Training
Cyber hygiene and risk management, for every level of the company
Most incidents that hit SMEs exploit nothing sophisticated: poorly managed accounts, unpatched systems and a convincing message that someone opened. That is what these three courses are about.
Cyber hygiene and risk for management
from €950 · 3 hours
Cybersecurity risk as a matter of decision, not a technical subject.
Cyber hygiene and risk management for technical teams
from €1,800 · 7 hours
The practices that stop most incidents, and the evidence the law requires.
Cyber hygiene for employees
from €650 · 2 hours
Two hours that change the behaviour of whoever sits at the computer.
All three together, from €2,800, instead of €3,400. VAT not included, priced per session and not per participant. Each session takes up to 10 participants (20 for the employee training); larger groups run as additional sessions.
How it runs
Closed training, about your company
Remote and live
By video call, with a trainer present and room for questions. No travel and no logistics costs, anywhere in the country.
Closed group, your company only
Nobody from outside in the room. That makes it possible to discuss the company's real situation, including what is not yet resolved, with no exposure at all.
A record that counts as evidence
At the end, everyone who attended is recorded. That record is exactly the evidence the verification criterion of the QNRCS training control asks for.
Why this counts
Training is not just good practice, it is a required measure
Decree-Law 125/2025 expressly names cyber hygiene and training among the areas that risk management measures must cover, alongside incident handling, business continuity, supply chain security and access control.
And it places on the management body the obligation, which cannot be delegated, of ensuring regular cybersecurity training for itself and for employees.
In the QNRCS, training appears under the Protect objective from the Basic level onwards, and its verification criterion asks for what any audit will ask for: a training record. That is why each of these sessions ends with a record of who attended, ready to enter the platform as evidence.
A note of honesty, because the whole site is built this way: training covers one control, out of 43 minimum measures at the Basic level alone. It is a necessary piece, not the whole of compliance. To find out where your company stands, the diagnosis is the starting point.
Frequently asked questions
About the courses
Is cybersecurity training mandatory?
Decree-Law 125/2025 determines that the management body ensures regular cybersecurity training, for itself and for employees. "Cyber hygiene and training" is, in fact, one of the areas expressly named among the risk management measures. On top of that, training is a QNRCS control present from the Basic level onwards.
Is the certificate officially recognised?
NIS2PME issues a participation certificate. It serves as a training record for evidence purposes, exactly what the law and the QNRCS ask for, but it is not a professional certification nor training certified by the Portuguese DGERT, and therefore it is not eligible for the Cheque-Formação scheme.
Can we book only one of the three?
You can. All three are independent and solve different problems. Booked together they cost less than the sum of the parts, but there is no obligation to take them all.
What if we are more people than the session limit?
You run more than one session, each with its own fee. The limit is not commercial: above 10 participants (20, for the employee training) there is no room left for questions or for discussing the company's actual situation, and the session loses what makes it useful. A company of 40 runs two employee sessions, not one session with 40 silent people.
Who delivers the training?
Daniel Barreiros, author of the NIS2PME platform, with experience in auditing and in training teams. The training is designed and delivered by NIS2PME.
Does training alone make the company compliant?
No, and it is worth saying so plainly. Training is one control among the 43 minimum measures required at the Basic level alone: a necessary piece, not the whole of compliance. To find out where the company stands, the starting point is the diagnosis.
Want to train your team?
State how many people you have and which course interests you. You get a fixed written quote, with no commitment.