04Advanced level

Compliance and frameworks: NIS2, NIST CSF 2.0, CIS Controls v8.1, ISO/IEC 27001

The regulatory and methodological framework within which a defensible security programme is built. The path does not stop at describing the frameworks: it shows how they map onto each other and how they turn into verifiable evidence.

NIS2ACN basic specificationsNIST CSF 2.0ISO/IEC 27001

Enrol meI already have an account

8modules
35estimated hours
129test questions
8exercises
30questions in the final test

How it is delivered

Delivery
Entirely online and asynchronous, from any device: you study when you want, at your own pace.
Passing the tests
At least 70% correct answers; every answer comes with an explanation of why.
Attempts per test
Unlimited: the best attempt counts.
Time per test
25-30 minutes per test.
Progress
Tracked module by module: each module unlocks when you pass the test of the previous one.
On completion
A personal PDF certificate, with a unique verification code.
Length of access
You have 90 days from enrolment to complete the learning path. Once you complete it your access stays available with no expiry; if the deadline passes without the path being completed, the enrolment is suspended and the results you have already achieved stay on record.
Enrolment
With a personal key, after you have created your account.

The learning path in detail

Welcome. This path builds the regulatory and methodological framework of a defensible security programme: not only what NIS2, NIST CSF 2.0, the CIS Controls and ISO/IEC 27001 require, but how they map to one another and how they become evidence that stands up in front of an auditor. The underlying idea is that compliance is not a formality to be added to security, but the way of demonstrating it.

Path objectives

By the end of the path you will be able to:

  • establish whether and how your organisation falls under NIS2 and with which obligations (Modules 1 and 2)
  • use the NIST Cybersecurity Framework 2.0 as the lingua franca of the security programme (Module 3)
  • apply the CIS Controls v8.1 as a prioritised implementation route (Module 4)
  • understand how an ISO/IEC 27001:2022 management system works and what a certification body looks at (Module 5)
  • build an integrated programme with cross-mappings, avoiding doing the same work four times (Module 6)
  • prepare for and undergo an audit: evidence, non-conformities, continual improvement (Module 7)
  • implementing and governing the ACN basic specifications that apply to your entity qualification, with the evidence that demonstrates them and the deadlines that order them (Module 8)

Who it is for and prerequisites

IT and security managers, compliance managers, DPOs, internal auditors and anyone who has to answer security questionnaires from customers and lead firms. It is advisable to have taken the paths on fundamentals and on hygiene first: this path takes the concepts of risk, threat and control as given.

How it runs

The path runs entirely online, in asynchronous mode: you can study whenever you want, at your own pace, from any device. The total estimated duration is 35 hours, to be spread out within the completion deadline given further on.

Each module is organised into four lessons and two tests:

  1. Lesson. A reasoned treatment of the topic, with diagrams, examples and concrete cases.
  2. In depth. The updated regulatory and technical framework, with the deadlines that matter and references you can check at source.
  3. Real-world cases. What really happens in the market: documented episodes always read with the same grid, down to the control that would have broken the chain.
  4. In practice. What you do on Monday morning: procedures, checklists, ready-made templates and indicators to measure the result.
  5. Test. Closed answer questions on the whole module. Passing requires at least 70%; attempts are unlimited and the best mark counts. At the end of each attempt you get a precise explanation of every answer, including the correct ones.
  6. Exercise. A case to work through by deciding: every choice opens a different path and the outcome depends on what you chose, with an explanation of what would have happened otherwise. Marking is automatic and you can retake it as many times as you like.

Progression. The 8 modules are worked through in sequence: each module unlocks only after passing the previous module's test. The exercises don't block progress, but they are an integral part of the path and of the overall assessment.

Final test and certificate

Once you have passed the tests of all the modules, the final test is unlocked: 30 questions drawn at random from the topics of the whole path, with the same 70% threshold and unlimited attempts. On passing you obtain the path certificate, downloadable as a PDF, with a unique code that allows its authenticity to be verified.

Warning

The contents are up to date as at August 2026, are for training purposes and do not constitute legal advice. For the obligations that fall on your organisation always refer to the legislation in force and to internal legal support.

Support

In the Announcements forum you will find messages from the tutor. For questions about the content or the exercises, use the channels indicated by your training contact.

Programme

The modules are taken in sequence: each one opens when you pass the test of the previous one.

  1. Module 1

    NIS2: scope and regulated entities

    Directive (EU) 2022/2555 and its Italian transposition: sectors, the size criterion and its derogations, the distinction between essential and important entities, the calendar of ACN determinations and the cascade effect on suppliers.

    LessonLessonLessonLessonTest · 17 questionsExercise

  2. Module 2

    NIS2: risk management measures and reporting obligations

    The ten minimum measures of Art. 21 translated into controls and evidence, the direct responsibility of the management bodies, the penalty regime and the notification chain of 24 hours, 72 hours, one month.

    LessonLessonLessonLessonTest · 17 questionsExercise

  3. Module 3

    NIST Cybersecurity Framework 2.0

    The six functions GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER; current and target profiles as a work plan, maturity Tiers and use of the framework as a tool for dialogue with the top.

    LessonLessonLessonLessonTest · 16 questionsExercise

  4. Module 4

    CIS Controls v8.1

    The 18 Controls, the Safeguards and the three Implementation Groups: how to build a defensible roadmap starting from IG1, and how the mappings to NIST CSF 2.0 and ISO let you reuse the same evidence.

    LessonLessonLessonLessonTest · 16 questionsExercise

  5. Module 5

    ISO/IEC 27001:2022 and the management system

    The structure of the ISMS, mandatory clauses 4-10, Annex A with its 93 measures in four themes, the Statement of Applicability as the central document and the three-year certification cycle.

    LessonLessonLessonLessonTest · 17 questionsExercise

  6. Module 6

    Cross-mappings and integrated compliance programme

    How to make NIS2, ISO/IEC 27001, NIST CSF and CIS Controls live together without multiplying the work: the single control register, where CRA, DORA, the AI Act and Law 90/2024 fit, and the points where the mappings do not work.

    LessonLessonLessonLessonTest · 15 questionsExercise

  7. Module 7

    Audits, evidence and continual improvement

    What counts as evidence for an auditor, how to document a control, how to handle non-conformities and corrective actions by tracing back to the causes, and how to build indicators that trigger decisions.

    LessonLessonLessonLessonTest · 16 questionsExercise

  8. Module 8

    The ACN basic specifications for essential and important entities

    The basic specifications adopted by ACN: how they're structured, what distinguishes Annex 1 for important entities from Annex 2 for essential entities, how they map onto existing controls, which evidence holds up and how compliance is governed through the deadline and beyond.

    LessonLessonLessonLessonTest · 15 questionsExercise

  9. Final test and certificate

    Thirty questions drawn at random from the topics of all the modules. On passing, the path certificate is issued.

    Test · 30 questionsCertificate

How to get access to the learning path

To follow "Compliance and frameworks: NIS2, NIST CSF 2.0, CIS Controls v8.1, ISO/IEC 27001" you need an account on the platform: registration is free and takes a minute. Once the account is created you can request the enrolment key for the learning path.

Enrol meI already have an account

Back to all learning paths