GCSI — Global Cyber Standards Institute, official PECB Partner, Luxembourg.
Regulatory Compliance (NIS2, DORA)
NIS2 extends direct cybersecurity accountability to the governing bodies of operators of essential and important services. DORA imposes digital operational resilience requirements on financial entities and their ICT third-party providers, supervised in Luxembourg by the CSSF. Both regulations share the same underlying demand as every framework in this catalogue: not just compliance on paper, but demonstrable, auditable competence.
Why this matters for your organization
Board & executive leadership
NIS2 is explicit and unusual in this respect: it extends personal accountability for cybersecurity risk management directly to management bodies, including potential liability. Board members named as accountable under NIS2 or DORA need to be able to demonstrate they understood what they were accountable for.
Risk, compliance & data protection functions
For compliance functions inside financial entities specifically, DORA’s ICT risk management framework, incident reporting and third-party risk requirements are not optional guidance — they are supervisory expectations enforced by the CSSF, with specific documented processes required.
Operational & technical specialists
For the specialists managing ICT risk and incident response day to day, both regulations require documented, testable processes — this is where the gap most often appears between what an organization believes it does and what it can actually evidence under supervisory review.
Certifications offered
NIS 2 Directive
Cybersecurity risk-management obligations for operators of essential and important services under the EU’s NIS 2 Directive.
- NIS 2 Directive Foundation (2 days) — fundamental concepts and requirements of the NIS 2 Directive.
- NIS 2 Directive Lead Implementer (5 days incl. exam) — plan and implement a cybersecurity program compliant with NIS 2, including risk, controls, incident and crisis management. Self-study option available →
DORA — Digital Operational Resilience Act
Digital operational resilience obligations for financial entities and their ICT third-party providers, supervised in Luxembourg by the CSSF.
- DORA Foundation (2 days) — fundamental concepts and requirements of an ICT risk management framework under DORA.
- DORA Lead Manager (5 days incl. exam) — a structured, operational approach to implementing DORA requirements: ICT risk and incident management, third-party risk, testing, and continuous improvement.
Delivered live online. Includes the PECB certification exam and a structured exam preparation approach.
