Skip to main content
BLOG • 10 min read

The best cyber security certifications for the European market: what DORA, NIS2, the CRA and the UK TSA require

Choosing a cyber security certification for a team that operates under European regulation involves more than picking a well-known name. Search results tend to rank familiar credentials, but a team under DORA (the Digital Operational Resilience Act), the NIS2 Directive, the Cyber Resilience Act (CRA), or the UK's Telecommunications (Security) Act (TSA) faces a more specific question: how well a certification can prove capability, and to whom. Recognized theory credentials can clear hiring filters, but regulated industries can’t stop validation at general knowledge. They need evidence that a team can actually do the work.

European regulations don't generally require a named cybersecurity certification. They require organizations to demonstrate appropriate competence, training and capability. ENISA's ECSF provides a useful role-and-skills framework for deciding what that competence looks like; practical certifications can provide evidence that individuals have developed those skills.

TL; DR

  • For a team in an organization with compliance obligations under DORA, NIS2, the CRA, or the UK TSA, the certifications with the most impact will be those that prove capability with practical evidence.
  • These regulations are part of a larger shift towards requirements around training and competence. DORA Article 13(6) makes ICT security awareness and digital operational resilience training a compulsory module for all staff; NIS2 Article 20 requires management bodies to undergo cybersecurity training and holds them liable for the entity's risk-management measures; the CRA makes secure-by-design engineering a legal prerequisite for EU market access, raising the bar on developer competence; and the UK TSA requires that staff responsible for network security are suitably skilled and experienced.
  • ENISA, the EU Agency for Cybersecurity, defines the field through 12 professional role profiles and their competences, and notes that certification bodies have aligned their credentials to that framework.
  • TryHackMe's certifications are practical by design and map to what these regimes ask of a team, across the stack from Pre Security (SEC0) to AI Security (AI1). Its Security Analyst Level 1 (SAL1) was built with Accenture and Salesforce.

What should a cyber security certification prove for a regulated team?

For a team under European regulation, a cyber security certification tends to be most useful when it provides evidence of role-aligned capability. It helps to separate two things a certification can do: signal knowledge, and provide actual proof.

A recognized theoretical credential answers a hiring question, but that’s usually where its utility ends. It clears the applicant-tracking filter, reassures a non-technical stakeholder, and signals that someone has studied the field. Regulations ultimately require evidence of competence within specific roles and responsibilities, for example whether a hire can triage an alert in a security operations center (SOC), contain an intrusion, or escalate effectively to protect an organization.

What do European regulations require of cyber practitioners?

European security regulations is noticeably shifting towards demonstrable competence, and several of these instruments name training and skills as explicit duties. Four regulations, three from the EU and one from the UK, are helping reshape what a certification should assist organizations in evidencing.

DORA governs ICT risk across EU financial entities and has applied since 17 January 2025. The Digital Operational Resilience Act (Regulation (EU) 2022/2554) places explicit obligations on skills and training. Article 13(1) requires financial entities to have the capabilities and staff to gather and analyze information on vulnerabilities, threats, and cyber-attacks. Article 13(6) requires ICT security awareness and resilience training as "compulsory modules in their staff training schemes," for all employees and senior management. Entities identified as significant must also carry out threat-led penetration testing under Articles 26 and 27, which is a controlled exercise modeled on the tactics of real attackers against live systems. In practice, DORA expects practitioners who can analyze threats, who have been trained, and who can be tested against a realistic attack.

NIS2 extends similar expectations across the economy. The NIS2 Directive (Directive (EU) 2022/2555), with a transposition deadline of 17 October 2024, applies to essential and important entities, broadly the larger organizations across 18 sectors such as energy, transport, banking, health, and digital infrastructure. Article 20(2) requires the members of the management body to follow cyber security training to catch and prevent security gaps, and encourages entities to offer similar training to their employees. Article 20(1) makes those management bodies responsible for approving and overseeing the entity's cybersecurity measures, and allows their members to be held liable. Article 21 lists the risk-management measures entities must take, among them incident handling and "basic cyber hygiene practices and cybersecurity training." A national authority can ask to see the evidence during supervision.

The CRA works on the product rather than the person. The Cyber Resilience Act (Regulation (EU) 2024/2847) applies its reporting obligations from 11 September 2026 and its main obligations from 11 December 2027, and it covers products with digital elements, meaning the hardware and software placed on the EU market that connect to a device or a network. It does not explicitly mandate staff training, but by making security by design and vulnerability handling a condition of selling into Europe, it raises demand for the secure-development and vulnerability-handling skills the teams shipping those products need.

The UK TSA sits outside the EU framework following the UK's departure from the Union, so it is a UK regulation rather than a European one, though it applies a comparable logic. The Telecommunications (Security) Act 2021 amends the Communications Act 2003, and itsElectronic Communications (Security Measures) Regulations 2022 set out the skills duty directly. Regulation 13 requires providers to ensure that the responsible persons, meaning the staff a provider puts in charge of security measures, have "appropriate knowledge and skills to perform their responsibilities effectively," and are competent and resourced to carry them out. A companion measure requires providers to monitor and analyze access to the network's security-critical functions, the parts whose compromise would do the most harm. Ofcom enforces it and can impose significant financial penalties.

What does ENISA say about skills, and how does that relate to certifications?

ENISA frames cyber security competence around defined roles and their skills. The European Cybersecurity Skills Framework (ECSF), which ENISA describes as the EU reference point for defining and assessing relevant skills, organizes the field into 12 professional role profiles, each broken down into the tasks, competences, and knowledge that role requires.

ENISA has tied that framework to both regulation and credentials. It has mapped NIS2 obligations onto the role profilesso an organization can see which roles carry which duties, and it notes that "professional certifications bodies have aligned their credentials to the ECSF." The sequence is consistent: the regulations ask for competence tied to a role, ENISA defines the roles and the skills each one requires, and a certification is useful to the degree that it validates the skills a named role needs.

Read through that lens, TryHackMe's certifications correspond to specific ECSF role profiles rather than to a general idea of security knowledge:

  • SAL1 and SAL2 map to the Cyber Incident Responder profile, for which ENISA's crosswalk to the EU skills classification (ESCO) records SOC analyst as an alternative title; SAL2's forensics and investigation content extends into the Digital Forensics Investigator profile.
  • PT1 and WEB1 map to the Penetration Tester profile.
  • SEC0 and SEC1 build the foundations several profiles draw on, rather than a single role.
  • AI1 addresses the security of AI systems, an area the ECSF is being revised to reflect.

This is a correspondence by role and skill, but enables a team choose a credential by the ECSF role a person will fill and the duties NIS2 attaches to it. A credential chosen that way tends to carry a stronger regulatory and workforce-planning rationale.

How do TryHackMe certifications map to European regulatory requirements?

TryHackMe certifications map to these requirements by validating, in a live environment, the specific capabilities each of these regulations expects a team to demonstrate, from foundational training through SOC analysis, penetration testing, and AI security. A practical exam produces a record of what a person did rather than what they’ve read, and that record is closer to a work sample that an auditor, regulator, or hiring manager can inspect. It’s a stronger signal, and maps more clearly onto the regulatory duties above than a knowledge exam tends to.

The table below sets each regulatory provision against the capability it signals, and the TryHackMe certifications, paths, and tools that build it.

Regulation and provision What it asks of practitioners Relevant TryHackMe certifications, paths, and tools
DORA Art. 13(6): compulsory ICT security awareness and resilience training for all staff and senior management Role-based, evidenced security training for all staff SEC0 (Pre Security) and SEC1 (Cyber Security 101) for foundational, hands-on training; Cyber Security 101 path
DORA Art. 13(1): capabilities and staff to gather and analyze vulnerabilities, threats, and cyber-attacks Threat detection, triage, and incident analysis SAL1 and SAL2 (Security Analyst Level 1 and 2); the SOC Level 1 path; and the Threat Hunting Simulator
DORA Arts. 26 and 27: resilience testing, including threat-led penetration testing for significant entities Offensive testing against the organization's own systems PT1 (Jr Penetration Tester) and WEB1 (Web Application Pentester Level 1) for offensive testing; the Jr Penetration Tester path; plus tabletop and CTF-style readiness exercises
NIS2 Art. 20(2): management-body training; employee training encouraged; sufficient knowledge and skills Staff and leadership cyber literacy and role skills SEC1 foundational validation; role-aligned certs as evidence of ability
NIS2 Art. 21: incident handling; basic cyber hygiene and cybersecurity training Incident detection, handling, and SOC analysis SAL1 and SAL2; the SOC Level 1 path; and the SOC Simulator
CRA (Reg. 2024/2847): security by design and vulnerability handling for products with digital elements Secure development, vulnerability discovery and remediation WEB1 and PT1 for finding and remediating vulnerabilities; AI1 for AI product security
UK TSA, Reg. 13 of SI 2022/933: responsible persons with appropriate knowledge and skills; monitoring of security-critical functions Network security monitoring, analysis, and incident response SAL1 and SAL2 for monitoring and IR; PT1 for identifying and reducing risks

Several of these obligations are about exercising capability rather than holding a credential. DORA's resilience-testing pillar and NIS2's incident-handling measure both call for teams that can rehearse a response under pressure, beyond documentation. Alongside the certifications, TryHackMe supports this with hands-on environments: a SOC Simulator and a Threat Hunting Simulator for detection and investigation, and tabletop and capture-the-flag (CTF)-style readiness exercises that can be run at a regular cadence, so a team tests its response rather than only planning for it. The Cyber Resilience Act applies the same expectation across the product lifecycle, where engineering, DevOps, QA, and product roles need the secure-development and vulnerability-handling fluency the same hands-on content can build across experience levels.

These regulations also expect organizations to show their work. DORA's information-sharing pillar, and the supervision built into NIS2 and the TSA, rely on records that leadership and auditors can review. Management dashboards, completion tracking, and team leaderboards turn that training and testing into documented evidence of who has built which capability, which is the difference between planning for readiness and being able to demonstrate it.

It’s important to note thatTryHackMe does not replace compliance platforms, GRC (governance, risk, and compliance) tooling, or external auditors. It does, however, strengthen the human and operational capability layer those depend on. A certification or a completed exercise validates an individual's capability, but it does not, by itself, make an organization compliant with any of these instruments. Compliance depends on governance, documented measures, and testing at the organizational level, and a role-aligned, hands-on credential contributes the evidence of competence several of these regulations expect.

Because the certifications are practical, their preparation doubles as capability building. The SOC Level 1 path builds the triage, SIEM (security information and event management), and detection skills an analyst uses in day-to-day operations, the Jr Penetration Tester path covers web, network, and Active Directory testing end to end, and the full set is listed on the TryHackMe certifications page.

FAQ

Do DORA, NIS2, the CRA, or the UK TSA require a specific cyber security certification?

No. None of these instruments names a required certification. DORA (Regulation (EU) 2022/2554) requires financial entities to run compulsory ICT security training under Article 13(6) and to have staff who can analyze threats under Article 13(1). NIS2 (Directive (EU) 2022/2555) requires management-body training under Article 20(2) and lists cybersecurity training among risk-management measures under Article 21. The CRA (Regulation (EU) 2024/2847) sets product security requirements. The UK TSA's regulations require staff responsible for security to have appropriate knowledge and skills. Each raises the value of demonstrable, role-aligned capability rather than mandating a named credential.

Does DORA require staff training?

Yes. DORA Article 13(6) requires financial entities to develop ICT security awareness and digital operational resilience training as compulsory modules in their staff training schemes, applicable to all employees and senior management at a complexity matched to their roles. Article 13(1) separately requires the capabilities and staff to gather and analyze information on vulnerabilities, threats, and cyber-attacks, and entities identified as significant must carry out threat-led penetration testing against their own systems under Articles 26 and 27.

How does the UK Telecommunications (Security) Act relate to the EU regulations?

The UK Telecommunications (Security) Act 2021 is a UK regulation rather than an EU one, since the UK has left the European Union, though it follows a similar logic of demonstrable capability and evidence. It amends the Communications Act 2003, is detailed by the Electronic Communications (Security Measures) Regulations 2022 and a statutory Code of Practice, and is enforced by Ofcom. Regulation 13 requires the staff responsible for security measures to be competent, with the knowledge and skills their duties demand, which points to the same analyst and network-security competence the EU regulations expect.

What does ENISA's European Cybersecurity Skills Framework mean for choosing certifications?

ENISA's European Cybersecurity Skills Framework (ECSF) is the EU reference point for defining and assessing cyber security skills, and it describes the field through 12 professional role profiles, each with its own tasks, competences, and knowledge. ENISA notes that professional certification bodies have aligned their credentials to the framework. For a team, choosing certifications by the ECSF role a person will perform, and the skills that role requires, tends to give a stronger regulatory and workforce-planning rationale than choosing by name recognition.

Which TryHackMe certification fits a regulated European team?

The right TryHackMe certification depends on the role. SEC1 (Cyber Security 101) validates foundational skills that support the training DORA and NIS2 require. SAL1 and SAL2 (Security Analyst Level 1 and 2) validate SOC monitoring, incident handling, and investigation, which map to DORA's threat-analysis duty, NIS2's incident-handling measure, and the UK TSA's network-security competency. PT1 (Jr Penetration Tester) and WEB1 (Web Application Pentester Level 1) validate offensive testing relevant to DORA resilience testing and the CRA's vulnerability-handling requirement, and AI1 (AI Security Level 1) addresses securing AI systems.

Choosing well tends to come down to matching each credential to the capability a regulation asks a role to demonstrate, and holding evidence that stands up to inspection. Explore how role-mapped, hands-on certifications fit into your team's hiring, onboarding, and progression plans on TryHackMe for Business.

authorJoanna Duffy
Aug 14, 2026

Recommended

Get more insights, news, and assorted awesomeness around cyber training.

Join over 640 organisations upskilling their
workforce with TryHackMe