Standards & regulation

ISO 27001, NIS2 and DORA: employee training requirements

ISO 27001, NIS2 and DORA all require employees to receive regular information security training, and the organisation to prove it. ShieldWise covers the training part: courses, phishing simulations, completion history and certificates for the auditor.

  • ISO 27001 control A.6.3: awareness, education and training
  • NIS2 Article 20: training for management and staff
  • DORA: ICT security awareness programmes
  • Completion history and certificates in one tab

Updated:

ISO 27001: control A.6.3

Annex A control 6.3 of ISO/IEC 27001:2022 requires personnel to receive appropriate information security awareness, education and training, with regular updates. The auditor asks for evidence: who completed what, on which topics and when. Other controls, such as clear desk (A.7.7), also depend on employee behaviour.

NIS2 and DORA

Article 20 of the EU NIS2 Directive requires the management of essential and important entities to follow training themselves and to encourage regular training for employees. DORA, the Digital Operational Resilience Act, requires ICT security awareness programmes and training for all staff in the financial sector.

This matters to Georgian companies serving EU customers or partners: an EU customer asks its suppliers for the same level of training.

What ShieldWise gives the audit

For the training part, the platform produces the evidence an auditor asks for:

  • Who completed which course, when and with what score
  • Phishing simulation results and their change over time
  • Certificates with public verification
  • Overdue training and reminder history

What training does not cover

Training is one part of ISO 27001 or NIS2, not the whole system. Risk assessment, policies, access control and incident management are separate work. ShieldWise covers the human factor and the training evidence.

Related courses

All courses β†’

Frequently asked questions

Is ShieldWise enough for ISO 27001 certification?

No. Training is one requirement of the standard (A.6.3). ShieldWise covers that part and produces the evidence; the rest of the information security management system is built by the organisation.

Does NIS2 apply to Georgian companies?

NIS2 applies directly to entities operating in the EU. It reaches a Georgian company when an EU customer or partner requires the same standard from its suppliers.

How often should training be refreshed for ISO 27001?

The standard asks for regular updates. In practice auditors expect every employee to train at least once a year, and new starters during onboarding.

Terms on this topic

More topics

Start with your team's risk baseline

15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.