BLOG · GUIDE ·

NIS2 management training: what Article 20 requires, what to cover and which records to keep

Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software

IN BRIEF
  • Under Article 20(2) of Directive (EU) 2022/2555, members of the management bodies of essential and important entities are required to follow training, so that they can identify risks and assess cybersecurity risk-management practices and their impact on the entity’s services
  • Management bodies also approve the Article 21 measures, oversee their implementation and can be held liable for infringements of that article (Article 20(1)); for employees, Member States need only encourage similar training on a regular basis, and the Directive sets no syllabus, duration or frequency
  • Article 21(2)(g) lists basic cyber hygiene practices and cybersecurity training among the ten minimum measures; section 8 of the Annex to Implementing Regulation (EU) 2024/2690, binding only the digital providers in its Article 1, details it with an awareness programme repeated over time and regular role-based training
  • ENISA’s guidance of June 2025 lists training records, workshop and seminar attendance and continuous learning materials as evidence of management training, and suggests including management bodies in incident response tests where necessary
  • We recommend training the management body on appointment and once a year, with a yearly tabletop exercise, and keeping the curriculum, attendance per person, the training needs per role and a record of each exercise

Eurokommerz × Vixen.UNO: Enterprise Training  Talk to an expert →

What NIS2 Article 20 requires for management training

Article 20(2) of the NIS2 Directive, Directive (EU) 2022/2555, requires Member States to ensure that “the members of the management bodies of essential and important entities are required to follow training”. Its purpose, stated in the same sentence, is sufficient knowledge and skills “to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity”. The Directive asks Member States only to “encourage” entities to offer similar training to their employees “on a regular basis”. Article 20(1) adds that the management bodies approve the cybersecurity risk-management measures taken under Article 21, oversee their implementation and “can be held liable for infringements by the entities of that Article”.

The Directive sets no syllabus, duration, frequency or exam for this training. It is addressed to the Member States, so the duty reaches a company through the national law that transposes it, and that law may add detail. Whether a company is an essential or important entity is a legal assessment for its legal department. On its NIS2 page, last updated on 2 July 2026, the Commission says the Directive “introduces accountability of the top management for non-compliance with cybersecurity risk management measures”.

Article 21(2)(g): cyber hygiene and cybersecurity training

Article 21(2)(g) lists “basic cyber hygiene practices and cybersecurity training” among the ten minimum measures that essential and important entities take. Article 20(2) is about training the people who approve and oversee the measures, while point (g) is one of the measures they approve. The Directive does not say whom this measure covers, on what or how often. Under Article 21(1), proportionality is judged by the entity’s exposure to risks, its size and the likelihood and severity of incidents. The same factors can guide how deep the training goes. Our guide to the NIS2 Article 21 measures covers the other nine measures and the evidence for each.

Awareness and security training in Implementing Regulation 2024/2690

Commission Implementing Regulation (EU) 2024/2690 details point (g) in section 8 of its Annex, “Basic cyber hygiene practices and security training”. It binds only the providers listed in its Article 1, such as DNS, cloud computing, data centre and managed service providers, online marketplaces and trust service providers. Any other company can use the regulation as a reference. ENISA writes that its June 2025 guidance on the regulation may give indications “which may be considered useful by other public or private bodies for improving their cybersecurity”.

Point 8.1.1 asks the entity to ensure that employees, “including members of management bodies”, and direct suppliers and service providers are aware of risks, informed of the importance of cybersecurity and apply cyber hygiene practices. The awareness raising programme of point 8.1.2 is “scheduled over time, so that the activities are repeated and cover new employees”. It follows the security policy and covers relevant cyber threats, the measures in place, contact points for advice and cyber hygiene practices for users. Point 8.1.3 adds a test of its effectiveness, where appropriate, and updates at planned intervals.

Security training under point 8.2 is for employees “whose roles require security relevant skill sets and expertise”. The entity identifies them and lays down the training needs of roles and positions “based on criteria” in a training programme. The entity gives them regular training, which fits the job function and is assessed for effectiveness (8.2.3). The training covers the secure configuration and operation of the systems, “including mobile devices”, a briefing on known cyber threats and “training of the behaviour when security-relevant events occur”. Staff moving into such a role are trained (8.2.4), and the programme is updated and run periodically (8.2.5). Under human resources security, point 10.1.2(c) adds mechanisms ensuring that members of management bodies “understand and act in accordance with their role, responsibilities and authorities regarding network and information system security”.

What NIS2 board and management training covers

Article 20(2) names the goal but no syllabus, so we recommend building cybersecurity training for management from the duties its members carry and the decisions they take.

Members first need the duties under Articles 20, 21 and 23 as national law transposes them, and what is at stake. Article 34 requires Member States to provide maximum fines for essential entities that infringe Article 21 or 23. The maximum is at least EUR 10 million or 2 per cent of the total worldwide annual turnover, whichever is higher. This turnover is that of the undertaking to which the entity belongs, in the preceding financial year. For important entities the figures are EUR 7 million or 1.4 per cent. The Commission’s NIS2 FAQ, last updated on 29 June 2023, adds that NIS2 “introduces provisions on the liability of natural persons holding senior management positions”.

For the providers it binds, the regulation’s Annex sets out what the management bodies decide and who reports to them. They review the security policy “at least annually” and after significant incidents or significant changes to operations or risks (1.1.2). Risk assessment results and residual risks are accepted by them or, where applicable, by “persons who are accountable and have the authority to manage risks”, with adequate reporting to the management bodies (2.1.1). At least one person reports to them directly on security (1.2.3). Members should learn to read the risk register, the treatment plan and the figures in a security report well enough to question them. Such figures include patch status, multi-factor coverage, restore test results and reported phishing.

The programme also covers the reporting clock of Article 23 and who in the company decides that an incident is significant. That article asks for an early warning within 24 hours of becoming aware of a significant incident and an incident notification within 72 hours. Our guide to NIS2 incident reporting has the details. Each member should know their own crisis role, such as who may take systems offline, who informs customers, staff and the authority, and how members are reached when email is down. ENISA’s guidance for Annex point 3.5.5 suggests: “Where necessary, include management bodies in the tests so that they understand their role during an incident.” A tabletop exercise with the management body does that. Our guide to the incident response plan and its tabletop test explains how to run one.

Supplier risk belongs in the programme because of Article 21(3). Under that paragraph, entities take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers. Both matter when the management body approves an outsourcing or a major IT contract. Where the company uses AI systems, Article 4 of the AI Act separately asks providers and deployers to take measures to support the development of AI literacy of their staff. Our guide to AI literacy training covers that duty.

Our tailored training builds the programme from your team’s own tasks, with cybersecurity among its topics. Tell us which roles your management body includes and what security training its members have had so far.

NIS2 training for employees, administrators and suppliers

Our suggestion for all staff is a module built on point 8.1.2(c). The module covers the threats people meet, such as phishing and fake payment requests, the company’s rules, contact points and the channel for reporting a suspicious email or event. The Annex asks the providers it covers to “regularly train their employees how to use the mechanism” for reporting suspicious events (3.3.2). Awareness training alone does not stop an adversary-in-the-middle kit that relays a password and a one-time code to the legitimate site. Our guide to phishing-resistant MFA covers the sign-in methods that do not depend on a user spotting the fake page.

In our reading, administrators, security staff and developers are the typical roles of point 8.2. They need hands-on training on the systems each person runs, such as the hypervisor, backup, firewalls and the directory service, with the attacks known against them and the first actions when an alert fires. New joiners complete the staff module before they get access. An employee moving into an administrative role is trained for it, as point 8.2.4 asks. We suggest completing that training before the new rights are granted. Suppliers with remote access belong in the programme as well: point 8.1.1 includes direct suppliers and service providers. Point 5.1.4(b) puts requirements on the “awareness, skills and training” of their employees into contracts, where appropriate.

AUDIENCEWHAT THEY LEARNHOW OFTENEVIDENCE TO KEEP
Management bodyduties under Articles 20, 21 and 23, risk decisions, reading security reports, supplier risk, their role in an incidenton appointment, then yearly, with a yearly tabletop exercisecurriculum, attendance per member, exercise record, minutes of approvals
All staffphishing and social engineering, the reporting channel, passwords and MFA prompts, data handling, remote workbefore first access, then yearly, with phishing simulations in betweencompletion per person and module version, simulation results
Administrators, securitysecure configuration and operation of their systems, known threats, first actions in a security eventon taking the role, yearly, and when a system changestraining needs per role, completion per person, lab results
Developerssecure coding, dependencies and secrets, handling of reported vulnerabilitieson taking the role, then yearlycompletion per person, exercise results
Suppliers with accessaccess rules, the reporting channel, contactsbefore access, required by contractcontract clause, acknowledgement record

Our recommendation, built on Articles 20(2) and 21(2)(g) of Directive (EU) 2022/2555 and Annex section 8 of Implementing Regulation (EU) 2024/2690; evidence after ENISA’s examples for Annex points 1.1, 3.3.2 and 3.5.5 (June 2025) where they exist.

How often NIS2 training should take place

Neither Article 20 nor Article 21 sets a frequency, and the only words on frequency in Article 20(2), “on a regular basis”, refer to the training of employees. The regulation’s Annex asks the providers it binds for an awareness programme offered “at planned intervals” (8.1.3), regular training for security roles (8.2.1) and a training programme “updated and run periodically” (8.2.5). ENISA’s guidance suggests testing incident response procedures “at least annually” (3.5.5).

We suggest a fixed calendar, in which members of the management body train when they join and once a year after that, with a tabletop exercise each year. Staff take the module before first access and a refresher each year, with short items such as simulated phishing emails in between. Administrators train when they take on a system and when it changes. A significant incident, a major new system or a shift in the threats the company faces calls for an extra session.

Evidence of NIS2 training to keep

Training evidence shows who was trained, on which content and when. ENISA’s Technical Implementation Guidance of June 2025 gives tips for the security policy (Annex point 1.1). Among them it lists “Evidence of cybersecurity training of management, for instance: training records; workshop and seminar attendance; and continuous learning materials.” It also names “records showing regular briefings or updates provided to management bodies”. For the reporting channel, ENISA’s examples include training materials for employees, suppliers and customers and periodic simulations that test staff readiness (3.3.2). For incident response, they include “Records from tests of different types of incidents” (3.5.5). The examples are indicative, and entities “may choose alternative methods to fulfil a requirement or use different evidence to demonstrate compliance”.

Keep five records. The first is the curriculum per audience with its version and date. The second records attendance per person with role, module version and date. The third sets out the training needs per role that point 8.2.2 describes. The fourth is a record of each exercise with scenario, participants, decisions, findings and owners. The fifth holds measures of effectiveness, such as the share of staff who reported a simulated phishing email. Simulated phishing processes personal data, so settle its scope and how results are reported with your data protection contact and any employee representatives before the first campaign. Minutes of the meetings at which the management body approves the measures and reviews the security policy show the approval and oversight that Article 20(1) asks for.

After a cyber resilience project you have a NIS2 compliance map with the gaps listed and a plan to close them. Send us the training records you keep today through the form below, with the audiences they cover.

General information on EU law as of October 2026, not legal advice for an individual case.

What we do

Under our enterprise training, Eurokommerz holds the contract. The training centre of our engineering partner Vixen.UNO delivers the training, online, on your site or blended, with practitioner-instructors from its projects. Lab environments in its own data centre let each participant deploy, break and restore a live environment. After a security implementation under our cyber resilience service, we train your team to work with the new infrastructure, and the incident response plan we write sets out roles, actions and deadlines. The first call is free of charge and the price is fixed before the training starts. The compliance map is a technical assessment, and we do not issue compliance certificates.

FAQ

What does NIS2 Article 20 require for management training?
Article 20(2) of Directive (EU) 2022/2555 requires Member States to ensure that members of the management bodies of essential and important entities follow training. The aim is that the members gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the entity’s services. Under Article 20(1) the management bodies also approve the Article 21 measures, oversee their implementation and can be held liable for infringements of that article. The Directive sets no syllabus, duration or frequency, and national transposition laws may add detail.
What are the NIS2 training requirements for employees?
Article 20(2) obliges only members of management bodies to follow training and asks Member States to encourage entities to offer similar training to their employees on a regular basis. Article 21(2)(g) separately lists basic cyber hygiene practices and cybersecurity training among the minimum measures every essential and important entity takes, without saying who is trained or how often. For the digital providers it binds, Implementing Regulation (EU) 2024/2690 requires an awareness programme for all employees and regular training for roles that need security skills.
How often is NIS2 management training required?
At EU level, neither the Directive nor Implementing Regulation (EU) 2024/2690 sets a fixed interval for management training. The regulation, binding only the digital providers in its Article 1, asks for awareness activities that are repeated over time and offered at planned intervals, members of management bodies included. We recommend training members of the management body when they join and once a year, with a yearly tabletop exercise and an extra session after a significant incident or a major change.
What should NIS2 board training cover?
Article 20(2) sets the goal of sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the entity’s services. We recommend covering the duties under Articles 20, 21 and 23 and the sanctions, the risk register and the residual risks the management body accepts. We also recommend covering how to read security reports, supplier risk, and the members’ own role in an incident, including the reporting decision, practised in a tabletop exercise.
What evidence of NIS2 training should a company keep?
ENISA’s Technical Implementation Guidance of June 2025 lists training records, workshop and seminar attendance and continuous learning materials as evidence of management training, together with records of regular briefings to management bodies. We recommend also keeping the curriculum per audience with version and date, attendance per person and the training needs per role. The same applies to a record of each exercise with its decisions and findings, and to measures of effectiveness such as phishing simulation results.
Is a certificate required for NIS2 management training?
Article 20(2) requires members of management bodies to follow training but names no certificate, accredited course or exam. ENISA’s guidance on the implementing regulation gives training records, workshop and seminar attendance and continuous learning materials as examples of evidence of management training.

Send us the audiences you need to train, from the management body to administrators and suppliers with access, the security training each has had so far and the records you keep of it. We reply within one business day; in the first call we clarify your team’s level, goals and timelines, and you leave with a draft training programme. The first call is free of charge.

Talk to an expert
Talk to an expert

We reply within one business day

By sending this form you agree that we process your details to answer your enquiry – see our privacy policy.

request@eurokommerz.at
Jordangasse 7, 1010 Vienna