EU Cyber Regulation: NIS2 & DORA
Turn the EU's tightening cyber rulebook into a scope decision, a control set, and a defensible plan.
Tuition
$399
Intermediate
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
5 hours
Estimated time
What you will be able to do
- You will be able to describe how NIS2, DORA, GDPR, and related EU instruments fit together and explain why directives and regulations bind organizations differently.
- You will be able to classify an organization as an essential entity, an important entity, or out of scope under NIS2 using the size-cap and sector rules.
- You will be able to list the core NIS2 risk-management obligations and explain the personal accountability NIS2 places on management bodies.
- You will be able to determine whether an organization is a financial entity in scope of DORA and identify its ICT third-party and critical-provider obligations.
- You will be able to walk the NIS2 24-hour / 72-hour / one-month reporting timeline and the DORA major-incident reporting flow, and tell the two apart.
- You will be able to map NIS2 and DORA requirements onto ISO 27001 Annex A controls and identify the genuine gaps an ISMS does not already cover.
- You will be able to draft a phased EU cyber compliance plan with a gap assessment, ownership, and evidence that would withstand a competent authority's review.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
The EU Cyber Landscape and NIS2 Scope
Before any control matters you have to know which instrument binds you and how. This module maps the EU regulatory landscape and then pins down exactly who NIS2 covers and at what tier.
2 lessons · 5 quiz questions
- 02
NIS2 Obligations and Management Liability
Knowing you are in scope is only the start. This module covers the concrete risk-management measures NIS2 requires and the personal accountability it places on senior management.
2 lessons · 5 quiz questions · assignment
- 03
DORA Scope and ICT Third-Party Risk
DORA is the financial sector's resilience regime. This module pins down who counts as a financial entity, the resilience pillars DORA mandates, and its distinctive rules for ICT third-party and critical providers.
2 lessons · 5 quiz questions
- 04
Incident Reporting, ISO 27001 Overlap, and the Compliance Plan
This module compares the incident-reporting clocks under NIS2 and DORA, shows how an ISO 27001 ISMS maps onto both regimes, and walks through building a phased, defensible compliance plan.
2 lessons · 5 quiz questions · assignment