Cyberact
Guides
What NIS2, the EU AI Act, the Cyber Resilience Act and GDPR expect of your people's competence, and how to show it.
Security awareness training for employees: what EU law requires
What NIS2, GDPR, the EU AI Act and ISO 27001 expect of staff security training, what the training should cover and how to keep a record an auditor accepts.
Updated
NIS2 training requirements: what the Directive asks of staff and management
What the NIS2 Directive (EU) 2022/2555 requires on cybersecurity training for staff and the management body, who is in scope in any EU country, and how to evidence it.
Updated
AI literacy under Article 4 of the EU AI Act
The Digital Omnibus rewrote Article 4 of the EU AI Act in July 2026. What supporting AI literacy now requires, who it covers in any EU country and how it is supervised.
Updated
Cyber Resilience Act (CRA): a practical guide
The EU Cyber Resilience Act (CRA) in practice: who it covers, 24-hour reporting since 11 September 2026, Annex I, fines and what to do before December 2027.
Updated
NIS2 training requirements in Finland
Finland's Cybersecurity Act 124/2025 makes cybersecurity training part of risk management. Who is in scope, what the Act requires and how to evidence it.
Updated