What training does NIS2 require of management bodies and staff?
The NIS2 Directive (Directive (EU) 2022/2555) requires EU Member States to ensure that members of the management bodies of essential and important entities follow cybersecurity training (Article 20(2)), and to encourage similar regular training for employees. Article 21(2)(g) also makes basic cyber hygiene practices and cybersecurity training a mandatory risk management measure. Management bodies approve and oversee those measures and can be held liable for infringements.
By the Knowledge Foundry editorial team. How we write and check these pages
- Published
- Updated
- Reading time
- 8 min
- Jurisdiction
- European Union (Directive (EU) 2022/2555, applied through national transposing laws)
- Regulator
- National competent authorities designated by each Member State (in Portugal, the Centro Nacional de Cibersegurança and sectoral authorities); the European Commission and ENISA at EU level
Key takeaways
- Article 20(2): members of management bodies are required to follow training so they can identify risks and assess cybersecurity risk management practices; employees should be offered similar training regularly.
- Article 21(2)(g) lists basic cyber hygiene practices and cybersecurity training among the minimum risk management measures for all essential and important entities.
- NIS2 is a directive, so the binding obligation is the national transposing law. The transposition deadline was October 17, 2024, and many Member States were late.
- Portugal transposed NIS2 through Decree-Law 125/2025 of December 4, 2025, which entered into force on April 3, 2026, with the Centro Nacional de Cibersegurança (CNCS) as national cybersecurity authority.
- Commission Implementing Regulation (EU) 2024/2690 sets detailed awareness and training requirements for digital infrastructure and digital service providers, including assessing training effectiveness.
What does NIS2 require for training?
NIS2 contains two training obligations: a personal training requirement for members of management bodies in Article 20(2), and an organizational requirement in Article 21(2)(g) to implement basic cyber hygiene practices and cybersecurity training. As at September 2026, both apply through national transposing laws across the EU.
Article 20(2) of Directive (EU) 2022/2555 reads: "Member States shall ensure that the members of the management bodies of essential and important entities are required to follow training, and shall encourage essential and important entities to offer similar training to their employees on a regular basis, in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity."
Article 21(2) then lists ten minimum cybersecurity risk management measures. Point (g) is "basic cyber hygiene practices and cybersecurity training". Point (i), human resources security, access control policies and asset management, also shapes who needs what training. Recital 89 gives examples of cyber hygiene, including user awareness and training on cyber threats, phishing and social engineering. These measures sit inside a wider compliance training program rather than replacing it.
Why does it matter that NIS2 is a directive?
Because NIS2 is a directive, organizations must comply with their national law, not with the directive text directly. An EU regulation, such as DORA or the GDPR, is binding in its entirety and directly applicable in every Member State from its application date. A directive sets results that each Member State must achieve through its own legislation, a process called transposition, and national laws can add detail or go further.
Article 41 of NIS2 required Member States to adopt and publish transposing measures by October 17, 2024 and to apply them from October 18, 2024. For readers outside the EU, the practical effect is that a group operating in several Member States may face slightly different training, registration, and reporting rules in each one, all traceable back to the same Article 20 and Article 21.
Many Member States missed the deadline. The European Commission's NIS2 transposition page records that on May 7, 2025 it sent reasoned opinions to 19 Member States, including Portugal, for failing to notify full transposition, and the Commission has since referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union.
How has Portugal transposed NIS2?
Portugal transposed NIS2 through Decree-Law 125/2025, published on December 4, 2025, which approves the new Regime Jurídico da Cibersegurança (Cybersecurity Legal Regime). Under Article 11 of the decree-law it entered into force 120 days after publication, on April 3, 2026, and Article 9 revokes the earlier framework under Law 46/2018. The national cybersecurity authority is the Centro Nacional de Cibersegurança (CNCS).
Article 25 of the regime requires the management, direction, and administration bodies of essential and important entities to approve the cybersecurity risk management measures, supervise their implementation, and ensure that cybersecurity training is carried out at regular intervals to promote an internal culture of cyber risk management. Office holders can answer for acts or omissions committed with intent or gross negligence (Article 25(2)), and fines for an essential entity that is a legal person can reach 10 million euros or 2% of worldwide annual turnover, whichever is higher.
The list of cybersecurity measures in Article 27(1), which includes basic cyber hygiene and cybersecurity training for top management and workers, only takes effect 24 months after the CNCS publishes the implementing regulations (Article 10(2) of the decree-law).
The Portuguese regime covers 17 sectors (Annexes I and II) and a significant part of public administration, and covered entities must identify themselves on an electronic platform provided by the CNCS (Article 8). For financial entities, Article 15 designates the Banco de Portugal, the Comissão do Mercado de Valores Mobiliários, and the Autoridade de Supervisão de Seguros e Fundos de Pensões as special national cybersecurity authorities for digital operational resilience matters.
What are management bodies accountable for under NIS2?
Management bodies must approve the Article 21 cybersecurity risk management measures, oversee their implementation, and can be held liable for the entity's infringements of Article 21 (Article 20(1)). Training is the mechanism that makes this accountability credible: a board cannot oversee measures it does not understand.
Enforcement is set by national law within minimums in NIS2. Article 34 requires maximum fines of at least 10 million euros or 2% of total worldwide annual turnover for essential entities, and at least 7 million euros or 1.4% for important entities, whichever is higher. For essential entities, Article 32(5) allows authorities, as a last resort, to request a temporary prohibition on a natural person at chief executive officer or legal representative level from exercising managerial functions.
Is there more detailed guidance on what the training must cover?
Yes, for certain digital sectors. Commission Implementing Regulation (EU) 2024/2690 sets detailed Article 21 requirements for DNS service providers, TLD name registries, cloud computing, data center, content delivery network, managed service and managed security service providers, online marketplaces, search engines, social networking platforms, and trust service providers. Section 8 of its annex covers cyber hygiene and security training, and is a useful benchmark for other sectors.
- Point 8.1.2: an awareness raising program for employees, including members of management bodies, and for direct suppliers and service providers where appropriate, scheduled so activities are repeated and cover new employees.
- Point 8.1.3: the awareness program is tested for effectiveness where appropriate and updated at planned intervals as threats change.
- Point 8.2.1: identify employees whose roles require security relevant skills and ensure they receive regular training.
- Point 8.2.3: role training must be relevant to the job function and its effectiveness must be assessed; it covers secure configuration and operation, known cyber threats, and behavior when security relevant events occur.
- Point 8.2.4: staff moving into roles that need security skills are trained on transfer.
How do you evidence NIS2 training to a supervisor?
Supervisors look for proof that directors actually gained the knowledge Article 20(2) describes and that staff training matches roles and risks, not only attendance lists. The table below is an illustrative mapping from each obligation to a learning outcome and the evidence that would support it.
| Obligation | Learning outcome | Assessment evidence |
|---|---|---|
| Article 20(1): approve and oversee risk management measures | Board members can explain the entity's main cyber risks and the measures they approved | Board minutes showing informed challenge, plus a short scenario based knowledge check |
| Article 20(2): management body training | Board members can identify risks and assess risk management practices and their effect on services | Dated training record per director, content version, and assessment result |
| Article 21(2)(g): cyber hygiene and training | All staff apply defined cyber hygiene practices, such as reporting phishing and protecting credentials | Awareness completion by population, phishing simulation trends, and incident reporting rates |
| Implementing Regulation annex point 8.2: role based security training | Staff in security relevant roles perform secure configuration and incident response tasks correctly | Role training matrix, practical assessments, and effectiveness review |
| Article 21(2)(d) and annex point 8.1.2: suppliers | Direct suppliers with access know the entity's security requirements and contact points | Contract clauses, supplier attestations, and access linked training records |
A training matrix that links each role to its required modules and refresh cycle makes this evidence easy to produce. The guides on reporting training compliance to the board and preparing training records for an audit cover the mechanics.
Are the NIS2 training rules changing?
No change to Article 20 or Article 21(2)(g) has been adopted as at September 2026. On January 20, 2026 the Commission proposed targeted amendments to NIS2 (COM(2026) 13), which it describes as simplifying jurisdictional rules, streamlining ransomware data collection, and facilitating supervision of cross-border entities, complementing a single entry point for incident reporting proposed in the Digital Omnibus. These are proposals and still need agreement by the European Parliament and the Council.
How does Knowledge Foundry approach this?
Knowledge Foundry models the NIS2 obligations, the national transposing provisions, and role competencies as linked objects with defined assessment points. Board training, staff awareness, and role based security training then trace back to Article 20 and Article 21, and the same concepts can be mapped to DORA or ISO/IEC 27001 where an entity is subject to both.
Frequently asked questions
Does NIS2 say how many hours of training directors need?
No. Article 20(2) sets an outcome, not a duration: directors must gain sufficient knowledge and skills to identify risks and assess cybersecurity risk management practices and their impact on services. National laws or authorities may add detail, so check the transposing law in each Member State where the entity is covered.
Is employee training mandatory under NIS2 or only encouraged?
Article 20(2) only requires Member States to encourage similar training for employees. However, Article 21(2)(g) makes basic cyber hygiene practices and cybersecurity training a mandatory risk management measure for the entity, so in practice staff training is required, scaled to risk and role.
Do financial entities covered by DORA also need to follow NIS2 training rules?
NIS2 recital 28 treats DORA as a sector specific act for financial entities, so DORA's ICT risk management provisions, including its training requirements, apply instead of the equivalent NIS2 provisions. Financial entities should build training to DORA and confirm how their national NIS2 law treats them.
When did Portugal's NIS2 law take effect?
Decree-Law 125/2025, published December 4, 2025, entered into force on April 3, 2026, 120 days after publication (Article 11). Entities already operating must register on the CNCS electronic platform within 60 days after the platform is made available (Article 8(1) of the regime). Some provisions, including the Article 27 list of cybersecurity measures, take effect 24 months after the CNCS implementing regulations are published.
Sources
- Directive (EU) 2022/2555 (NIS 2 Directive), Official Journal of the European Union (EUR-Lex)
- Commission Implementing Regulation (EU) 2024/2690, Official Journal of the European Union (EUR-Lex)
- NIS2 Directive transposition in EU countries, European Commission
- NIS2 Directive: securing network and information systems, European Commission
- Proposal for a Directive as regards simplification measures and alignment with the Cybersecurity Act, European Commission
- Decreto-Lei n.º 125/2025, Diário da República (Portugal)
- Regime Jurídico da Cibersegurança, Centro Nacional de Cibersegurança (CNCS)
This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.