← Back to Blog

NIS2 Training Requirements: Who Must Be Trained, and How Often?

What executives and employees should learn, what frequency makes sense, and how companies can reliably document implementation.

By Autophish Team|Published on 9/30/2026
Cover image for NIS2 Training Requirements: Who Must Be Trained, and How Often?

The NIS2 training requirement does not apply only to the IT department. For critical and highly critical facilities in Germany, basic training and awareness-raising measures for internal and external users are part of cybersecurity risk management. Members of senior management are also subject to their own specific training requirements. However, NIS2 does not prescribe a rigid, Europe-wide standard number of training sessions: the content and frequency must be tailored to the risk, the role, and changes within the organization.

In practice, this means: provide training upon joining, conduct regular refresher courses, offer targeted training for new risks or systems, and document the training process.

What NIS2 Requires Regarding Training

The legal framework consists of several levels.

The NIS2 Directive specifies in Article 21(2)(g) that basic cyber hygiene procedures and cybersecurity training are part of risk management measures. Article 20(2) provides for training for members of management bodies and, at the same time, calls on Member States to promote regular, comparable training for employees.

In Germany, the BSI Act specifies these requirements. The BSI mandates basic training and awareness-raising measures to the obligations of important and particularly important entities under Section 30 of the BSI Act. Training for senior management is regulated separately in Section 38(3) of the BSIG.

It is important to note the distinction: A single course or a phishing simulation does not automatically make a company NIS 2-compliant. Training is one component within a larger system comprising governance, risk management, technical controls, incident response, and continuous improvement.

Who Must Be Trained?

Members of Senior Management

Senior management must understand cybersecurity risks to the extent that they can assess, approve, and oversee the implementation of appropriate measures. This is not specialized technical training. It is about decision-making ability and responsibility.

Depending on the legal form of the company, typical target groups include, for example:

  • Managing directors
  • Board members
  • Other individuals who are considered part of senior management under applicable law

The company should clarify the specific classification with its legal or compliance department. What matters is not the job title alone, but the actual managerial responsibility.

Employees and External Users

The BSI identifies the internal and external users of systems and applications within the affected organization as the target audience for the basic training. Thus, the training requirement is not limited to permanent office staff.

Depending on the risk profile, this may include:

  • Full-time and part-time employees
  • New employees during onboarding
  • Temporary workers
  • External service providers with system access
  • Freelancers
  • Privileged IT administrators
  • Employees in production, logistics, or field service

Not everyone requires the same training. A basic module for all can be supplemented with role-specific content for finance, HR, support, procurement, IT, and management.

How often is NIS2 training required?

A blanket answer such as “once a year is enough” falls short. The law requires an effective, appropriate approach to managing risks. The frequency should therefore be determined based on the risk profile and the training objective.

The BSI considers training during initial orientation and annual updates on current developments to be appropriate. In addition, measures should be continuously reviewed and refined. This is a reasonable minimum frequency, but not a universal standard.

A robust model consists of four levels:

  1. Initial training: before or immediately after granting relevant access.
  2. Regular refresher training: at least at a defined, traceable interval.
  3. Event-driven training: following major system changes, new threats, incidents, or revised policies.
  4. Role-Based In-Depth Training: more frequent or more specific for high-risk groups.

Phishing simulations can serve as brief practice and assessment points between formal learning modules. However, they do not replace either basic training or executive training.

A Practical Annual Schedule

A medium-sized company could structure the program as follows, for example:

  • During onboarding: A basic module covering reporting procedures, phishing, passwords, MFA, data handling, and secure work practices.
  • Quarterly: A brief awareness session or secure phishing simulation on a current risk topic.
  • After a risky interaction: A short, context-specific learning module instead of a blanket disciplinary training session.
  • Annually: Updated basic training and a documented review of the program.
  • As needed: Role-specific modules for particularly high-risk areas.
  • For executive management: Regular, dedicated training on governance, risk decisions, incidents, and oversight.

The frequency shouldn’t just be a calendar entry. Every element must serve a purpose: imparting knowledge, practicing behavior, testing reporting channels, or evaluating the effectiveness of a measure.

What content should be included in the basic training?

A NIS2-oriented awareness program should, at a minimum, cover the risks that the respective users actually encounter. These often include:

  • Phishing and social engineering
  • Secure use of passwords and password managers
  • Multi-factor authentication and suspicious authorization requests
  • Reporting channels for suspicious messages and security incidents
  • Handling sensitive information
  • Mobile work and personal devices
  • Secure use of cloud and collaboration services
  • Roles and responsibilities during security incidents

The detailed structure of a curriculum is explored in greater depth in the article on NIS2 training content.

How Can Implementation Be Verified?

The BSI explicitly states that the implementation must be documented. This requires more than just an invoice from the training provider.

Appropriate evidence includes:

  • Defined target groups and training objectives
  • Content and version status of the module
  • Date of assignment and completion status
  • Proof of participation or completion
  • Documented exceptions and grace periods
  • Results of knowledge tests or exercises, to the extent necessary and proportionate
  • Review of the program and agreed-upon improvements
  • Evidence of role- or event-specific refresher training

Personal data should only be stored in as much detail and for as long as is necessary for the specified purpose. Managers and auditors often require aggregated reports; individual results should be restricted to a clearly authorized group of individuals.

How a Training Platform Can Help

A training platform can simplify operational implementation by supporting the entire learning cycle:

  • Assign training courses based on rules
  • Integrate custom SCORM content
  • Track completion status
  • Trigger targeted refresher training following simulations
  • Provide reports for security, compliance, and management
  • Differentiate content by role or risk

The AutoPhish Training Platform combines phishing simulations with automated training assignment, progress tracking, and custom SCORM-compatible content. It thus supports the repeatable execution and documentation of the awareness program. It does not replace a legal review or comprehensive NIS2 risk management.

FAQ

Do all employees have to complete the same NIS2 training?

No. A common basic module is useful, but it should be supplemented with role- and risk-specific content. Finance, IT administration, and executive management have different decisions to make.

Is annual training sufficient?

Not necessarily. An annual refresher course can be part of the program. In addition, initial training, event-driven updates, and regular awareness campaigns are recommended. The key is that the program is tailored to the risk and is regularly reviewed.

Are phishing simulations mandatory under NIS2?

NIS2 does not prescribe a specific phishing simulation product or a fixed number of campaigns. However, simulations can help to systematically test behavior, reporting channels, and the effectiveness of awareness measures.

Does senior management need its own training?

Yes. The requirements for senior management must be distinguished from general employee training. Management bodies must be able to assess and monitor risks and risk management measures.

What records should a company retain?

At a minimum: the target audience, content, version, date, assignment, completion, and review of the program. The scope and retention period should be determined on a risk-based basis and in compliance with data protection regulations.

Conclusion

A robust NIS2 training program reaches the right people at the right time: management, employees, and external users receive appropriate content; new risks trigger updates; and implementation and improvement remain traceable.

Those who do not want to manage these processes with lists and manual reminders can use the AutoPhish Training Platform to assign training sessions, document progress, and combine simulations with targeted follow-ups.


Run your first phishing test in 10 minutes.

Sign up free — no credit card. Try Pro free for 7 days when you're ready.