NIS2 Compliance: What Security Awareness Training Do You Need?
The NIS2 Directive mandates cybersecurity training for management and staff. Learn who must comply, what training is required, and how to document it.
What NIS2 says about cybersecurity training
The NIS2 Directive (EU 2022/2555) entered into force in January 2023, with member states required to transpose it into national law by October 2024. It significantly expands the scope and teeth of EU cybersecurity regulation compared to the original NIS Directive.
Article 20 of NIS2 is direct: management bodies of essential and important entities must approve cybersecurity risk-management measures, oversee their implementation, and undergo training themselves. The article further requires that entities offer similar training to their employees on a regular basis to enable them to identify risks and assess cybersecurity practices.
This is not a recommendation. NIS2 carries enforcement provisions including fines of up to EUR 10 million or 2% of global annual turnover for essential entities.
Who must comply
NIS2 applies to two categories of organizations operating in the EU:
Essential entities include energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management (B2B), public administration, and space.
Important entities include postal services, waste management, chemicals, food, manufacturing (medical devices, computers, electronics, machinery, motor vehicles), digital providers (online marketplaces, search engines, social networks), and research organizations.
The directive applies to medium-sized and large organizations in these sectors. However, member states may also include smaller entities if they are considered critical.
What training is actually required
NIS2 does not prescribe a specific curriculum, but the directive and the recitals point to several requirements:
- Management training is mandatory. Article 20(2) explicitly states that management bodies must receive training to gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices. This is a personal obligation on board members and senior leaders.
- Staff training must be regular. The same article requires that similar training is offered to employees on a regular basis. "Regular" is not defined, but annual delivery aligned with the risk management cycle is the emerging standard.
- Content must be relevant to the entity's risk profile. Generic awareness material is insufficient. Training should address the specific threats facing the sector: ransomware in healthcare, supply chain attacks in manufacturing, social engineering in financial services.
- Cyber hygiene practices are called out in Article 21(2)(g), which lists basic cyber hygiene and cybersecurity training as one of the minimum risk-management measures.
The documentation requirement
While NIS2 does not specify how training must be documented, the compliance logic is clear: if you cannot prove it happened, it did not happen.
National supervisory authorities will expect:
- Records showing who received training and when.
- Evidence that management bodies completed their training obligation.
- Documentation that training content was appropriate to the entity's risk context.
- Proof of regular delivery, not a one-off exercise at the start of the compliance period.
The penalty framework makes documentation critical. In an enforcement action, the burden of demonstrating compliance falls on the entity. An assertion that "we did the training" without supporting evidence will not withstand regulatory scrutiny.
How to build a NIS2-ready awareness program
A practical approach to NIS2 security awareness compliance:
- Start with the board. Deliver cybersecurity training to management bodies first. This satisfies the Article 20 requirement and signals top-down commitment.
- Map training to your risk assessment. Identify the threats most relevant to your sector and operations, and ensure training content addresses them.
- Deliver to all staff regularly. Annual training as a baseline, with supplemental training for new hires, role changes, and after incidents.
- Collect verifiable evidence. Each completion should generate a record that can be independently verified, not a manual attendance list.
- Review and update annually. The threat landscape changes. Your training program should evolve with it.
Why verifiable proof matters for NIS2
NIS2 supervision will be proactive, not reactive. National authorities can conduct audits, request documentation, and impose penalties without waiting for an incident.
This means organizations need evidence that is:
- Tamper-evident: records that cannot be modified after the fact.
- Independently verifiable: a supervisor should be able to validate a completion record without relying on the entity's internal systems.
- Comprehensive: covering every person in scope, including management.
- Timestamped: proving when training occurred, not just that it occurred.
ProofAware's cryptographically signed Completion Signatures satisfy all four criteria. Each record is HMAC-signed at the moment of completion, links to the specific training module, and can be verified via a public URL without access to the organization's account.
For entities facing NIS2 compliance, this removes the documentation risk entirely. The training evidence is built into the training process itself.