EBIOS Risk Manager
Assess and treat digital risk with a top-down method built around business missions.
EBIOS Risk Manager: what it is and why it matters
EBIOS Risk Manager is a method to assess and treat digital risks. It uses an iterative, top-down approach that starts from the major missions of the studied object and gives an adaptable toolbox for identifying measures, validating acceptable risk and supporting decisions.
It applies to public and private organisations of any size or sector, for new or existing information systems, and the ANSSI guide states compatibility with ISO 31000 and alignment with the ISO/IEC 27000 series.
Built for the people who carry the work
- Risk managers and information security officers
- Consultants and auditors who run risk analyses
- Project managers who need security accreditation
- Public-sector and regulated-sector security teams
What you will be able to do
- Explain the five workshops of the method
- Scope a study and define the security baseline
- Identify risk sources and build strategic and operational scenarios
- Define a risk treatment plan and residual risk
- Present results to decision makers
Subject outline
- 01
Workshop 1: scoping and security baseline
- 02
Workshop 2: risk sources
- 03
Workshop 3: strategic scenarios
- 04
Workshop 4: operational scenarios
- 05
Workshop 5: risk treatment
- 06
Using EBIOS with ISO 31000 and ISO/IEC 27005
How it supports real work
Running a mission-led risk study for a new digital service
Producing risk treatment decisions an accreditation board can review
Complementing asset-based risk work with a scenario view
Training, examination and certification are different steps
EBIOS Risk Manager is a method owned by ANSSI. PECB offers a training course and personal certification built on it. ANSSI separately runs a label for EBIOS RM training; this page makes no claim about that label.
- PECB publishes a 3-day course: two days of workshops and a 3 hour exam on day 3.
- Its handbook describes a paper-based exam of essay-type questions with a 70% pass mark.
- PECB documents describe the credential names and experience requirements slightly differently, so we confirm the current position before you enrol.
Certification bodies set and can change their own exam, eligibility and renewal rules. The details below are what the body publishes; we confirm the current position with you before you enrol.
Sources checked, October 2026: pecb.com
What is confirmed, and what people ask
Delivery information
Delivery details for this course have not been confirmed for publication, so none are listed here. Course length, schedule, language, delivery format and fees are confirmed per enquiry. Certification bodies set their own exam and eligibility rules, and we confirm the route to any certificate before you enrol.
Enquire About This CourseFrequently asked questions
Who owns the EBIOS method?
ANSSI, the French national cybersecurity agency, with support from Club EBIOS.
How many workshops does the method have?
Five: scoping and security baseline, risk sources, strategic scenarios, operational scenarios, and risk treatment.
Is it only for French organisations?
No. The method is applicable to organisations of any size or sector.
Related courses
Related Valtrenix services
Request course information
Tell us who the training is for and what you want to achieve. We reply with confirmed details only, including what is currently available for EBIOS Risk Manager.
- Individual and team training enquiries welcome
- No fees, dates or formats are published until confirmed
- We confirm the certification route before you enrol


