Article updated: 23.07.2026
NIS 2 Directive and Mandatory Awareness Training: Why the Management Board Is Responsible for Employee Education and How to Meet the Requirements?
The NIS 2 Directive introduces two separate educational obligations: regular training for Management Board members is an explicitly stated legal requirement, while cyber hygiene and employee training are a mandatory element of the cybersecurity risk management system.
Following the entry into force of the amendment to the Act on the national cybersecurity system, which transposes the NIS 2 Directive into Polish law, these obligations apply to essential and important entities — meaning medium and large companies from strategic sectors such as energy, transport, healthcare, banking, manufacturing, and digital services. The regulations emphasise the continuity and measurability of educational activities, moving away from the model of a single e-learning lecture. Find out how to translate these requirements into real organisational resilience without burdening internal IT and HR teams.
Does the NIS 2 Directive impose an obligation to provide cybersecurity training?
Yes. Art. 21(2)(g) of the NIS 2 Directive explicitly lists "basic cyber hygiene practices and cybersecurity training" as a mandatory element of the risk management system that essential and important entities must implement.
In addition, Art. 20(2) imposes a separate, even more stringent obligation: regular training for members of the management body (the Board), so that they are able to identify risks and assess cybersecurity management practices. The scope and frequency of training for other employees is left to the proportionality of the company's size and risk level — but the obligation to have a continuous educational programme is beyond dispute.
Most discussions around the NIS 2 Directive focus on technology: new SIEM-class systems, advanced firewalls, audits, or ISO procedures. These are critical elements, but amid the flood of technical requirements it is easy to lose sight of a fundamental factor — the human side of cyber resilience.
The NIS 2 Directive is unequivocal: employee education and Board training become a legal requirement for essential and important entities. Board members do not need to deliver training themselves, but they have a statutory obligation to undergo regular training (Art. 20(2)) and must be able to provide hard evidence that the company's employee education process is continuous, effective, and measurable — since it is they who approve and oversee cybersecurity risk management measures (Art. 20(1)) and who may be held liable for their absence.
When an employee clicks a malicious link and an incident occurs, an auditor or regulator will not only ask whether the server had up-to-date patches. Specific questions about people will follow:
- Were employees regularly and practically prepared for that type of attack?
- Was the education continuous, or was it merely a one-off event to be "ticked off"?
- Can you demonstrate measurable progress and prove the effectiveness of the actions taken?
How to meet NIS 2 requirements without burdening the IT department? The Awareness as a Service (AaaS) model
At Mission Cybersecurity, we believe that security must be simple, friendly, and understandable for everyone — from HR and finance, to production and senior management.
To help companies meet NIS 2 requirements without engaging internal IT or HR resources, we have created a comprehensive system delivered in the Awareness as a Service (AaaS) model. All activities are carried out and supervised by our dedicated account manager.
| # | AaaS Programme Element | Role in the Cycle | What Does It Include? |
|---|---|---|---|
| 1 | Educational Game "Mission: Cybersecurity" | Start | An approximately 180-minute scenario-based game built on gamification; over 100 decisions in realistic situations; learning over 80 key security principles through experience |
| 2 | 12-Month Awareness Building Programme | Continuity | Security culture assessments (5 pillars), knowledge bites and quizzes, educational materials (newsletters, posters, desktop wallpapers) |
| 3 | Controlled Phishing Simulations | Practice & Testing | Monthly phishing attacks, two alternating difficulty levels, immediate education at the point of click — without penalising employees |
1. Interactive Educational Game "Mission: Cybersecurity"
Instead of dry theory — an engaging, approximately 180-minute scenario-based game built on gamification. Employees step into the roles of characters at a fictional company and make over 100 decisions in realistic business situations, learning over 80 key security principles through experience. They learn by doing, seeing the immediate consequences of their choices in a safe test environment.
2. Proprietary Awareness Building Programme (12-month cycle)
To ensure the continuity required by NIS 2, the game serves as an introduction to the year-long programme. It consists of:
- Security culture assessments (before implementation and after 12 months) measuring 5 key pillars: Accountability, Competence, Support, Atmosphere, and Behaviour.
- Knowledge bites and quizzes reinforcing habits in key areas (e.g. password hygiene, remote work, AI-related threats).
- Educational materials (newsletters, posters, desktop wallpapers) that keep security topics alive in everyday conversations.
3. Simulated Phishing Attacks
Once a month, our team carries out controlled phishing attacks. We use two alternating difficulty levels (even months — advanced attacks; odd months — easier ones), allowing objective measurement of changes in team vigilance over time. If an employee clicks a malicious link, they are directed to an educational page that immediately explains how to spot a fake message — we educate rather than penalise.
How to prove NIS 2 compliance to an auditor? Measurable evidence
In accordance with Art. 32 and 33 of the NIS 2 Directive, supervisory authorities may require essential and important entities to provide a documented cybersecurity policy and evidence of its implementation, including security audit results. Thanks to our educational platform, the Management Board and those responsible for NIS 2 compliance gain a full set of hard data meeting these requirements:
- Attendance reports and login history: A record indicating exactly who completed which training modules and when.
- Measurable competence growth: Comparison of results from the initial test (before training) with the final test (after completing the game and knowledge bites).
- Phishing simulation reports: Monitoring of Click Rate and Data Entry Rate indicators over time.
- Evidence of cultural change: A detailed report with culture level assessment results comparing outcomes before and after the year-long awareness building programme.
"The implementation of the year-long programme in the organisations we analysed resulted in a 15 percentage point increase in the Support pillar. Employees stopped fearing procedures and began treating them as understandable tools for everyday work." — from our Cybersecurity Culture Report.
Summary: Turn a Legal Obligation into Real Protection
The NIS 2 Directive need not be seen as a burdensome regulatory obligation. It is an excellent opportunity to strengthen your organisation and build a team that serves as the first and most effective line of defence against cybercriminals.
Instead of taking risks and relying on outdated methods, opt for a solution that combines the psychology of habit change with an engaging form of communication.
Want to see how our game engages employees and helps meet NIS 2 requirements?
Try the Free DEMOFrequently Asked Questions
Are employee training sessions mandatory under the NIS 2 Directive?
Yes. For essential and important entities covered by the NIS 2 Directive, achieving compliance requires implementing cyber hygiene and training as a mandatory element of risk management (Art. 21(2)(g)). In addition, members of the Management Board have a separate, explicitly stated obligation under the regulations to undergo regular training (Art. 20(2)).
How to meet NIS 2 education requirements without burdening the IT department?
The ideal solution is the Awareness as a Service (AaaS) model. All activities — including the training platform, scenario-based game, quizzes, and monthly phishing attacks — are fully managed and reported by external specialists.
Sources: Act of 23 January 2026 amending the Act on the national cybersecurity system (Journal of Laws 2026, item 252) | Directive of the European Parliament and of the Council (EU) 2022/2555 (NIS 2)
