NIS2 and DORA place the human factor at the centre of EU cybersecurity law. SecurityAwared helps your organisation meet the security awareness and cyber-hygiene training requirements of both frameworks with measurable, audit-ready programs.
NIS2 is EU Directive 2022/2555, the successor to the original NIS Directive. Member States were required to transpose it into national law by 17 October 2024, significantly widening the scope of European cybersecurity obligations across sectors.
The directive classifies organisations as "essential" or "important" entities and holds them to strict cyber risk-management standards. Article 20 makes management bodies directly accountable for approving and overseeing cybersecurity risk-management measures, while Article 21 requires baseline cyber-hygiene practices and security awareness training for staff.
Core obligations for the human factor
Article 20 — management bodies are accountable and must follow training
Article 21 — cyber-hygiene and regular security awareness training
Risk-management measures proportionate to the entity’s exposure
Incident reporting and supply-chain security expectations
DORA
What is DORA?
DORA is EU Regulation 2022/2554 on digital operational resilience for the financial sector. As a regulation it applies directly across all Member States from 17 January 2025, with no national transposition needed.
DORA requires financial entities to build a comprehensive ICT risk-management framework. A central pillar is the human element: firms must run ICT security awareness programs and digital operational resilience training for staff and, where relevant, management, so that people can recognise and respond to cyber threats.
Core obligations for the human factor
Mandatory ICT risk-management framework
Staff awareness programs and resilience training
Testing of digital operational resilience
Oversight of ICT third-party and supplier risk
Who Must Comply?
Between them, NIS2 and DORA reach a broad slice of the European economy — and the suppliers that serve it.
NIS2 — essential & important entities
Energy, transport, water and digital infrastructure
Healthcare, pharmaceuticals and manufacturing
Public administration and digital service providers
Postal services, waste management and food supply
Many suppliers and vendors inside these supply chains
DORA — the financial sector
Banks, credit institutions and payment providers
Insurers, reinsurers and investment firms
Fintech, crypto-asset service providers and exchanges
Critical ICT third-party providers to financial entities
Crowdfunding platforms and asset managers
If your organisation is unsure whether it qualifies as an essential or important entity, or as a critical supplier, our team can help you map your obligations.
How SecurityAwared Helps You Comply
We do not sell a certification — we help you meet the training and awareness requirements that NIS2 Article 21 and DORA place on your people, with evidence you can show an auditor.
01
Security Awareness Training
Structured, role-based courses that operationalise the cyber-hygiene and awareness requirements of NIS2 Article 21 and DORA’s ICT security awareness programs — delivered in the languages your workforce uses.
02
Phishing Simulation Campaigns
Realistic phishing simulations measure and reduce human risk over time, giving you concrete before-and-after metrics that demonstrate continuous improvement in staff resilience.
03
Management & Board Enablement
Focused modules help management bodies satisfy their NIS2 Article 20 accountability to understand, approve and oversee cybersecurity risk-management measures.
04
Audit-Ready Reporting
Completion records, scores and campaign analytics give you the documented evidence of ongoing security awareness that supervisors and auditors expect to see.
05
Mapped to the Requirements
Every course and campaign is aligned to the human-factor obligations of NIS2 and DORA, so your program has a clear line back to the regulation it supports.
06
Continuous Cyber-Hygiene
Scheduled, repeating training and simulations turn one-off compliance into the ongoing cyber-hygiene culture that both frameworks expect from essential and important entities.
SecurityAwared provides security awareness training and phishing simulation to help you meet the human-factor training requirements of NIS2 and DORA. This page is informational and is not legal advice; consult your compliance or legal team for a full assessment of your obligations.
Build Your NIS2 & DORA Awareness Program
Talk to our team about a security awareness training and phishing simulation program mapped to your NIS2 and DORA obligations.