CAREER PATH · 6 courses
Cybersecurity GRC & Compliance Specialist
Move into cybersecurity through governance, risk and compliance: turn standards and regulations like ISO/IEC 27001 and NIS2 into controls, evidence and decisions. No hacking, no technical background needed.
About 6 months, up to two courses at a time. 6 courses, 36 live one-on-one sessions, 54 hours with your trainers.
The job
A GRC and compliance specialist helps an organisation protect what matters and prove it. They map assets and risks, choose and document the controls, check which rules apply, from ISO/IEC 27001 to NIS2 and DORA, build the policies and the evidence, assess suppliers, and audit whether controls really work. More and more, they also cover the organisation's AI uses. They work with IT, legal, procurement and management, and turn requirements into work people can do.
Why now
The EU NIS2 directive widens cybersecurity obligations to many more organisations, and each country applies it through its own law. In France, that law is still being debated in Parliament (October 2026); organisations that will be in scope are preparing now, with ANSSI's ReCyF framework as the reference. DORA already applies to the financial sector since January 2025, and the Cyber Resilience Act's reporting duties for digital products since September 2026. Organisations need people who can turn these rules into controls, evidence and decisions. This path is built for people switching into that role from audit, risk, IT, legal, quality or project work.
France's cybersecurity agency says NIS2 concerns thousands of entities that matter in citizens' daily lives.
Source: ANSSI, La directive NIS 2 · 2026The NIS2 directive asks each EU country to require the management bodies of organisations in scope to approve the cybersecurity risk-management measures, oversee them, and follow training. In France, this will apply once the transposing law is adopted.
Source: Directive (EU) 2022/2555 (NIS 2), article 20 · 2022
The journey
STAGE 1 · FOUNDATIONS
Security & Risk Fundamentals
STAGE 2 · STANDARDS AND REGULATIONS
ISO 27001 in Practice
NIS2, DORA & Cyber Resilience Act in Practice
Both courses run at the same time.
STAGE 3 · SUPPLIERS AND INCIDENTS
Third-Party & Supply-Chain Risk
Incident Response & Crisis Management
Both courses run at the same time.
STAGE 4 · AUDIT AND GOVERNANCE
Audit, Evidence & AI Governance
Who it's for
- Auditors, risk managers and internal control professionals moving into cybersecurity
- IT people who want to move from running systems to governing their security
- Legal, compliance, data protection and quality professionals asked to cover cybersecurity or NIS2
- Project managers and consultants who want to lead security and compliance programmes
Before you start
At least two years of professional experience in any field, ideally in audit, risk, IT, legal, quality or projects. No technical security background and no coding are needed: this is governance, not hacking. A real or realistic organisation to work on during the courses is strongly recommended.
What you'll be able to do
- Map assets, threats and controls, run a risk assessment and keep a risk register
- Build the core of an ISO/IEC 27001 management system: scope, risk method, Statement of Applicability and policies
- Check NIS2, DORA and Cyber Resilience Act scope, assess the gaps and turn them into a 12-month roadmap management can back
- Manage supplier and software supply-chain risk: tiering, due diligence, contract clauses and vulnerability handling
- Lead the response to a security incident: playbooks, crisis cell, notification clocks and a tabletop exercise
- Audit controls and AI governance with clear criteria, real evidence and findings people act on
Certificates
A certificate of completion for each course, and a path certificate, “Cybersecurity GRC & Compliance Specialist”, once all six courses are done. This is practical training, not an official certification such as ISO/IEC 27001 Lead Implementer or Lead Auditor, and Dymensionz is not a certification body.
Questions
How long does the path take?
About 6 months, taking up to two courses at a time. You can also go one course at a time, which takes longer.
Do I need a technical or security background?
No. The path is about governance, risk and compliance, not hacking. It starts from the basics and builds on the experience you already have in audit, risk, IT, legal, quality or projects.
Is this an official certification?
No. You receive certificates of completion from Dymensionz, which is not a certification body. The path prepares the practical work; if you want an official certification later, the courses help you understand what it covers.
Do I have to take all six courses?
The path is one package. If you already master one of its subjects, tell us during the intro call and we will look at it together.
Can I take a break?
Yes, between two courses. Inside a course, the usual session rules apply.
In which language?
English or French, chosen at the start for the whole path: sessions, documents and certificates.
Will this get me a job?
Nobody can honestly promise that. The path builds the skills employers ask for today, and leaves you with a portfolio you can show.