ISO 27001, NIS2 and DORA: employee training requirements
ISO 27001, NIS2 and DORA all require employees to receive regular information security training, and the organisation to prove it. ShieldWise covers the training part: courses, phishing simulations, completion history and certificates for the auditor.
- ISO 27001 control A.6.3: awareness, education and training
- NIS2 Article 20: training for management and staff
- DORA: ICT security awareness programmes
- Completion history and certificates in one tab
Updated:
ISO 27001: control A.6.3
Annex A control 6.3 of ISO/IEC 27001:2022 requires personnel to receive appropriate information security awareness, education and training, with regular updates. The auditor asks for evidence: who completed what, on which topics and when. Other controls, such as clear desk (A.7.7), also depend on employee behaviour.
NIS2 and DORA
Article 20 of the EU NIS2 Directive requires the management of essential and important entities to follow training themselves and to encourage regular training for employees. DORA, the Digital Operational Resilience Act, requires ICT security awareness programmes and training for all staff in the financial sector.
This matters to Georgian companies serving EU customers or partners: an EU customer asks its suppliers for the same level of training.
What ShieldWise gives the audit
For the training part, the platform produces the evidence an auditor asks for:
- Who completed which course, when and with what score
- Phishing simulation results and their change over time
- Certificates with public verification
- Overdue training and reminder history
What training does not cover
Training is one part of ISO 27001 or NIS2, not the whole system. Risk assessment, policies, access control and incident management are separate work. ShieldWise covers the human factor and the training evidence.
Related courses
- CourseIdentifying phishingThe phishing foundation course: how to spot a fake email, sender and link, and what to do when something looks off.
- CourseEmail threatsPhishing, dangerous attachments and financial fraud by email, with practical examples and an exercise.
- CourseLink safetyHow to read a link before clicking, spot a spoofed domain and avoid landing on a phishing page.
- CourseFake meeting invitesFake Zoom and Teams invites, vishing and deepfakes: how attackers use a meeting as the pretext for access.
- CourseVishing: voice phishingCalls "from the bank" and "from IT", caller ID spoofing and pressure tactics. How to hang up and verify.
- CourseSmishing: SMS fraudFake parcel, bank and fine notifications. The signs of smishing and four golden rules.
- CourseQR code safety (quishing)How QR codes are used for fraud and how to check one before and after scanning.
- CourseMalicious attachmentsDisguised file types, the psychological tricks that push you to open them, and the rule "verify before you open".
- CourseCorporate email securityAnatomy of a dangerous email, phishing, BEC and malware, and rules for using work email safely.
- CourseBEC & CEO fraudThe most expensive email attack: the fake CEO, the changed bank account and the transfer. The rule "verify, don't trust".
- SimulationFake login page detectorSimulation: practise telling real and fake login pages apart.
- SimulationSMS fraud simulationSimulation: judge incoming text messages and spot the scams.
Frequently asked questions
Is ShieldWise enough for ISO 27001 certification?
No. Training is one requirement of the standard (A.6.3). ShieldWise covers that part and produces the evidence; the rest of the information security management system is built by the organisation.
Does NIS2 apply to Georgian companies?
NIS2 applies directly to entities operating in the EU. It reaches a Georgian company when an EU customer or partner requires the same standard from its suppliers.
How often should training be refreshed for ISO 27001?
The standard asks for regular updates. In practice auditors expect every employee to train at least once a year, and new starters during onboarding.
Terms on this topic
More topics
Start with your team's risk baseline
15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.