Training

Cyber hygiene and risk management, for every level of the company

Most incidents that hit SMEs exploit nothing sophisticated: poorly managed accounts, unpatched systems and a convincing message that someone opened. That is what these three courses are about.

How it runs

Closed training, about your company

Remote and live

By video call, with a trainer present and room for questions. No travel and no logistics costs, anywhere in the country.

Closed group, your company only

Nobody from outside in the room. That makes it possible to discuss the company's real situation, including what is not yet resolved, with no exposure at all.

A record that counts as evidence

At the end, everyone who attended is recorded. That record is exactly the evidence the verification criterion of the QNRCS training control asks for.

Why this counts

Training is not just good practice, it is a required measure

Decree-Law 125/2025 expressly names cyber hygiene and training among the areas that risk management measures must cover, alongside incident handling, business continuity, supply chain security and access control.

And it places on the management body the obligation, which cannot be delegated, of ensuring regular cybersecurity training for itself and for employees.

In the QNRCS, training appears under the Protect objective from the Basic level onwards, and its verification criterion asks for what any audit will ask for: a training record. That is why each of these sessions ends with a record of who attended, ready to enter the platform as evidence.

A note of honesty, because the whole site is built this way: training covers one control, out of 43 minimum measures at the Basic level alone. It is a necessary piece, not the whole of compliance. To find out where your company stands, the diagnosis is the starting point.

Frequently asked questions

About the courses

Is cybersecurity training mandatory?

Decree-Law 125/2025 determines that the management body ensures regular cybersecurity training, for itself and for employees. "Cyber hygiene and training" is, in fact, one of the areas expressly named among the risk management measures. On top of that, training is a QNRCS control present from the Basic level onwards.

Is the certificate officially recognised?

NIS2PME issues a participation certificate. It serves as a training record for evidence purposes, exactly what the law and the QNRCS ask for, but it is not a professional certification nor training certified by the Portuguese DGERT, and therefore it is not eligible for the Cheque-Formação scheme.

Can we book only one of the three?

You can. All three are independent and solve different problems. Booked together they cost less than the sum of the parts, but there is no obligation to take them all.

What if we are more people than the session limit?

You run more than one session, each with its own fee. The limit is not commercial: above 10 participants (20, for the employee training) there is no room left for questions or for discussing the company's actual situation, and the session loses what makes it useful. A company of 40 runs two employee sessions, not one session with 40 silent people.

Who delivers the training?

Daniel Barreiros, author of the NIS2PME platform, with experience in auditing and in training teams. The training is designed and delivered by NIS2PME.

Does training alone make the company compliant?

No, and it is worth saying so plainly. Training is one control among the 43 minimum measures required at the Basic level alone: a necessary piece, not the whole of compliance. To find out where the company stands, the starting point is the diagnosis.

Want to train your team?

State how many people you have and which course interests you. You get a fixed written quote, with no commitment.