Course types
Certikon offers both courses based on international ISO standards and courses developed by PECB's own experts. The two types of courses have different purposes but follow the same structures for training, examination, and certification.
ISO-based courses are founded on official standards published by the International Organization for Standardization (ISO), from which PECB has designed specific ISO-based courses. These courses are clearly identified by the fact that the course title always begins with ISO followed by the standard number, for example ISO/IEC 27001 Lead Implementer or ISO 9001 Lead Implementer. The ISO courses are therefore designed by PECB, but based on the ISO standards, and focus on requirements, principles, and methods that are internationally recognized and widely used in both private and public organizations.
PECB-developed courses, on the other hand, are based on PECB's own frameworks, models, and best practices, including internationally recognized frameworks and standards. They are not tied to a specific ISO standard and therefore do not have "ISO" in the title. Examples include courses such as PECB’s CISO, AI Risk Manager, risk management, governance, or other specialized areas where PECB has developed an independent competence framework. These courses often provide a more practical, role-based, or methodological approach that complements the ISO-based certifications. PECB courses may be based on ISO standards, but do not use them as their main structure.
Regardless of whether an ISO-based course or a PECB-developed course is chosen, all Certikon courses follow the same transparent structure from PECB.
Course levels
Certikon works with three core course levels based on the ISO standard and PECB’s course structure: Foundation, Manager and Implementer/Auditor. These levels are used consistently across both ISO‑based courses and PECB‑developed courses. PECB’s official course descriptions state a total duration, but this generally includes the exam time. To provide an accurate picture of the actual learning effort for the different courses, Certikon therefore distinguishes between training days, exam day and estimated self‑study time.
Foundation – the basic level
Foundation provides a solid basis for further learning and certification. The course typically consists of two days of classroom training and often concludes with an exam at the end of day two. Since the exam is not training time, it is not included in PECB’s estimated study time, which is estimated 12–16 hours. One should allocate some time for light exams preparation. Foundation is the natural starting point for participants who want a clear understanding of the core concepts and structure of a standard or framework.
Implementer/Manager – the practical and methodological level
Manager level courses normally comprise three days of training followed by a separate exam day. PECB describes these as “3‑day training + exam”. PECB only states the actual learning time, which typically ranges between 24 and 30 hours. The courses focus on the practical implementation, operation and improvement of management systems or frameworks and are aimed at specialists, project managers and function owners.
Implementer / Auditor – the advanced and responsibility‑bearing level
Implementer / Auditor courses consist of four days of intensive training and one exam day. PECB markets them as “5‑day courses”, but the actual learning effort lies in the four training days. Certikon therefore clearly distinguishes between training and exam and states an estimated learning time of 24–40 hours. Lead courses provide the deepest understanding of requirements, methods and governance principles and prepare participants to lead larger implementation or audit programmes.
Other course types and specialized programs
In addition to the three classic levels, Certikon also offers a range of specialized PECB courses that do not follow the Foundation‑Implementer‑Lead structure. These courses are developed by PECB’s own experts and cover areas where there is no official ISO standard, or where the market demands more role‑based competencies.
Examples include, among many others:
CISO courses focusing on leadership, governance, and security strategy
DORA courses covering the EU regulation on digital operational resilience
NIS2 courses addressing cybersecurity and risk management requirements in critical sectors
Governance and risk management courses based on PECB’s own frameworks
Specialized compliance and privacy courses that are not tied to an ISO standard
These courses have their own structures, but Certikon still applies the same principles of transparency: teaching days, exam day, and estimated learning effort are specified, so it is always clear how much time needs to be allocated.

