← All 186 courses
SEC-307 Security

NIS2 & DORA Compliance Engineering

Turn regulatory obligations into controls, pipelines and evidence that survive an examination. Learners map legal text to testable control statements, build an ICT third-party register that holds up under scrutiny, automate incident classification and reporting, and replace screenshot debt with evidence by query. The output is a gap assessment and remediation plan sequenced against real enforcement dates.

B4Professional
6modules
42skill atoms
2role journeys
Curriculum

What this course covers.

6 modules, 42 named skill atoms. Expand any module to see them.

1Obligation To Control Mapping7 skill atoms
parsing legal text into testable statementscontrol library designISO 27001 and NIST CSF crosswalksone control satisfying many obligationsRACI per controldefining evidence and test method up frontversioning as transpositions change
2ICT Third-Party Register7 skill atoms
DORA register of information fieldscriticality and substitutability assessmentcontractual audit, exit and subcontracting clausesfourth-party and concentration riskcontinuous vendor monitoring signalstesting exit plan feasibilityregister data quality and refresh cadence
3Incident Classification Pipeline7 skill atoms
significance criteria expressed as codeseverity triage decision treeclock start on detection, automaticallydeduplication across source systemsescalation to legal and regulator liaisonreport generation from case datacorrecting a misclassification after the fact
4Evidence Automation7 skill atoms
evidence by query against config and identity APIscontinuous control monitoringfreshness and coverage metricsimmutable timestamped storagepopulation completeness vs samplingalerting when the evidence pipeline failsretiring screenshot debt
5Resilience Testing Obligations7 skill atoms
scenario-based testing programmevulnerability assessment cadencethreat-led penetration testing scoping expectationsseparation of tester and defender rolesfindings to remediation trackingretest and closure evidencereporting outcomes to the authority
6Gap Assessment & Remediation7 skill atoms
structured gap workshop methodmaturity scoring that survives challengeremediation backlog with cost and ownersequencing against enforcement datesinterim compensating controlsdocumented residual risk acceptanceprogress reporting to the management body
Where it fits

SEC-307 in the role journeys.

This course appears in 2 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

DevSecOps Engineer

Professional stage
SEC-207SEC-307SEC-404

GRC / Compliance Analyst

Professional stage
SEC-505SEC-307SEC-506

Roles this course serves

The capability ladder

This course is authored to band B4.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-307 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free