Introduction
This operational guide provides a structured approach to onboarding a new business entity subject to NIS2/DORA requirements, dedicated to users with an MSP role.
NIS2/DORA reference material
All the material mentioned in this article is available within the Partner Portal.
Company creation
Access your MSP company, navigate to "Company Management" and click on "Add Company" to create the new company via the wizard.
Follow these recommendations:
WIZARD - "GENERAL INFORMATION" SECTION
Company name:
- For NIS 2/NIS 2 PA: Company name + NIS2 (example ACME - NIS2). No need to add "PA"
-
For DORA: Company name + DORA
-
The subdomain must follow one of the following formats (also for PA)
- Existing customer: sottodominioesistente-nis2.platform.cyberguru.eu or sottodominioesistente-dora.platform.cyberguru.eu
- New customer: use the domain provided by the customer → nomedominio-nis2.platform.cyberguru.eu or nomedominioesistente-dora.platform.cyberguru.eu
-
Note: the subdomain can only be modified once after creation
⚠️ Board Training Type: Indicate the company type among: NIS2, NIS2 PA and DORA. This option allows the correct graphic theme to be associated with the company and the correct paths to be displayed.
Adding supported languages and default language
Available languages for NIS 2
- Each country applies the NIS2 regulation according to its own national legislation. For this reason, within the platform, the regulation versions are localized in the official language of the country and in English. It is therefore important, when creating a new company, to support both the country's official language and English. In the case of Italian regulation, for example, you will need to set Italian and English as supported languages (and set Italian as the default language).
- Italian regulation is also available in German (the language is still in progress, so it is important to follow up on course assignment quarterly; in case of doubt contact Cyber Guru)
Regarding DORA, the only available language is ITALIAN (for English, ask Cyber Guru for more information)
For NIS 2 PA, the only available language is ITALIAN
WIZARD - "CUSTOMIZATION" SECTION
Logos
Upload the logo (if the customer already exists, use the one already available, otherwise have the customer provide it)
Colors
Set #121528 as the primary color. Enter the value in the dedicated field
WIZARD - "AUTHENTICATION" SECTION
Choose the authentication mode:
- SSO if the customer already exists and is already using SSO, they will need to create a new dedicated application.
- Hybrid (SSO and application credentials)
- Application credentials
USER PROVISIONING WIZARD + GAMIFICATION
- Select the manual upload mode for users.
- Leave gamification DISABLED
WIZARD - LICENSES
You need to create the licenses, always setting a duration of 12 months (or a multiple thereof)
The licenses are ONLY of the AWARENESS and CYBER ADVISOR type.
NOTE: The Cyber Advisor is able to reason on the NIS2 regulation documents, allowing users to ask not only technical questions, but also legal or organizational ones.
Confirm the entered settings and create the company.
COMPANY CONFIGURATION AFTER CREATION
Once the company has been created via the wizard, it will be necessary to proceed with
1. Welcome message customization
Customize the welcome message by entering the texts found in the Partner Portal.
2. Certificate customization (Background and Text)
- Change the background image, applying one consistent with the regulation.
- The background is applied automatically to all languages.
- Update the certificate text (the text is available in the Partner Portal.): 🔁 Note: The texts to use are identical for NIS 2 and NIS 2 PA. A different text is provided for DORA,
To enter the text:
Click on the "Content" section.
Delete the pre-existing text.
Paste the correct text in the default language
Then repeat the same operation for the enabled languages, using the corresponding text.
Click "Save" to make sure you don't lose the changes made.
Creating the Contact User
Create the contact person's user account, entering only the mandatory platform information and without assigning a license. The contact person must be assigned the role of company manager and student (if they will need to take the training)
Customizing Student Caring
- Enable events: First license association and Multiple Content.
- Customize the content with the texts according to the enabled languages (texts available on the Partner Portal)
- Customize the email subject
- This operation must be repeated for each enabled language (it +en)
Customize the Company Options
In the "Company Management > Options" section you need to
In the "Awareness" section
- Remove the mandatory video viewing requirement
- Enable alignment of new users with the release calendar
In the "Appearance" section
- Hide the sidebar
In the "Phishing" section
- Hide the "Phishing Mail"
In the "Gamification" section
- Hide Gamification for the company's students
- Disable Gamification at the company level
Click "SAVE" otherwise the changes made will be lost.
Associate the learning paths
Prerequisite: during company creation, the correct type of NIS 2 was selected (field Board Training Type).
First-year structure: 5 learning paths distributed quarterly.
Learning path names – NIS 2 (Italian regulation)
- Board Training - NIS2 - ITA (Q1)
- Quadro Normativo - ITA (Q1)
- Rischi Cyber - ITA (Q2)
- Attacchi Cyber - ITA (Q3)
- Casi Cyber - ITA (Q4)
Learning path names – NIS 2 PA (Italian regulation)
- PA Training - NIS2 - PA (Q1)
- Quadro Normativo - PA (Q1)
- Rischi Cyber - PA (Q2)
- Attacchi Cyber - PA (Q3)
- Casi Cyber - PA (Q4)
DORA learning path names
- DORA Training (Q1)
- Quadro Normativo - DORA (Q1)
- Rischi Cyber - DORA (Q2)
- Attacchi Cyber - DORA (Q3)
- Casi Cyber - DORA (Q4)
Second-year structure: 4 sections distributed quarterly
The second year (or level) instead provides 4 sections, released quarterly.
The sections are named as follows:
- Integrated Cyber Security (Q1 - year 2)
From Governance to AI (Q2 - year 2)
Casi Cyber II (Q3 - year 2)
Security Awareness (Q4 - year 2)
The section names are common to all three services (NIS 2 BT, NIS 2 PA and DORA), but are identified by the abbreviation of the relevant path (e.g. PA or DORA).
Learning path characteristics
- The first year must be completed before accessing the second (prerequisite between years)
- No prerequisite between the contents of a single path (free access, no set order).
- The learning paths are prerequisites for one another: complete the previous one to access the next.
- Certificate: enable on all learning paths
How to associate the learning paths
First Learning Path (Q1)
The first two learning paths (from the first quarter) must be immediately available to the contact person and board members, so the first learning path must be released with the following options
- Release all activities
- Enable certificate
- No prerequisites
- No preliminary learning path
- Associate with existing users
Second Learning Path (Q1)
Once the association of the first learning path is completed, you can associate the second learning path (still referring to the first quarter)
This learning path must also be associated using the same options indicated previously, setting the previous learning path as the prerequisite.
Subsequent Learning Paths (from Q2 onwards)
Starting from the second quarter, the releases of the learning paths must be scheduled on the calendar with a quarterly frequency. RELEASES WILL THEREFORE NOT BE INSTANT
When associating the learning paths after the first quarter:
- The learning paths will NOT be fully released at the time of association (--> the learning path is scheduled on the calendar)
- The learning paths must have the certificate enabled
- Have the previous learning path set as the prerequisite.
- The learning paths must be synchronized with the users and must not be made available instantly (but scheduled).
In the release calendar, it will be sufficient to set a single release every quarter to release the entire learning path.
This release will make all the activities available for that learning path (because they all have the same order ID).
Therefore, there must be a TOTAL of 3 releases scheduled on the calendar (covering the second, third and fourth quarters)!
How the second year is assigned
When associating the first section of the second year (e.g. Integrated Cyber Security — Q1, year 2), it is necessary to set as the prerequisite the last section of the first year, i.e. Casi Cyber (Q4, year 1).
This ensures continuity of the prerequisite structure between the two years: the user will only be able to access the second year's content after completing the entire first year.
Managing new users
Below are the operational instructions for managing users depending on the scenario in which they join the program.
- New user joining during the first year: the user aligns with the releases already made for the rest of the group via the checkbox checked during company setup "Align new users with the release calendar"
- Existing user moving to the second year. The user must have completed the first-year learning paths before accessing the second-year sections.
- New user joining directly in the second year The user will have access to both the first-year and second-year content. All available learning paths will be associated, respecting the expected prerequisite structure.
7. Sending the welcome email to the contact person
Send a confirmation email that the tenant setup is complete and that credentials are on their way.
An example email (to be customized according to the customer's specific details)
Subject: Activation of the Board Training path – NIS2 on Cyber Guru
Dear [Customer Name],
we are pleased to welcome you to the training path dedicated to the NIS2 Directive, delivered through the Cyber Guru platform. Shortly you will receive a communication from no-reply@cyberguru.eu, containing the credentials and the link to access the platform.
The service is already active. Please remember to also complete the acceptance of the Terms and Conditions, via the link included in the license certificate you received.
📌 Materials and support
Below you will find the instructions needed to compile and upload the list of board members within the platform, in order to correctly start the training path: Guide to creating the user list
📥 Next steps
We invite you to check that you have received the credentials and to log in to the platform, where you will find the first quarter's content available.
Attached you will find a draft communication plan that you can use to internally announce the program before uploading the users [ATTACHMENT]
If you have any needs or special requests, your Customer Success Manager, [CSM Name], will be available to provide extraordinary support.
[SIGNATURE]
8. Associate the license with the contact person and enable automatic license association
- After the notice email, associate the license with the contact person to trigger the sending of the welcome email.
- Enable automatic license association for future users.
9. Communication to board members
- The contact person sends the kick-off communication to board members (CEO and CISO drafts available in the Partner Portal, to be attached to the welcome email)
10. Uploading Users to the platform
- The MSP proceeds with uploading the users
- Users automatically receive the license (and the corresponding communication) and find the first two learning paths available.
- When users log in to the platform, they will find the first two learning paths available for use.