Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
CIRP Professional Certification, Critical Infrastructure Resilience | Resilience Guard
Resilience Guard Academy

CIRP, the certification for critical infrastructure resilience.

The European training architecture for NIS2 Article 20, the German BSI Act and KRITIS, and the Swiss Information Security Act. Made in Switzerland, by practitioners.

Why it exists

Training is no longer optional

CIRP, the Critical Infrastructure Resilience Professional certification, is Resilience Guard Academy's answer to the training obligation that now sits in European law: three professional tiers train the leaders, the implementers and the workforce specialists, and the Workforce Awareness Programme trains everyone else.

The European cyber resilience landscape changed materially in 2023 and 2024. The NIS2 Directive imposes binding cybersecurity obligations on tens of thousands of essential and important entities across the European Union. The German BSI Act and the KRITIS regime extend that picture in Germany. The Swiss Information Security Act, in force since the beginning of 2024, places parallel obligations on the operators of Swiss critical infrastructure. DORA and the Critical Entities Resilience Directive complete the picture for financial entities and for physical resilience.

Across these regimes one rule cuts through: training for the management body, and similar training for employees, is no longer good practice. It is the law. NIS2 Article 20(2) requires the members of management bodies to follow training, and in Germany the BSI Act makes personal liability explicit. For senior leaders, training is not a procurement item to be delegated. It is a personal compliance matter.

Tiers
CIRP-F, CIRP-A, CIRP-E
Plus
Workforce Awareness
Included
Manual, self assessment, exam
Certificate
Resilience Guard Academy
CIRP-E Expert3 days, 24 hours, senior leadersCIRP-A Advanced2 days, 16 hours, implementersCIRP-F Foundation1 day, 8 hours, managers and assuranceCIRP Workforce Awareness ProgrammeRegular training for everyone else, as the regulations expectMapped to NIS2 Article 20, the German BSI Act and KRITIS, the Swiss ISG, DORA and CER
The CIRP architecture: three professional tiers on a workforce foundation, mapped to the European regulatory regime.
The tiers

Three levels, one certification programme

CIRP-F Foundation, 1 day, 8 hours. The starting point for managers, compliance staff, internal audit, board secretaries and others new to the regulatory landscape. Covers the directives, the obligations, the language, and the elements of a resilience programme. Includes the 80 page reference manual, the self assessment tool and the one hour examination.
CIRP-A Advanced, 2 days, 16 hours. For ISMS or BCMS leads, programme managers and CISO reports, the people who actually implement the controls. Moves from understanding the obligations to building and operating the programme that satisfies them.
CIRP-E Expert, 3 days, 24 hours. For CISOs, senior compliance and board advisors, including content on personal liability under the German BSI Act. The tier for those who carry the accountability the regulations create.
CIRP Workforce Awareness Programme. Regular, structured awareness training for the wider workforce, answering the second half of the NIS2 Article 20 obligation: similar training for employees, on a regular basis.
Recognition

Mapped to the frameworks the profession already trusts

CIRP is independently mapped to six recognised frameworks: the ENISA European Cybersecurity Skills Framework, the ISC2 CISSP Common Body of Knowledge, the ISACA domains, the IAPP continuing privacy education scheme, the BCI Good Practice Guidelines Edition 7.0 and the DRI International Professional Practices. The mapping documents are available on request.

CIRP complements rather than replaces the established credentials. The established certifications are global and framework led; CIRP is built specifically around the European regulatory regime, by practitioners who advise on these obligations daily. Structured learning hours, 8 for Foundation, 16 for Advanced and 24 for Expert, may be self reported under each body's continuing development scheme. CIRP is not endorsed, approved or accredited by ENISA or by the European Union; the ECSF mapping is a legitimate use of the EU's own skills taxonomy with source attribution.

Delivery

Public, in house and through partners

English is the default delivery language, with German, French, Italian and Greek available for in house cohorts and through accredited training partners. In house cohorts are most cost effective at 8 to 15 participants, require a minimum of 4, and can be delivered at your site anywhere in Switzerland, the EU and the UAE.

Training providers can join the Authorised Training Provider scheme, with standard, master partner, train the trainer and white label arrangements available. Express interest through the contact form and the Academy responds within five working days.

Questions

Frequently asked questions

What does CIRP stand for?+

CIRP is the Critical Infrastructure Resilience Professional certification. The P stands for Professional, the standing the certification establishes for its holder. Three levels, CIRP-F, CIRP-A and CIRP-E, address Foundation, Advanced and Expert competence.

Who is each CIRP tier for?+

CIRP-F Foundation is for managers, compliance staff, internal audit and board secretaries new to the regulatory landscape. CIRP-A Advanced is for ISMS or BCMS leads, programme managers and CISO reports who implement controls. CIRP-E Expert is for CISOs, senior compliance and board advisors, and includes content on personal liability under the German BSI Act.

How is CIRP different from CISSP, CISM or an ISO lead implementer certification?+

The established credentials are global and framework led. CIRP is built specifically around the European regulatory regime and is created by practitioners who advise on these obligations daily. It complements rather than replaces the established credentials, and is independently mapped to the ISC2 CISSP CBK and the ISACA domains.

Does CIRP count for CPE or CPD with ISC2, ISACA, BCI or DRI?+

Yes, under each body's self reporting policy. A CIRP holder may record the structured learning hours, 8 for Foundation, 16 for Advanced and 24 for Expert, under the relevant continuing development scheme. Resilience Guard Academy is not an accredited provider of those bodies; recognition operates through each member's self reporting.

Can CIRP be delivered in house?+

Yes. In house cohorts are typically priced at approximately 55 percent of the equivalent public per delegate price, are most cost effective at 8 to 15 participants per cohort, and require a minimum of 4 participants. They can be delivered at the client's site anywhere in Switzerland, the EU and the UAE.

How does CIRP compare to DRI International's accredited training?+

The two programmes complement each other rather than compete. DRI accredited courses focus on the discipline of business continuity management. CIRP addresses critical infrastructure resilience under the European regulatory regime, integrating business continuity with cybersecurity, regulatory compliance and crisis management. Many professionals hold both. See our DRI accredited training.

Explore further

Related programmes

Professional Certification

7A Risk Management Framework Training and Certification

A three level pathway on the proprietary 7A framework, from Foundation through Professional to the governed Lead and Assessor scheme.

Explore the programme ›
Professional Certification

DRI Accredited Training

The global gold standard in business continuity education, delivered by an exclusive accredited DRI International provider.

Explore the programme ›
Professional Certification

CRLE 2000 Cyber Resilience Training

DRI's CRLE 2000, Cyber Resilience for the Business Continuity Professional, integrating cyber security and continuity across five elements.

Explore the programme ›
Professional Certification

BCLE 2000 Business Continuity Training

DRI's seminal 4.5 day course on all ten Professional Practices, the foundation of a defensible continuity programme.

Explore the programme ›
Simulations and Exercises

Operation HELVETIA

Our proprietary gamified crisis decision exercise: 72 cards, six functions, one cascading ransomware crisis, ninety minutes.

Explore the programme ›
Executive and Masterclass

Crisis Management Masterclass

One intensive, practitioner led day that prepares boards and executives to lead through a serious crisis, anchored on ISO 22361.

Explore the programme ›
Simulations and Exercises

Crisis Management Exercises

Tabletop exercises, functional and cyber crisis exercises and full scale rehearsals: the exercise programme that proves your plans and evidences ISO 22301, NIS2 and DORA.

Explore the programme ›
Professional Certification

BCP IT/DR Workshop

DRI's two day IT Disaster Recovery Planning workshop: project plan, risk and BIA for IT, strategy, plans and new DR technologies.

Explore the programme ›
Simulations and Exercises

Top-Team Exercises

Board level crisis simulations that place your leadership team inside a realistic, escalating disruption, scored and debriefed.

Explore the programme ›
Executive and Masterclass

Executive Training for Advisory Firms

Training and accreditation for global consulting teams, trusted by three of the world's four largest professional services networks.

Explore the programme ›
Next step

Start the CIRP conversation.

Whether you are a professional considering the certification, an organisation meeting an NIS2, KRITIS or ISG training obligation, or a training provider exploring partnership, the first step is a conversation. We respond within one working day.

Book a consultation
All consultations are treated with strict confidentiality.