What has to be evidenced is not the training. It is the competence.
The frameworks do not ask for an attendance list. They ask for proof that the person can do what their job requires. Our units are built around that.
Three levels that often get mixed up
Treating all three alike trains too many people too shallowly, and the decisive ones too little.
- Awareness for everyoneShort, concrete, recurring: handling credentials, spotting phishing, how to report a suspicion, using devices away from the office. Half an hour that everyone needs.
- Specialist training for the people who own the workFor those with particular duties: risk methodology, evidence handling, internal audit, incident handling, vendor assessment. Cut to each framework.
- Management bodiesExplicitly required under NIS2 and not delegable. Content: management duties, approving and overseeing the measures, personal liability, reporting deadlines, and what is expected of management when something happens.
Units per framework
- ISO/IEC 27001 — the people who own the work. Structure of the standard, scope, risk methodology, Statement of Applicability, types of evidence, how stage 1 and stage 2 run.
- ISO 9001 — the people who own the work. Process orientation without a mandatory manual, metrics and effectiveness, corrective actions, a combined audit with ISO 27001.
- NIS2 — management and the people who own the work. Whether you are in scope and how you are classified, the ten measures, reporting deadlines from 24 hours to one month, management approval.
- DORA — the people who own the work. The seven areas, classifying major incidents, the register of information, the testing programme and when TLPT actually applies.
- All frameworks — all staff. Awareness: credentials, phishing, reporting routes, mobile working.
How we train
- On site or by video callCut to your framework and your scope, using your examples. Half a day or a full day, depending on the level.
- With evidence that counts in an auditAttendance, content, date and trainer are documented. Where competence is what matters, we add a short check — that is the difference between an attendance list and evidence.
- Separate from certificationWe advise and train; we do not certify. Under ISO/IEC 17021 a certification body may not do both, so you choose your body freely and independently of us.