.
NIS2 Article 20
Governance
Management bodies must approve and oversee risk-management measures — and follow training themselves to gain the knowledge to identify risks and judge whether controls actually work.
NIS2 Article 21
Technical & operational measures
Cyber hygiene and training, incident handling, crisis management, vulnerability handling, supply-chain security — and assessing the effectiveness of all of it.
NIS2 is broad — governance, risk, supply chain, reporting. We don't sell you a policy binder. We close the part you can't buy off a shelf: people who can do the job, exercises that prove they can, and evidence an auditor will accept.
// SECTORS COVERED BY NIS2 IN THE EU
Energy · Transport · Banking · Health · Water · Digital infrastructure · ICT services · Public administration · Space · Postal services · Waste management · Chemicals · Food · Manufacturing · Digital suppliers · Research
Awareness training alone won't meet NIS2
NIS2 expects capability you can show — built, tested, and measured. That takes three things working together.
— HOW WE HELP
Three ways to build NIS2 capability
01 · Build it
Training
Hands-on Cyberium Arena programs — from all-staff security awareness to expert incident response, forensics, security testing and OT/ICS. Participants run real commands and resolve real incidents, not multiple-choice tests.
Answers Art 21: cyber hygiene & training, incident handling, vulnerability handling
Explore training ↗
02 · Prove it
City & Guilds certifications
Selected programs carry City & Guilds Assured certification. Every credential is verifiable individually through its own City & Guilds URL — proof of competence you can hand to an auditor or customer.
Answers Art 21: verifiable evidence of competence
​
03 · Test & assess it
Specto+
Beyond training: Specto+ runs SOC drills for your responders and an AI-led tabletop for your leadership — each scored, each grounded in your real posture. Deployed inside your own network.
​
Answers Art 21 (assess effectiveness) + Art 20 (management training)
— NIS2 → PRACTICAL TRAINING
Every NIS2 requirement matched to a hands-on training program
Mapped from what each program actually teaches — not its title. 100% practical: real terminals, real malware, scenarios drawn from real attacks.
CYBERIUM ARENA PROGRAMS
NIS2 REQUIREMENT
XE100 Security Awareness
Security awareness — all staff
Article 21 — basic cyber hygiene & training (+ enabling MFA)
XE107 Web App Fundamentals
Cyber & secure-dev foundations
Article 21 — training; XE107 → secure development
NX224 AI Security
Detection & incident response
Article 21 — incident handling
Digital forensics & evidence
Article 21 — incident handling / investigation
ZX305 Network Security
ZX331 Exploit Development
ZX327 Linux Offensive
Security testing & vulnerability handling
Article 21 — vulnerability handling & testing
CX401 Intro to ICS/SCADA
CX410 OT/ICS Security Assessment
OT / ICS security
Critical-infrastructure sectors (energy, water, transport…)
NX214 OSINT
​
Threat intelligence
Supports Article 21 — risk analysis
Shown above are the NIS2 requirements training can address. Governance-only measures (supply-chain, MFA, asset-management policy) sit outside training — we won't pretend otherwise.
— BEYOND TRAINING
Test your NIS2 readiness with Specto+
Training builds the skills; Specto+ tests them and proves readiness — the part NIS2 calls "assessing effectiveness," plus the leadership training Article 20 asks of management. It's our internal-network defence command centre, deployed as a virtual appliance inside your own environment.
And because Specto+ runs inside your own environment, your network data never leaves it — the evidence that proves your compliance stays under your control.
— ONGOING READINESS
Continuous NIS2 compliance — build, prove, drill, then drill again
Build.
Hands-on training builds real capability — from all-staff awareness to expert red-team.
Prove.
City & Guilds certifications evidence competence, individually verifiable.
Drill.
Run a Specto+ SOC drill or leadership tabletop — it scores how your team actually responds.
Repeat.
Run the same drill again after training. The change in score is the improvement — and your Article 21 "assess effectiveness" evidence. That's exactly what the drills are for.
— PREPARATION ASSESSMENT
Does your organisation meet
NIS2 training requirements?
Do your SOC analysts train with real incident scenarios?
1.
When was the last practical cyber exercise completed by your team?
2.
Can you provide verifiable evidence of your team's competence to an auditor or customer?
3.
Do you currently have visibility into threats and malicious activity on your network?
4.
Request a free NIS2 briefing
We will show you how your organisation can strengthen its readiness for NIS2-related requirements through practical training, verifiable certifications, and continuous capability improvement — using the same infrastructure trusted by CERT-IL, Microsoft, Israeli Police, and academies in 15+ countries.
Using the same infrastructure trusted by CERT-IL, Microsoft, Israeli Police, and academies in 15+ countries.
MSPs & IT consultancies
Co-sell NIS2 training alongside your compliance services. Add certified cyber training to your offer.
CO-SELL WITH US →
Training centers & academies
Deliver NIS2 training to your corporate clients. White-label Cyberium Arena and build a new revenue stream.
BECOME A PARTNER →
— OTHER PATHS
Not a CISO? There's a path for you too.
