Stage 3 · Ongoing Operations

Training & Awareness

Management training is mandatory under NIS2 — and must be documented.

Duration:3 hrs to 1 day per format
Price from:€890 excl. VAT
Enquirekontakt@maplee.de

from €890

excl. VAT · 3 hrs to 1 day per format

Get in touch

Training is required by almost every framework and is ticked off with minimal effort in almost every company. Yet understanding determines whether a process functions in an emergency — and with NIS2 there is the additional point that management training is explicitly mandatory and must be evidenced.

We train in a practical, scenario-based way, using your own topics, and issue certificates that hold up in an audit.

Who it's for

  • Executive management — fulfil and evidence the NIS2 training obligation
  • CISOs, compliance and IT security staff, and everyone who operates the ISMS
  • Key users who work daily with the ISMS in Jira and Confluence
  • All employees — the baseline that NIS2 and ISO 27001 both require

The situation

Under NIS2 management training is explicitly mandatory — annually, with a participation certificate. Auditors will ask for it, and the obligation applies regardless of whether anyone has checked compliance.

How it works

  1. 01

    Management training NIS2 — 3 hours

    For executive management, board, and leadership. Content: NIS2 obligations · personal liability · evidence requirements · ten measure areas · role in the incident-reporting process · realistic case studies. Output: participation certificate per person, training record, documented basis for approval. From €1,200 excl. VAT.

  2. 02

    ISMS & CISO training — 1 day

    For security officers and everyone who operates the ISMS. Content: ISO/IEC 27001:2022 · risk methodology · Annex A and SoA · effective measure management · evidence · audit situation. From €1,900 excl. VAT.

  3. 03

    ISMS app key-user training — half day, remote

    For everyone who works daily with the ISMS in Jira and Confluence. Content: module structure · maintaining risks, measures, and requirements · reports · review cycles · administration. From €890 excl. VAT.

  4. 04

    Awareness programme — over 12 months

    For all employees. Four sessions spread over the year, 45–60 minutes each: fundamentals · phishing and social engineering · handling data and AI · behaviour when something looks wrong. Optional short test for effectiveness measurement. From €2,400/year excl. VAT.

What you receive

ErgebnisForm
Participation certificate per personPDF
Training record with content, dates, and durationPDF
Slide deck for referencePDF
Practical guide for daily work (ISMS training)PDF
Quick reference for daily work (key-user training)PDF

Details

Formatremote or on-site in DACH; travel costs for on-site sessions on request
LanguageGerman or English
ParticipantsManagement and ISMS training up to 10 people, key-user up to 12, awareness unlimited
CertificatesParticipation certificate per person and training record always included
CombinationDiscount when booking multiple formats or as part of an implementation project

Not included

No accredited certification courses — we train for practice, not a personal certification exam. Also not included: phishing simulation campaigns (available with a partner on request), e-learning platforms, and technical implementation of security measures.

Frequently asked questions

Formally a certificate can be produced from that too. In practice a conversation delivers more: the relevant questions at leadership level are company-specific — which risk are we carrying right now, what do I need to sign off, where does my personal liability begin.

Interested? Get in touch.

We typically respond within one working day.

kontakt@maplee.de