NIS2 training requirements: what the Directive asks of staff and management
What the NIS2 Directive (EU) 2022/2555 requires on cybersecurity training for staff and the management body, who is in scope in any EU country, and how to evidence it.
Updated
In short
NIS2 is an EU Directive, (EU) 2022/2555. It does not bind companies directly: each member state transposes it into its own national law, which then applies to the organisations in its scope. Member states had to adopt their laws by 17 October 2024 and apply them from 18 October 2024 (Article 41).
Two articles carry the training duty. Article 21(2)(g) lists "basic cyber hygiene practices and cybersecurity training" among the risk-management measures an entity must take. Article 20(2) requires the members of the management body to follow training, and asks member states to encourage entities to offer similar training to their employees regularly.
The Directive sets no hours, frequency or syllabus. Your national law may add detail, so read it alongside this guide.
Who is in scope
NIS2 covers entities in 18 critical sectors, listed in its Annexes I and II: among them energy, transport, banking, financial market infrastructures, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing, digital providers and research.
As a rule, an entity is in scope if it is at least a medium-sized enterprise under Commission Recommendation 2003/361/EC: 50 staff or more, or turnover and balance sheet both above €10 million (Article 2(1)). Some are in scope regardless of size, such as providers of public electronic communications networks or services, trust service providers, top-level domain registries and DNS service providers, and entities a member state identifies as critical (Article 2(2)).
For financial entities covered by DORA, Regulation (EU) 2022/2554, DORA's ICT risk-management and incident-reporting rules apply instead of NIS2's risk-management, reporting, supervision and enforcement provisions (recital 28, Article 4).
Essential and important entities
Entities of a type in Annex I that exceed the ceilings for medium-sized enterprises are essential entities, as are qualified trust service providers, top-level domain registries and DNS service providers regardless of size, and central government administration (Article 3(1)). Every other entity in scope is an important entity (Article 3(2)).
The duties, training included, are the same for both. Supervision differs: essential entities face supervision before and after the fact, including inspections, random checks and security audits; important entities only after the fact, when there is evidence, indication or information of non-compliance (recital 122, Articles 32 and 33).
Member states must set maximum fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher (Article 34). For an essential entity, a person at chief-executive level can be temporarily barred from managerial functions once other measures have proved ineffective (Article 32(5)).
What Article 21 asks of staff training
Article 21(2) lists ten areas the risk-management measures must cover, from (a) risk analysis to (j) multi-factor authentication. Point (g) is basic cyber hygiene practices and cybersecurity training. Others reach staff too: (b) incident handling, (d) supply chain security and (i) human resources security, access control and asset management.
Measures must be appropriate and proportionate to the risks. In practice, your training should address the risks your own assessment identified. For some digital providers, such as cloud, data centre and managed service providers, Commission Implementing Regulation (EU) 2024/2690 adds detail on cyber hygiene and security training.
Training for the management body
Article 20(1) makes the management body approve the risk-management measures, oversee their implementation, and be liable for the entity's infringements, on terms national law sets. Article 20(2) requires its members to follow training, so that they gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices.
National laws word this in their own way. Finland's Cybersecurity Act, for example, requires management to be sufficiently familiar with cybersecurity risk management rather than repeating the training duty as such; our guide to NIS2 in Finland covers that case. Whatever the wording, a supervisor will ask about named people, and a dated training record is the simplest way to answer.
Reporting: 24 hours, 72 hours, one month
A significant incident starts three deadlines (Article 23(4)): an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours, and a final report no later than one month after the incident notification. The trigger is a significant incident, not a personal-data breach, so it is a different clock from GDPR's 72 hours. Often the first person to notice is an ordinary member of staff, which is why reporting belongs in the training.
Where national laws stand
Most member states have passed their NIS2 law, but not all on time. On 28 November 2024 the Commission sent letters of formal notice to 23 member states, and on 7 May 2025 reasoned opinions to 19. On 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for not having notified full transposition.
Three examples, checked at official sources: Italy's Legislative Decree No. 138 of 4 September 2024 has been in force since 16 October 2024; Finland's Cybersecurity Act (kyberturvallisuuslaki, 124/2025) since 8 April 2025; and Germany's NIS2 implementation act since 6 December 2025. Check your own country's law and competent authority before relying on the details.
How to evidence training
Few organisations can show training today. In 2024, 60% of EU enterprises with ten or more staff made their staff aware of their ICT security obligations, but only about one in four (24.5%) did so through compulsory training or compulsory material (Eurostat). A record that would satisfy an auditor usually has these parts:
- A training plan inside the risk-management measures: who, what and how often
- The link to your risk assessment: why these topics
- Dated completion records per person
- Evidence of knowledge, not just attendance, such as question results
- The management body's own training, by name, and its approval and oversight of the measures
- A change history: when content was updated and why
How Cyberact helps
Cyberact is security and AI training in two-minute daily lessons, with spaced review to keep it remembered. Every lesson is mapped to the NIS2 article it supports, and the manager console reports staff and the management body by name, with dated completions you can hand to an auditor or supervisor. The lessons are in English and Finnish only, and the data is hosted in the EU, in Germany. Start for free at cyberact.io: your account is ready at once.
Sources
Checked against primary sources on 1 October 2026.
- NIS2 Directive (EU) 2022/2555, Official Journal L 333, 27.12.2022, EUR-Lex: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
- Commission Implementing Regulation (EU) 2024/2690, EUR-Lex: https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj
- European Commission, NIS2 Directive: https://digital-strategy.ec.europa.eu/en/policies/nis2-directive
- European Commission, NIS2 transposition: https://digital-strategy.ec.europa.eu/en/policies/nis-transposition
- European Commission, referral of four member states, 8 July 2026: https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1499
- Italy, ACN, the NIS legislation: https://www.acn.gov.it/portale/en/nis/la-normativa
- Germany, BSI, the NIS-2 implementation act in force, 5 December 2025: https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html
- Finland, Cybersecurity Act 124/2025 (Finnish), Finlex: https://www.finlex.fi/fi/lainsaadanto/2025/124
- Eurostat, ICT security in enterprises, 11 February 2025: https://ec.europa.eu/eurostat/web/products-eurostat-news/w/ddn-20250211-1
Frequently asked questions
- Is cybersecurity training mandatory under NIS2?
- For entities in scope, yes: Article 21(2)(g) lists basic cyber hygiene practices and cybersecurity training among the required risk-management measures, and your country's NIS2 law transposes it. The Directive does not prescribe a format, length or frequency.
- Do board members have to take NIS2 training?
- Article 20(2) requires member states to ensure that members of the management body of essential and important entities are required to follow training. How each national law words it varies, so check yours.
- How often must NIS2 training be repeated?
- The Directive sets no interval. Measures have to stay appropriate to the risks, so short, continuous training that is kept up to date fits the duty better than a once-a-year course.
- What are the NIS2 fines?
- Member states must set maximum fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher (Article 34). Your national law sets the exact amounts.
- Has my country transposed NIS2?
- Most member states have. In July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for not having notified full transposition. Check your national competent authority for the current state.
Read next
Training your team will actually finish
Cyberact teaches security and practical AI in two minutes a day, and keeps a record of what each person knows.