The European training architecture for NIS2 Article 20, the German BSI Act and KRITIS, and the Swiss Information Security Act. Made in Switzerland, by practitioners.
CIRP, the Critical Infrastructure Resilience Professional certification, is Resilience Guard Academy's answer to the training obligation that now sits in European law: three professional tiers train the leaders, the implementers and the workforce specialists, and the Workforce Awareness Programme trains everyone else.
The European cyber resilience landscape changed materially in 2023 and 2024. The NIS2 Directive imposes binding cybersecurity obligations on tens of thousands of essential and important entities across the European Union. The German BSI Act and the KRITIS regime extend that picture in Germany. The Swiss Information Security Act, in force since the beginning of 2024, places parallel obligations on the operators of Swiss critical infrastructure. DORA and the Critical Entities Resilience Directive complete the picture for financial entities and for physical resilience.
Across these regimes one rule cuts through: training for the management body, and similar training for employees, is no longer good practice. It is the law. NIS2 Article 20(2) requires the members of management bodies to follow training, and in Germany the BSI Act makes personal liability explicit. For senior leaders, training is not a procurement item to be delegated. It is a personal compliance matter.
CIRP is independently mapped to six recognised frameworks: the ENISA European Cybersecurity Skills Framework, the ISC2 CISSP Common Body of Knowledge, the ISACA domains, the IAPP continuing privacy education scheme, the BCI Good Practice Guidelines Edition 7.0 and the DRI International Professional Practices. The mapping documents are available on request.
CIRP complements rather than replaces the established credentials. The established certifications are global and framework led; CIRP is built specifically around the European regulatory regime, by practitioners who advise on these obligations daily. Structured learning hours, 8 for Foundation, 16 for Advanced and 24 for Expert, may be self reported under each body's continuing development scheme. CIRP is not endorsed, approved or accredited by ENISA or by the European Union; the ECSF mapping is a legitimate use of the EU's own skills taxonomy with source attribution.
English is the default delivery language, with German, French, Italian and Greek available for in house cohorts and through accredited training partners. In house cohorts are most cost effective at 8 to 15 participants, require a minimum of 4, and can be delivered at your site anywhere in Switzerland, the EU and the UAE.
Training providers can join the Authorised Training Provider scheme, with standard, master partner, train the trainer and white label arrangements available. Express interest through the contact form and the Academy responds within five working days.
CIRP is the Critical Infrastructure Resilience Professional certification. The P stands for Professional, the standing the certification establishes for its holder. Three levels, CIRP-F, CIRP-A and CIRP-E, address Foundation, Advanced and Expert competence.
CIRP-F Foundation is for managers, compliance staff, internal audit and board secretaries new to the regulatory landscape. CIRP-A Advanced is for ISMS or BCMS leads, programme managers and CISO reports who implement controls. CIRP-E Expert is for CISOs, senior compliance and board advisors, and includes content on personal liability under the German BSI Act.
The established credentials are global and framework led. CIRP is built specifically around the European regulatory regime and is created by practitioners who advise on these obligations daily. It complements rather than replaces the established credentials, and is independently mapped to the ISC2 CISSP CBK and the ISACA domains.
Yes, under each body's self reporting policy. A CIRP holder may record the structured learning hours, 8 for Foundation, 16 for Advanced and 24 for Expert, under the relevant continuing development scheme. Resilience Guard Academy is not an accredited provider of those bodies; recognition operates through each member's self reporting.
Yes. In house cohorts are typically priced at approximately 55 percent of the equivalent public per delegate price, are most cost effective at 8 to 15 participants per cohort, and require a minimum of 4 participants. They can be delivered at the client's site anywhere in Switzerland, the EU and the UAE.
The two programmes complement each other rather than compete. DRI accredited courses focus on the discipline of business continuity management. CIRP addresses critical infrastructure resilience under the European regulatory regime, integrating business continuity with cybersecurity, regulatory compliance and crisis management. Many professionals hold both. See our DRI accredited training.
A three level pathway on the proprietary 7A framework, from Foundation through Professional to the governed Lead and Assessor scheme.
The global gold standard in business continuity education, delivered by an exclusive accredited DRI International provider.
DRI's CRLE 2000, Cyber Resilience for the Business Continuity Professional, integrating cyber security and continuity across five elements.
DRI's seminal 4.5 day course on all ten Professional Practices, the foundation of a defensible continuity programme.
Our proprietary gamified crisis decision exercise: 72 cards, six functions, one cascading ransomware crisis, ninety minutes.
One intensive, practitioner led day that prepares boards and executives to lead through a serious crisis, anchored on ISO 22361.
Tabletop exercises, functional and cyber crisis exercises and full scale rehearsals: the exercise programme that proves your plans and evidences ISO 22301, NIS2 and DORA.
DRI's two day IT Disaster Recovery Planning workshop: project plan, risk and BIA for IT, strategy, plans and new DR technologies.
Board level crisis simulations that place your leadership team inside a realistic, escalating disruption, scored and debriefed.
Training and accreditation for global consulting teams, trusted by three of the world's four largest professional services networks.
Whether you are a professional considering the certification, an organisation meeting an NIS2, KRITIS or ISG training obligation, or a training provider exploring partnership, the first step is a conversation. We respond within one working day.
Book a consultation