Training isno longeroptional.
With NIS2 implemented into German law, training is among the measures an affected company has to take. For management there is a separate duty that cannot be handed down to the IT department.
What the obligation means in practice
Four points that regularly get lost in the discussion.
Employees and management are governed separately
Training for employees belongs to the risk management measures. For management the duty is set out separately in its own provision.
Management cannot delegate it
Approving and supervising the measures, and attending training personally, rest with the management. Appointing a service provider does not remove that.
Without evidence the duty is not met
What counts is not the intention but the proof. Anyone who cannot show when what was trained and with what result stands as if no training happened.
Once is not enough
The requirement aims at regular training. An introductory session on joining does not cover it.
What ends up on the table.
An audit does not ask whether you trained, but with what, when and to what effect. Those three answers are what the report delivers, separately for staff and management.
Separate records for staff and management
Content and periods traceable
Development across rounds instead of a snapshot
Export for your risk management documentation
How to meet the obligation
Three steps that produce the evidence along the way.
1. Define the audience
Employees by department and role, management as its own group with its own record.
2. Run the programme
Training units and simulations run spread across the year instead of being bundled into one date.
3. Export the evidence
Reports per period and department can be exported and added to your risk management documentation.
What you end up holding
Six points an audit expects.
Separate records
Employees and management are tracked separately, because the duties rest on different grounds.
Coverage over time
Reports show that training ran across the year, not only on one reference date.
Content is identifiable
It stays visible which content was delivered, not merely that a session took place.
Evidence of effect
Simulation results across several rounds show a development that an attendance list cannot.
Group level evaluation
The evidence works without personal rankings, which makes internal agreement easier.
Export for documentation
Reports can be exported and filed with the rest of your risk management records.
What evidence has to deliver
Attendance list versus solid documentation.
With Conbool | Attendance list | |
|---|---|---|
| Shows when training happened | yes | yes |
| Shows which content was delivered | yes | usually not |
| Shows a development over time | yes | no |
| Separate record for management | yes | rarely |
| Without personal rankings | yes | depends on how it is kept |
This page is not legal advice. Whether and to what extent your company is affected depends on sector, size and the applicable national provisions.
Frequently asked questions
Who is covered by the training obligation?
Why is management named separately?
How often must training take place?
Is a phishing simulation mandatory?
Is an induction session enough?
What about the works council?
Related solutions
NIS2 im Überblick
Richtlinie, Umsetzungsgesetz und BSIG: wer betroffen ist und was gilt.
Security Awareness Training
Schulung, die sich gegenüber einer Prüfung belegen lässt.
Phishing-Simulation
Den Ernstfall üben, ohne Einzelne vorzuführen.
Phishing-Schutz
Die technische Abwehr, bevor eine Nachricht den Menschen erreicht.
NIS-2 E-Mail-Sicherheit
Alle E-Mail-Anforderungen nach Paragraf 30 BSIG im Überblick.
Obligation and evidence in one go
We set up the programme for staff and management and show what the final record looks like.