NIS2 · European Union

NIS2 trains the board.
Your people need it too.

NIS2 (Directive (EU) 2022/2555) requires members of management bodies to follow cybersecurity training, lists basic cyber hygiene practices and cybersecurity training among the risk-management measures entities in scope must take, and asks Member States to encourage regular training for employees.

Framework
Directive (EU) 2022/2555, to be transposed by 17 October 2024
Management
Training required for members of management bodies (Article 20(2))
Staff
Basic cyber hygiene and cybersecurity training (Article 21(2)(g))
Incidents
Early warning in 24 hours, notification in 72 hours, final report within a month

What NIS2 says about people

Training is a required
risk-management measure.

Articles apply to essential and important entities.

ProvisionWhat it saysApplies to
Article 20(2)Members of management bodies are required to follow training, and entities are encouraged to offer similar training to employees regularly.Essential and important entities
Article 21(2)(g)Risk-management measures include basic cyber hygiene practices and cybersecurity training.Essential and important entities
Implementing Regulation 2024/2690, Annex 8.1Awareness programmes are repeated over time, cover new employees and, where appropriate, are tested for effectiveness.Listed digital infrastructure and digital service providers
Implementing Regulation 2024/2690, Annex 8.2Training is relevant to the job function, and its effectiveness is assessed.Listed digital infrastructure and digital service providers
Article 23Early warning within 24 hours, incident notification within 72 hours and a final report within one month.Essential and important entities

Invoices, parcels, executives

Familiar lures,
new channels.

Invoice fraud, parcel notices and urgent requests from senior leaders now arrive on Teams, Slack and the phone as well as email.

Simulated example
Slack17:55

“CFO” · external workspace

Quick favour before the board

Can you process a supplier payment for me tonight? I’m in meetings, details in the link.

  • External workspace
  • Unusual request
  • Bypasses the process
A sample executive impersonation scenario.

Expectation to record

The people side
of your NIS2 record.

TRAINING

Staff complete security training.

LMS completions, assessments and certificates.

SIMULATION RESULTS

Staff tested on realistic threats.

Outcomes per channel, team and campaign.

REPORT LOGS

Staff report suspicious messages.

Phishing Reporter logs with automated analysis.

POLICY ACKNOWLEDGEMENTS

Staff accept your policies.

Dated records per person and version.

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. Directive (EU) 2022/2555 (NIS2)14 December 2022 · Articles 20, 21 and 23
  2. Commission Implementing Regulation (EU) 2024/269017 October 2024 · Annex sections 8.1 and 8.2
  3. Commission refers four Member States to the Court of Justice over NIS28 July 2026 · Ireland, Spain, France and the Netherlands
  4. Regulation (EU) 2022/2554 (DORA)Applies from 17 January 2025 · Article 13(6), compulsory staff training

Questions buyers ask

Frequently asked questions.

Does NIS2 require phishing simulation?

No. It requires cybersecurity training, and for certain digital providers, awareness programmes tested for effectiveness where appropriate. Phishing is mentioned only in the recitals. Simulations are a practical way to show that training works.

Has every EU country transposed NIS2?

Not all. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose it. Check the national law that applies to you.

Does KeenSec make us compliant with NIS2?

No tool makes you compliant on its own. KeenSec helps you run and evidence staff awareness; your auditors and national authorities decide compliance.

Does NIS2 apply to us?

That depends on your sector, size and national implementation. Check with your legal and compliance team.

Let’s connect the dots

Train for the real attack.
Keep the real record.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo