Cybersecurity Legal Framework in force since 3 April 2026. Fines of up to €10 million or 2% of annual global turnoverThe transition period ends in April 2027.

NIS2 Training

Understand What the Law Requires and Where to Start: Aligned with Decreto-Lei 125/2025 e ao regulamento.

7H

of live online training with practical case studies

8

structured modules 

300€

per participant,

with discounts available for groups

+600

Strongstep client organisations

Strongstep has already helped organisations across these sectors through its NIS2 training

Banking and Financial Services Information Technology Healthcare Chemical Industry Public Administration

This NIS2 Training Is for You If You Are...

Board Members and Senior Executives

Article 25 places direct responsibility on you and requires regular cybersecurity training. Understand what you must approve, what you are expected to oversee, and what cannot be delegated.

Compliance Officers and Data Protection Officers (DPOs)

Understand what Decree-Law No. 125/2025 adds to your existing GDPR obligations, and where the two legal frameworks overlap rather than simply adding new requirements.

IT Directors and Managers

Learn what the legal framework requires from an operational perspective and identify which requirements are already covered by your existing cybersecurity practices before committing additional budget.

CISOs and Information Security Managers

You need to translate mandatory requirements into defensible priorities and present them to the Board in a way that supports informed decision-making.

Procurement and Supplier Management Professionals

Your supply chain is now a legal responsibility. Learn what contractual requirements you must impose, on whom, and what to do when suppliers fail to respond.

Suppliers to Organisations Subject to NIS2

You may not be directly in scope, but your clients are, and they will expect evidence of your compliance. Prepare now before losing contracts because you cannot meet their requirements.

Full Programme

8 Modules in the NIS2 Training Course

7 Hours of live online training
Certificate of participation
Follow-up Support Q&A session after the training
1

Introduction: Why NIS2 Exists and What It Means for Your Organisation

The essential starting point for those who need to make informed decisions, not simply comply with the law.

50 min
+
  • The objectives of NIS2: What the legislation is really designed to achieve, and why
  • The benefits of implementation: What your organisation gains beyond avoiding regulatory fines
✔ By the end of this module, you will understand the rationale behind the legal framework and be able to explain internally why acting now is worthwhile.
2

The Legal Framework: Understanding the Requirements That Apply to Your Organisation

Three different legal instruments, one clear set of obligations you need to understand.

55 min
+
  • NIS2: The purpose of the Directive and the rationale behind the European legislation
  • CNCS Regulation No. 756/2026: What it is, what it covers, and how to use the MyCiber platform
  • The National Cybersecurity Strategy: The wider context in which the legislation operates
  • The key question: What compliance obligations does your organisation actually have?
✔ By the end of this module, you will have a clear understanding of the specific obligations that apply to your organisation, rather than relying on isolated interpretations of legal texts.
3

Governance and Accountability: What Senior Management Cannot Delegate

NIS2 places personal responsibility on those in leadership positions. This module explains what that means in practice.

50 min
+
  • How senior management is expected to be involved, and where that involvement becomes mandatory
  • The evidence management must be able to demonstrate to prove it has fulfilled its responsibilities
  • The requirement for ongoing cybersecurity training for members of the governing body
✔ By the end of this module, you will know what the Board must approve, oversee, and be able to demonstrate if called upon to account for its decisions.
4

Risk Management and Secure Architecture: From Legal Requirements to Practical Implementation

Where the requirements of the legal framework are translated into concrete decisions about your organisation's systems.

55 min
+
  • Risk management methodology: Identifying critical assets, essential services, and key suppliers
  • Threat modelling: How to systematically anticipate where your organisation is most vulnerable to cyber attacks
  • Defining risk-based technical controls: Implementing security measures that are proportionate to the actual level of risk, without overinvesting or leaving critical gaps
✔ By the end of this module, you will be able to translate legal requirements into practical technical measures tailored to your organisation's specific risk profile.
5

Secure Operations, Security Operations Centre (SOC) and Monitoring: Demonstrating Continuous Oversight

Compliance is not a static document, it requires continuous monitoring that you must be able to demonstrate.

55 min
+
  • Continuous monitoring: What needs to be monitored and why
  • Event detection and correlation: How to identify genuine security incidents among the constant flow of events
✔ By the end of this module, you will understand what needs to be monitored, how to recognise a security incident, and when to escalate it to the appropriate teams or specialists.
6

Incident Management and Business Continuity: You Have Hours, Not Days

When an incident occurs, there is no time to decide what to do. This module ensures those decisions have already been made.

55 min
+
  • What is a security incident?
  • What NIS2 defines as a significant incident: The events that trigger mandatory reporting obligations
  • Incident notification: What must be reported, to whom, and within which deadlines
  • Business continuity: How to ensure your organisation remains operational during and after an incident
✔ By the end of this module, you will have a clear understanding of the processes for incident classification, notification, and business continuity—before you need to put them into practice.
7

Supply Chain and Cloud Security: The Risk You Do Not Control but Are Still Responsible For

To the regulator, the weakest link in your supply chain is still your responsibility.

45 min
+
  • Technical assessment of critical suppliers: What to evaluate before placing your trust in them
  • Security requirements in contractual agreements: What you must require in writing
  • Monitoring critical dependencies: Including the cloud services your organisation relies on
✔ By the end of this module, you will have clear criteria for assessing suppliers and understand the contractual security requirements you should insist upon.
8

Continuous Compliance, Evidence and Penalties: Preparing for Regulatory Oversight

Compliance is demonstrated through consistently maintained evidence, not by good intentions on the day of an audit.

55 min
+
  • Preparing for CNCS audits and inspections: What the supervisory authority will expect to see
  • Ongoing collection of evidence: What should be documented over time and how to organise it effectively
  • The penalties regime: What non-compliance can mean for your organisation, including the personal liability of senior management
✔ By the end of this module, you will understand your organisation's actual level of exposure and the evidence you need to have in place before the CNCS comes knocking.

NEXT SESSION

Your opportunity is scheduled

To ensure a highly interactive learning experience and dedicated attention for every participant, we run one cohort at a time.

24

September 2026

Thursday · 10:00 AM – 6:00 PM

Live Online Training 

The Strongstep approach to professional training

Small cohorts, maximum engagement We deliberately keep our training groups small, giving every participant the opportunity to ask questions, discuss their organisation's specific challenges, and leave with practical, actionable guidance.
Real Implementation Case Studies Our examples come from real-world DORA implementation projects, not academic scenarios. They reflect the same operational and regulatory challenges faced by organisations like yours.
Practitioners Who Implement, Not Just Teach Our trainers are actively involved in DORA implementation projects across a wide range of organisations. What they teach is based on hands-on experience, not theory.
Post-Training Support The most important questions often arise once you return to work. That's why you'll have 30 days of access to your trainer, ensuring you receive practical guidance on the challenges you encounter in your day-to-day role.
What Our Participants Say
This knowledge will be directly applicable to my future work.
Carla B.
Quality, Environment & Health and Safety Manager
I found the training extremely interesting and highly valuable for my future within the company. The topics were presented in a clear, engaging, and dynamic way.
Ana C.
Test Engineer
Training Investment

VAT at the prevailing legal rate applies. For payment terms or any questions regarding registration, please contact us at geral@strongstep.pt

Frequently Asked Questions about the NIS2 Training

Does NIS2 apply to my organisation?

It depends on your sector, the size of your organisation, and the type of services you provide. Decree-Law No. 125/2025 distinguishes between essential entities, important entities, and relevant public entities, with different requirements applying to each category. The first module is dedicated to helping you determine where your organisation fits. If you would prefer to clarify this before enrolling, simply let us know using the enquiry form.

Is the certificate accredited or recognised by an external body?
The certificate is issued by Strongstep as a Certificate of Participation. It is not a professionally accredited certification; rather, it confirms that you have completed a cybersecurity training course relevant to the training obligations established under the legal framework for members of management bodies and employees.
 
We are already certified to ISO/IEC 27001. Is this training still relevant for us?

Yes—and probably even more so than for organisations starting from scratch. While an Information Security Management System based on ISO 27001 already addresses many of the mandatory requirements, it does not cover them all, and the NIS2 legal framework requires evidence that the standard alone does not provide. Throughout the technical modules, you will learn where ISO 27001 already supports compliance, where the gaps remain, and how to avoid duplicating effort or assuming a level of compliance that does not actually exist.

Does this training guarantee that our organisation will be compliant?

No, and you should be cautious of anyone who claims that a training course alone can guarantee compliance. Compliance is achieved through the implementation and ongoing documentation of appropriate measures over time. This training provides you with a comprehensive understanding of your legal obligations, the criteria for prioritising them, and a practical framework for implementing the necessary actions in the right order.

What if we need support with NIS2 implementation after the training?

Strongstep supports organisations with NIS2 implementation projects and preparation for regulatory supervision. If you require further assistance, simply indicate this on the registration form, and we will discuss your requirements separately, with no obligation and independently of your training enrolment.

Registration

Other Trainings

ISO 27001 Foundation

Duration: 16h

Make your registration

LEARN MORE

ISO 27001 Lead Auditor

Duration: 16h

Make your registration

LEARN MORE

Accelerate RGPD with ISO 27001

Duration: 16h

Make your registration

LEARN MORE

GDPR

Duration: 4 hours

Make your registration

LEARN MORE