NIS2 security awareness training: a practical programme and evidence checklist

Plan NIS2 security awareness training by role, connect activities to risks, and keep useful evidence. Includes management and employee training distinctions.

CyberPlay editorial team · Published · Updated · 8 min read

Guide and exercises in English

Scene from Ransomware Survival.

Expand image

From the CyberPlay Ransomware Survival gallery. Illustrative game scene; any interface text shown is in English.

NIS2 security awareness training is best planned as part of an organisation’s risk-management programme. Start with the decisions people must make, identify the groups responsible for them, and preserve evidence of what was taught and reviewed. Buying content or collecting completion records is only one part of that work.

This guide explains the EU directive’s training context as checked on 13 September 2026, then provides an original programme matrix and review exercise. National implementation and sector rules determine the obligations that apply to a particular entity. The programme suggestions below are practical design choices, not a prescribed legal syllabus or a certification scheme.

What you’ll take away

  • Separate management-body training from the employee awareness programme.
  • Check national implementation and entity scope before making a compliance claim.
  • Map each activity to a risk, a role, an observable decision and a retained record.
  • Use scenario practice alongside governance, procedures and technical controls.

Confirm scope before labelling the programme

Assign a named owner to determine which legal entity, services and locations the programme covers. Record the applicable national law, sector-specific obligations, and the internal decision about scope. A group-wide learning platform may serve several entities with different responsibilities; the learning records should still be understandable at the relevant organisational level.

Keep a short scope note beside the training plan. Include the date checked, the responsible function and the source used. Revisit it after acquisitions, a material change in services, or a relevant legal update. Avoid adding a “NIS2 compliant” badge to every exercise. The phrase would obscure the difference between useful supporting content and an assessed organisational obligation.

Give management a decision exercise of its own

A management session should let participants practise asking questions about risk ownership, proposed controls, resources and service impact. Present a realistic decision with incomplete information: a supplier supports an essential workflow, a security improvement competes with delivery commitments, and the operational owner needs direction.

Ask leaders which evidence they require, who owns the residual risk, and when the decision will be reviewed. Record the reasoning and the follow-up questions. This exercise is an original discussion format, not an accredited management course. Where accreditation or specific qualifications are required by national law, use a provider that can substantiate those requirements and retain the relevant evidence.

Ransomware Survival gameplay: comparing security choices with fictional game money.

Expand image · Game screenshot · English interface

  1. Match controls to failures

    Choose controls that address the failure being considered, rather than assuming the most expensive option fits every problem.

  2. Consider cost and time

    Compare cost, time and operational tradeoffs; the game's money and outcomes are fictional teaching aids, not investment forecasts.

Ransomware Survival gameplay: comparing security choices with fictional game money.

Translate risk into employee actions

For employees, replace abstract topic headings with responsibilities. “Incident handling” might mean recognising a suspicious message, reporting it through the approved channel, and describing whether an attachment was opened. It should not imply that every employee must investigate the incident or determine a regulatory reporting threshold.

Ask the security team to approve the expected response in each scenario. A finance employee may hold a payment change; a receptionist may contact the named host; an engineer may follow an approved removable-media process. Training should make those boundaries easy to remember. Where the procedure is unclear, fix the procedure before testing whether people follow it.

Role: Who needs which capability? Objective: What should that person be able to do? Practice: Choose an appropriate activity and debrief. Evidence: Record delivery, assessment and follow-up.

Expand image

From requirement to evidence. A planning framework; assess your entity and applicable national rules. Original CyberPlay explanatory diagram.

Build your role-to-evidence matrix

Use this original matrix as a working document. Replace the example roles with your own, attach the relevant procedure, and set an owner for each row. The records listed are useful programme evidence; they are not represented as a complete list demanded by NIS2. Keep a version so a later reviewer can identify exactly what participants saw.

Build your role-to-evidence matrix
AudienceDecision to practiseSuggested activityUseful record
Management bodyEvaluate a risk decision and the resources neededFacilitated supplier-risk discussionAgenda, attendance, materials, questions and actions
All personnelRecognise uncertainty and use the reporting routeMessage scenario plus reporting walkthroughAssigned version, participation and follow-up
Finance and procurementVerify changed payment details independentlySupplier-change role playScenario, answer rationale and process owner
IT and operational specialistsApply authorised technical proceduresRole-specific practical trainingCompetence objective and assessed task
New starters and contractorsFind local rules before requesting accessOnboarding scenario and contact checkCoverage, exceptions and completion record

Make one training record interpretable

A useful record explains the event without requiring someone to reconstruct it from screenshots. For a supplier-verification session, record the audience, date, objective, content version, facilitator or delivery method, participation status, assessment method, and any unresolved process questions. If no assessment took place, say so; attendance alone should not be renamed competence.

Keep individual data proportionate to the purpose. Decide who can see detailed responses and how long they are needed, then communicate those arrangements to staff. A management summary usually needs coverage, observed gaps and accountable actions. It rarely needs a public ranking of individual mistakes. Retention and access decisions belong in the organisation’s normal governance process.

Phishing Detective 3D gameplay: reviewing a supplier invoice.

Expand image · Game screenshot · English interface

  1. Compare the changed details

    Check which payment details changed and whether the request matches the expected invoice and work.

  2. Compare with trusted records

    Compare with a trusted invoice, then verify changed bank details through the supplier contact already on record.

Phishing Detective 3D gameplay: reviewing a supplier invoice.

Practise reviewing an incomplete evidence pack

Give a programme owner the following fictional situation. Ask them to identify what the evidence supports, what remains unknown, and the smallest useful next action. This can be run as a ten-minute discussion at a quarterly programme review.

Choose a cadence and explain why

Set timing around induction, changes in responsibility, relevant threats, incidents and scheduled refreshers. NIST’s learning-programme guidance supports continuing evaluation and improvement. Use that approach to explain your training cadence instead of assuming one annual event fits every role.

A practical starting pattern is onboarding, a focused periodic exercise, and a later revisit of a high-priority decision. Your organisation may need a different frequency. Record the reason, ensure people on leave or working shifts have a route to participate, and reserve time for follow-up. Repetition is useful only when the task remains relevant and the feedback addresses a real learning need.

Section sources: Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1

Check the stronger Romanian wording where relevant

Romania’s consolidated OUG 155/2024, amended by Law 124/2025, requires accredited management training and regular training for all personnel of essential and important entities in Article 14(2). A game-completion record does not establish that an accredited-course requirement has been met.

For a Romanian programme, keep the management training route and the broader workforce activities clearly identified. The programme-selection guide in this collection explains general buying criteria; its Romanian edition also covers local examples. Use the current national text and applicable guidance when approving your programme; an English summary of the EU directive is insufficient to settle every Romanian requirement.

Section sources: OUG nr. 155/2024, consolidated text including Law nr. 124/2025

Review whether people can use the process

At the next review, sample a few realistic decisions. Can a new starter locate the reporting route? Can finance verify a supplier change when its usual contact is absent? Can a manager identify the owner of a risk decision? Record the answer and assign responsibility for any gap. A missing contact or an unusable approval workflow is a programme finding, even when everyone passed the quiz.

CyberPlay can provide game-based practice for everyday awareness decisions. Select an appropriate topic, connect it to the local procedure, and retain activity evidence with a precise description. Continue to manage legal scope, accredited requirements, specialist competence and governance through the organisation’s wider programme. That makes each learning activity easier to justify and review.

Ransomware Reaction gameplay: preparing a useful incident report.

Expand image · Game screenshot · English interface

  1. Include time and device

    Report the observed symptoms, when they appeared, and the affected device through the organisation's approved reporting route.

  2. Distinguish observation from diagnosis

    Separate direct observations from suspected causes so responders can investigate without treating an early guess as fact.

Ransomware Reaction gameplay: preparing a useful incident report.

Put the decision into practice

Explore the relevant CyberPlay games, choose a suitable challenge, and discuss how its decisions connect to your own workplace procedures.

Explore practice games

Sources and further reading

  1. Directive (EU) 2022/2555, Articles 20 and 21 — EUR-Lex. Accessed 2026-09-13
  2. Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1 — NIST. Accessed 2026-09-13
  3. OUG nr. 155/2024, consolidated text including Law nr. 124/2025 — Portal Legislativ, Ministry of Justice of Romania. Accessed 2026-09-13

Keep exploring

All articles

Contact · About