SEC11NIS2 for Embedded
Objectives
|
- Theoretical course
- PDF material in English (printed for face-to-face); online over Teams.
- Trainer assistance throughout.
- Each session starts with a trainee check-in.
- Any embedded systems engineer or technician with the above prerequisites.
- Prerequisites are checked before the training.
- Progress is assessed by quizzes at the end of sections.
- Each trainee receives a completion certificate.
- If a prerequisite gap appears, alternative or additional training is offered.
Course Outline
- NIS2 at a glance
- Sectors in scope & “size-cap” rule
- Essential vs Important Entities (EEs vs IEs)
- Roles, authorities, penalties
- Management accountability
- Security policy & risk ownership
- Roles/RACI and coordination with product/OT teams
- Business continuity & incident handling
- Identity & Access and logging
- Vulnerability management & secure development
- OT/embedded specifics (segmentation, safety interplay)
- From requirements to release (Dev → Test → Release → Update)
- Secure updates & support periods (firmware/RTOS/toolchains)
- Vulnerability intake, triage, remediation, and user communication
- Evidence-by-design: what to capture during builds
- Triggers & thresholds (significant incidents)
- Timelines: 24h / 72h / 1-month reports
- Internal playbook, contacts, escalation
- Supplier due diligence & contractual expectations
- Updates, disclosure programs, and support commitments
- Evidence from vendors (SBOM/VEX, security posture)
- Registers: risks, incidents, assets, suppliers, training
- KPIs & dashboards for management
- Preparing for audits/inspections
- Quick wins
- Priority controls & contracts
- Exercises, metrics, internal audit
- Key takeaways
- Next steps & optional deep-dives (OT, IoT, CRA alignment)
More
To book a training session or for more information, please contact us on info@ac6-training.com.
Registrations are accepted till one week before the start date for scheduled classes. For late registrations, please consult us.
You can also fill and send us the registration form
This course can be provided either remotely, in our Paris training center or worldwide on your premises.
Scheduled classes are confirmed as soon as there is two confirmed bookings. Bookings are accepted until 1 week before the course start.
Last update of course schedule: 27 June 2026
Booking one of our trainings is subject to our General Terms of Sales
Related Courses
C1
Effective MISRA C
C2
MISRA Compliance for Project Managers
SEC1
Developing C/C++ Secure Embedded Systems
SEC10
Cyber Resilience Act (CRA) for Embedded Systems
SEC12
Comprehensive Secure Systems Programming
SEC2
Advanced Embedded Systems Security
SEC5
Embedded Security for STM32-based devices
SEC6
Embedded Security for NXP i.MX-based processors
SEC7
ARM TrustZone for Cortex-M based devices
SEC8
Secured Embedded Linux Platform Build
SEC9
Advanced Embedded Linux Security