One generic online course a year is not enough under NIS2. We explain what training obligations actually exist and what an effective programme looks like.
The explicit training obligation under § 38 BSIG applies to executive management. There is no comparably direct individual obligation for employees — but § 30 BSIG obligates entities to comprehensive risk management measures that simply cannot be implemented without trained staff.
Rule of thumb: Without regular, audience-appropriate training, NIS2-compliant risk management cannot be demonstrated. The BSI expects documented training measures for all employees who perform security-relevant tasks.
An effective security awareness programme is neither a one-off nor generic. It is tailored to target groups, repeated regularly, and tested for effectiveness.
We develop audience-tailored training programmes that fulfil NIS2 requirements and actually work within your workforce.
Request a Training Programme