NIS2 management training: what Article 20 requires, what to cover and which records to keep
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- Under Article 20(2) of Directive (EU) 2022/2555, members of the management bodies of essential and important entities are required to follow training, so that they can identify risks and assess cybersecurity risk-management practices and their impact on the entity’s services
- Management bodies also approve the Article 21 measures, oversee their implementation and can be held liable for infringements of that article (Article 20(1)); for employees, Member States need only encourage similar training on a regular basis, and the Directive sets no syllabus, duration or frequency
- Article 21(2)(g) lists basic cyber hygiene practices and cybersecurity training among the ten minimum measures; section 8 of the Annex to Implementing Regulation (EU) 2024/2690, binding only the digital providers in its Article 1, details it with an awareness programme repeated over time and regular role-based training
- ENISA’s guidance of June 2025 lists training records, workshop and seminar attendance and continuous learning materials as evidence of management training, and suggests including management bodies in incident response tests where necessary
- We recommend training the management body on appointment and once a year, with a yearly tabletop exercise, and keeping the curriculum, attendance per person, the training needs per role and a record of each exercise
Eurokommerz × Vixen.UNO: Enterprise Training Talk to an expert →
What NIS2 Article 20 requires for management training
Article 20(2) of the NIS2 Directive, Directive (EU) 2022/2555, requires Member States to ensure that “the members of the management bodies of essential and important entities are required to follow training”. Its purpose, stated in the same sentence, is sufficient knowledge and skills “to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity”. The Directive asks Member States only to “encourage” entities to offer similar training to their employees “on a regular basis”. Article 20(1) adds that the management bodies approve the cybersecurity risk-management measures taken under Article 21, oversee their implementation and “can be held liable for infringements by the entities of that Article”.
The Directive sets no syllabus, duration, frequency or exam for this training. It is addressed to the Member States, so the duty reaches a company through the national law that transposes it, and that law may add detail. Whether a company is an essential or important entity is a legal assessment for its legal department. On its NIS2 page, last updated on 2 July 2026, the Commission says the Directive “introduces accountability of the top management for non-compliance with cybersecurity risk management measures”.
Article 21(2)(g): cyber hygiene and cybersecurity training
Article 21(2)(g) lists “basic cyber hygiene practices and cybersecurity training” among the ten minimum measures that essential and important entities take. Article 20(2) is about training the people who approve and oversee the measures, while point (g) is one of the measures they approve. The Directive does not say whom this measure covers, on what or how often. Under Article 21(1), proportionality is judged by the entity’s exposure to risks, its size and the likelihood and severity of incidents. The same factors can guide how deep the training goes. Our guide to the NIS2 Article 21 measures covers the other nine measures and the evidence for each.
Awareness and security training in Implementing Regulation 2024/2690
Commission Implementing Regulation (EU) 2024/2690 details point (g) in section 8 of its Annex, “Basic cyber hygiene practices and security training”. It binds only the providers listed in its Article 1, such as DNS, cloud computing, data centre and managed service providers, online marketplaces and trust service providers. Any other company can use the regulation as a reference. ENISA writes that its June 2025 guidance on the regulation may give indications “which may be considered useful by other public or private bodies for improving their cybersecurity”.
Point 8.1.1 asks the entity to ensure that employees, “including members of management bodies”, and direct suppliers and service providers are aware of risks, informed of the importance of cybersecurity and apply cyber hygiene practices. The awareness raising programme of point 8.1.2 is “scheduled over time, so that the activities are repeated and cover new employees”. It follows the security policy and covers relevant cyber threats, the measures in place, contact points for advice and cyber hygiene practices for users. Point 8.1.3 adds a test of its effectiveness, where appropriate, and updates at planned intervals.
Security training under point 8.2 is for employees “whose roles require security relevant skill sets and expertise”. The entity identifies them and lays down the training needs of roles and positions “based on criteria” in a training programme. The entity gives them regular training, which fits the job function and is assessed for effectiveness (8.2.3). The training covers the secure configuration and operation of the systems, “including mobile devices”, a briefing on known cyber threats and “training of the behaviour when security-relevant events occur”. Staff moving into such a role are trained (8.2.4), and the programme is updated and run periodically (8.2.5). Under human resources security, point 10.1.2(c) adds mechanisms ensuring that members of management bodies “understand and act in accordance with their role, responsibilities and authorities regarding network and information system security”.
What NIS2 board and management training covers
Article 20(2) names the goal but no syllabus, so we recommend building cybersecurity training for management from the duties its members carry and the decisions they take.
Members first need the duties under Articles 20, 21 and 23 as national law transposes them, and what is at stake. Article 34 requires Member States to provide maximum fines for essential entities that infringe Article 21 or 23. The maximum is at least EUR 10 million or 2 per cent of the total worldwide annual turnover, whichever is higher. This turnover is that of the undertaking to which the entity belongs, in the preceding financial year. For important entities the figures are EUR 7 million or 1.4 per cent. The Commission’s NIS2 FAQ, last updated on 29 June 2023, adds that NIS2 “introduces provisions on the liability of natural persons holding senior management positions”.
For the providers it binds, the regulation’s Annex sets out what the management bodies decide and who reports to them. They review the security policy “at least annually” and after significant incidents or significant changes to operations or risks (1.1.2). Risk assessment results and residual risks are accepted by them or, where applicable, by “persons who are accountable and have the authority to manage risks”, with adequate reporting to the management bodies (2.1.1). At least one person reports to them directly on security (1.2.3). Members should learn to read the risk register, the treatment plan and the figures in a security report well enough to question them. Such figures include patch status, multi-factor coverage, restore test results and reported phishing.
The programme also covers the reporting clock of Article 23 and who in the company decides that an incident is significant. That article asks for an early warning within 24 hours of becoming aware of a significant incident and an incident notification within 72 hours. Our guide to NIS2 incident reporting has the details. Each member should know their own crisis role, such as who may take systems offline, who informs customers, staff and the authority, and how members are reached when email is down. ENISA’s guidance for Annex point 3.5.5 suggests: “Where necessary, include management bodies in the tests so that they understand their role during an incident.” A tabletop exercise with the management body does that. Our guide to the incident response plan and its tabletop test explains how to run one.
Supplier risk belongs in the programme because of Article 21(3). Under that paragraph, entities take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers. Both matter when the management body approves an outsourcing or a major IT contract. Where the company uses AI systems, Article 4 of the AI Act separately asks providers and deployers to take measures to support the development of AI literacy of their staff. Our guide to AI literacy training covers that duty.
Our tailored training builds the programme from your team’s own tasks, with cybersecurity among its topics. Tell us which roles your management body includes and what security training its members have had so far.
NIS2 training for employees, administrators and suppliers
Our suggestion for all staff is a module built on point 8.1.2(c). The module covers the threats people meet, such as phishing and fake payment requests, the company’s rules, contact points and the channel for reporting a suspicious email or event. The Annex asks the providers it covers to “regularly train their employees how to use the mechanism” for reporting suspicious events (3.3.2). Awareness training alone does not stop an adversary-in-the-middle kit that relays a password and a one-time code to the legitimate site. Our guide to phishing-resistant MFA covers the sign-in methods that do not depend on a user spotting the fake page.
In our reading, administrators, security staff and developers are the typical roles of point 8.2. They need hands-on training on the systems each person runs, such as the hypervisor, backup, firewalls and the directory service, with the attacks known against them and the first actions when an alert fires. New joiners complete the staff module before they get access. An employee moving into an administrative role is trained for it, as point 8.2.4 asks. We suggest completing that training before the new rights are granted. Suppliers with remote access belong in the programme as well: point 8.1.1 includes direct suppliers and service providers. Point 5.1.4(b) puts requirements on the “awareness, skills and training” of their employees into contracts, where appropriate.
| AUDIENCE | WHAT THEY LEARN | HOW OFTEN | EVIDENCE TO KEEP |
|---|---|---|---|
| Management body | duties under Articles 20, 21 and 23, risk decisions, reading security reports, supplier risk, their role in an incident | on appointment, then yearly, with a yearly tabletop exercise | curriculum, attendance per member, exercise record, minutes of approvals |
| All staff | phishing and social engineering, the reporting channel, passwords and MFA prompts, data handling, remote work | before first access, then yearly, with phishing simulations in between | completion per person and module version, simulation results |
| Administrators, security | secure configuration and operation of their systems, known threats, first actions in a security event | on taking the role, yearly, and when a system changes | training needs per role, completion per person, lab results |
| Developers | secure coding, dependencies and secrets, handling of reported vulnerabilities | on taking the role, then yearly | completion per person, exercise results |
| Suppliers with access | access rules, the reporting channel, contacts | before access, required by contract | contract clause, acknowledgement record |
Our recommendation, built on Articles 20(2) and 21(2)(g) of Directive (EU) 2022/2555 and Annex section 8 of Implementing Regulation (EU) 2024/2690; evidence after ENISA’s examples for Annex points 1.1, 3.3.2 and 3.5.5 (June 2025) where they exist.
How often NIS2 training should take place
Neither Article 20 nor Article 21 sets a frequency, and the only words on frequency in Article 20(2), “on a regular basis”, refer to the training of employees. The regulation’s Annex asks the providers it binds for an awareness programme offered “at planned intervals” (8.1.3), regular training for security roles (8.2.1) and a training programme “updated and run periodically” (8.2.5). ENISA’s guidance suggests testing incident response procedures “at least annually” (3.5.5).
We suggest a fixed calendar, in which members of the management body train when they join and once a year after that, with a tabletop exercise each year. Staff take the module before first access and a refresher each year, with short items such as simulated phishing emails in between. Administrators train when they take on a system and when it changes. A significant incident, a major new system or a shift in the threats the company faces calls for an extra session.
Evidence of NIS2 training to keep
Training evidence shows who was trained, on which content and when. ENISA’s Technical Implementation Guidance of June 2025 gives tips for the security policy (Annex point 1.1). Among them it lists “Evidence of cybersecurity training of management, for instance: training records; workshop and seminar attendance; and continuous learning materials.” It also names “records showing regular briefings or updates provided to management bodies”. For the reporting channel, ENISA’s examples include training materials for employees, suppliers and customers and periodic simulations that test staff readiness (3.3.2). For incident response, they include “Records from tests of different types of incidents” (3.5.5). The examples are indicative, and entities “may choose alternative methods to fulfil a requirement or use different evidence to demonstrate compliance”.
Keep five records. The first is the curriculum per audience with its version and date. The second records attendance per person with role, module version and date. The third sets out the training needs per role that point 8.2.2 describes. The fourth is a record of each exercise with scenario, participants, decisions, findings and owners. The fifth holds measures of effectiveness, such as the share of staff who reported a simulated phishing email. Simulated phishing processes personal data, so settle its scope and how results are reported with your data protection contact and any employee representatives before the first campaign. Minutes of the meetings at which the management body approves the measures and reviews the security policy show the approval and oversight that Article 20(1) asks for.
After a cyber resilience project you have a NIS2 compliance map with the gaps listed and a plan to close them. Send us the training records you keep today through the form below, with the audiences they cover.
General information on EU law as of October 2026, not legal advice for an individual case.
What we do
Under our enterprise training, Eurokommerz holds the contract. The training centre of our engineering partner Vixen.UNO delivers the training, online, on your site or blended, with practitioner-instructors from its projects. Lab environments in its own data centre let each participant deploy, break and restore a live environment. After a security implementation under our cyber resilience service, we train your team to work with the new infrastructure, and the incident response plan we write sets out roles, actions and deadlines. The first call is free of charge and the price is fixed before the training starts. The compliance map is a technical assessment, and we do not issue compliance certificates.
FAQ
What does NIS2 Article 20 require for management training?
What are the NIS2 training requirements for employees?
How often is NIS2 management training required?
What should NIS2 board training cover?
What evidence of NIS2 training should a company keep?
Is a certificate required for NIS2 management training?
Send us the audiences you need to train, from the management body to administrators and suppliers with access, the security training each has had so far and the records you keep of it. We reply within one business day; in the first call we clarify your team’s level, goals and timelines, and you leave with a draft training programme. The first call is free of charge.
Talk to an expertWe reply within one business day