What NIS2's Training and Awareness Requirement Means in Practice

Table of contents
Subscribe to newsletter
NIS2 has transformed cybersecurity training from an annual compliance exercise into a measurable governance obligation. With enforcement accelerating across Europe, organizations must show that leaders and employees can recognize, report, and respond to cyber threats rather than merely complete a course. Yet many programs remain generic, infrequent, and poorly documented, leaving a critical gap between regulatory expectations and operational readiness. This article explains what Articles 20, 21, and 23 require in practice, why regulators are scrutinizing human risk, and how organizations can build continuous, role-specific, audit-ready awareness programs that reduce exposure while demonstrating defensible compliance in a hostile threat landscape.
NIS2 enforcement is no longer theoretical. As of mid-2026, 23 of the 27 EU member states have transposed the directive into national law. The first fines have already been issued in Belgium, Italy, and Hungary, while four countries have been referred to the Court of Justice of the European Union for failing to meet the transposition deadline.
Yet organizations remain significantly underprepared. A spring 2026 survey of 670 business leaders across eight countries found that 84% of organizations already facing active NIS2 enforcement admit they are not ready. This article examines what NIS2's training and awareness requirement actually demands, why the human layer has become a central focus of cybersecurity regulation, and what it takes to build a program that can withstand an audit rather than simply satisfy an internal checklist.
Training Became a Legal Obligation, Not a Courtesy
For years, security awareness training occupied a gray area. It was considered good practice and but it was rarely a firm legal requirement with clearly defined consequences. NIS2 closes that gap.

- Article 20 requires the management bodies of essential and important entities to complete cybersecurity training themselves, giving them sufficient knowledge to identify risks and assess whether the measures presented to them are adequate.
- Article 20 also encourages, and through national transposition in several member states now requires, similar training for the broader workforce.
- Article 21(2)(g) goes further by listing basic cyber hygiene practices and cybersecurity training among the mandatory risk management measures that every in-scope entity must implement.
- Article 23 then closes the loop. When an incident occurs, staff must recognize and escalate it quickly enough to support the 24-hour early warning and 72-hour incident notification requirements. That capability must be trained. It cannot simply be assumed.
Taken together, these three articles transform cybersecurity training from a compliance line item into a governance obligation with clearly defined accountability and potential personal exposure. National transposition laws in Germany, Italy, and Bulgaria already provide for personal fines against individual directors, separate from penalties imposed on the entity, and some jurisdictions allow courts to suspend individuals from management duties.
Why the Human Layer Is Where Regulators Are Looking
NIS2's focus on training is not simply a matter of regulatory procedure. It reflects where breaches are actually beginning.

The 2026 Verizon Data Breach Investigations Report found that the human element was present in 62% of confirmed breaches, up from 60% the previous year. Phishing alone accounted for 16% of initial access, while pretexting, including voice calls, chat messages, and callback scams, contributed another 6%. When stolen credentials at 13% are included, identity-centered attacks account for 35% of initial access, roughly comparable to software vulnerability exploitation at 31%.
ENISA's threat landscape reporting for July 2024 through June 2025 found that phishing was responsible for 60% of observed initial intrusions across European critical sectors. These are precisely the sectors NIS2 is designed to protect.
The speed gap is the detail that should concern every security awareness leader. The same research found that the median employee clicks a phishing link within 21 seconds of receiving it but takes a median of 28 minutes to report a suspicious message. That gap of nearly half an hour can be the difference between an isolated click and a significant security incident. Closing that gap is exactly what effective awareness training is designed to achieve.
The Anti-Phishing Working Group tracked approximately 3.8 million phishing attacks globally throughout 2025, a volume that has remained at historically high levels rather than declining. Generative AI has changed the economics of these attacks more than the underlying mechanism. Personalized, well-written lures can now be produced cheaply and at scale, and several 2026 industry reports indicate that AI-crafted phishing campaigns achieve click-through rates several times higher than older, generic scam formats.
The Incidents That Show What Happens When the Human Layer Fails
Statistics can feel abstract. Recent incidents make the consequences much more tangible.
In April 2026, researchers reported that approximately 795 Hungarian government email addresses, spanning 12 of the country's 13 ministries, were circulating in online breach databases. They also found evidence that 97 government computers had been compromised by credential-stealing malware. The exposure was traced primarily to employees reusing work passwords on personal, non-work platforms, a textbook cyber hygiene failure of the kind Article 21(2)(g) is intended to prevent.
In mid-2026, the extortion group ShinyHunters claimed responsibility for compromising a major healthcare and diagnostics company by taking over a single employee's identity and access account through a voice phishing call, rather than by exploiting a software vulnerability. Once inside, the attackers moved across connected platforms and claimed to have obtained more than 30 million rows of personal data, more than 1 million Social Security numbers, and tens of millions of medical records and orders. One convincing phone call targeting a single employee opened the door to an enterprise-wide breach.
These were not isolated cases. Healthcare, a sector explicitly covered by NIS2, recorded 410 ransomware attacks in the first half of 2026 alone, a 14% increase year over year. During the same period, 189 large breaches affected an estimated 19 million individuals. According to CrowdStrike, voice phishing increased by 442% in the second half of 2024 and has continued to feature prominently in intrusion reporting since.
Each of these incidents illustrates the same underlying problem. The initial failure was not necessarily a firewall or an unpatched server. It was a person, often operating under time pressure or social pressure, making a judgment call. A well-designed training and awareness program should prepare employees to recognize those moments, respond appropriately, and prevent a single decision from becoming an enterprise-wide incident.
Where Most Programs Still Fall Short

Across early NIS2 audits, the same gaps keep surfacing.
- Content does not align with the risk register. Auditors assess whether an organization that identifies social engineering as a significant threat also provides corresponding phishing simulations and social engineering training. A mismatch can be viewed as a documented risk rather than a minor compliance gap.
- Training is annual rather than continuous. A once-a-year session no longer reflects the intent of Article 21. The expectation is a recurring cadence of short, relevant, and up-to-date training touchpoints rather than a single annual session that is not revisited for another 12 months.
- Evidence is fragmented. Spreadsheets and manual attendance records may be insufficient once an organization is subject to proactive supervision. Auditors expect clear, accessible training records, including completion data by role and department, that can be produced on demand.
- Everyone receives the same content. Board members, finance employees, and systems administrators face different risks and make different security decisions. Providing identical training to every employee reduces relevance and fails to develop the role-specific competencies the directive is designed to promote.
From Checkbox Training to Human Risk Intelligence

The organizations managing NIS2's training requirements most effectively are not necessarily the ones delivering the most training hours. They are the ones treating people as they already treat networks and endpoints: as a risk surface that can be measured, monitored, and continuously improved, rather than as a compliance box to check once a year.
This shift is at the core of Human Risk Intelligence. Instead of asking only whether someone completed a course, a Human Risk Intelligence approach asks a more meaningful question: Based on this person's role, previous simulation results, access level, and the threats currently targeting their sector, what is their actual level of risk today, and what is the most useful thing they should learn next?
In practice, this means combining phishing simulation results, policy training completion, and real-world incident reporting into a unified risk signal for each employee and department. Organizations can then use that signal to determine who needs a targeted refresher this week, rather than waiting for the next scheduled training module. It is the difference between a fire drill that everyone attends once a year and a smoke detector that is always listening.
This approach also creates the type of evidence regulators want to see. A risk score that improves over time and can be linked to specific interventions is a far stronger audit artifact than a collection of completion certificates. It demonstrates the outcome Articles 20 and 21 are ultimately designed to achieve: a workforce capable of identifying and responding to cyber risk, not one that has simply sat through a presentation about it.
Building a Program That Survives an Audit

A defensible, NIS2-aligned training and awareness program typically includes the same core elements, regardless of sector or country.
- Start with a gap assessment
Map your current training content directly to the measures in Article 21(2) and the management obligations in Article 20(2). Identify where existing training does not adequately address those requirements and document the gaps that need to be closed.
- Build a tiered curriculum
Training should reflect each group's responsibilities and level of risk. Board members and senior management need content covering governance, personal liability, risk oversight, and proportionality. Mid-level managers need a practical understanding of incident response and business continuity. Technical and security teams require deeper, role-specific training. The broader workforce needs practical cyber hygiene guidance and a simple, low-friction way to report suspicious activity.
- Set a cadence and maintain it
Training should be continuous rather than concentrated into a single annual session. A practical baseline is a short monthly or quarterly touchpoint, supported by a comprehensive annual refresher. Additional training should be delivered when emerging threats or changes in the organization's risk profile make it necessary.
- Assign an owner and establish a review cycle
Responsibility for the program should be clearly assigned. Someone within security, compliance, or a shared function should monitor the threat landscape and review training content regularly. Content should also be updated when a new attack pattern, regulatory development, or internal near miss identifies a gap that employees need to address.
- Maintain audit-ready evidence
Keep clear records of training completion, assessment results, phishing simulation outcomes, and content reviews. Document when materials were last reviewed, what changed, and why. The evidence should be organized so that an external auditor with no prior knowledge of the program can understand what was delivered, to whom, when, and with what results.
From Compliance Deadlines to Active Enforcement
The NIS2 transition period is ending in real time. Bulgaria's reduced personal fines for management bodies expired at the beginning of June 2026, bringing the full statutory penalties into effect. Germany's BSI is actively auditing tens of thousands of registered entities. Belgium set its first conformity assessment deadline in April 2026 and did not accept self-declarations as a substitute for verified documentation. More member states are expected to follow a similar pattern, with a relatively quiet transposition period giving way to rapid and increasingly rigorous supervision.
The organizations best positioned for this shift are the ones already treating human risk like any other risk on the register: something that is measured, assigned clear ownership, and continuously reduced rather than simply assumed to be under control. Book a demo to learn how to build a better training program to fulfill NIS2 requirements.
BOOK A DEMO
See usecure in action
A 30-minute walkthrough of how to cut human risk across your users, tailored to MSPs and IT teams.
Subscribe to newsletter
Discover how professional services firms reduce human risk with usecure
See how IT teams in professional services use usecure to protect sensitive client data, maintain compliance, and safeguard reputation — without disrupting billable work.
Related posts
Explore more insights, updates, and resources from usecure.



