CyberPlay editorial team · Published · Updated · 8 min read
Guide and exercises in English

NIS2 security awareness training is best planned as part of an organisation’s risk-management programme. Start with the decisions people must make, identify the groups responsible for them, and preserve evidence of what was taught and reviewed. Buying content or collecting completion records is only one part of that work.
This guide explains the EU directive’s training context as checked on 13 September 2026, then provides an original programme matrix and review exercise. National implementation and sector rules determine the obligations that apply to a particular entity. The programme suggestions below are practical design choices, not a prescribed legal syllabus or a certification scheme.
What you’ll take away
- Separate management-body training from the employee awareness programme.
- Check national implementation and entity scope before making a compliance claim.
- Map each activity to a risk, a role, an observable decision and a retained record.
- Use scenario practice alongside governance, procedures and technical controls.
Understand the directive’s two training references
Article 20 of Directive (EU) 2022/2555 addresses management approval, oversight and training; it also asks Member States to encourage regular similar employee training. Article 21(2)(g) includes basic cyber hygiene and cybersecurity training within risk-management measures. These provisions should be read together and with national implementation.
A useful planning question is therefore broader than “Which annual course should everyone complete?” Ask who needs to understand a risk, who can approve a response, who performs a control, and who needs to report an exception. A generic phishing activity may help several groups, but it cannot replace the management knowledge required to assess risk decisions or the specialist skills needed to operate security controls.
Section sources: Directive (EU) 2022/2555, Articles 20 and 21
Confirm scope before labelling the programme
Assign a named owner to determine which legal entity, services and locations the programme covers. Record the applicable national law, sector-specific obligations, and the internal decision about scope. A group-wide learning platform may serve several entities with different responsibilities; the learning records should still be understandable at the relevant organisational level.
Keep a short scope note beside the training plan. Include the date checked, the responsible function and the source used. Revisit it after acquisitions, a material change in services, or a relevant legal update. Avoid adding a “NIS2 compliant” badge to every exercise. The phrase would obscure the difference between useful supporting content and an assessed organisational obligation.
Give management a decision exercise of its own
A management session should let participants practise asking questions about risk ownership, proposed controls, resources and service impact. Present a realistic decision with incomplete information: a supplier supports an essential workflow, a security improvement competes with delivery commitments, and the operational owner needs direction.
Ask leaders which evidence they require, who owns the residual risk, and when the decision will be reviewed. Record the reasoning and the follow-up questions. This exercise is an original discussion format, not an accredited management course. Where accreditation or specific qualifications are required by national law, use a provider that can substantiate those requirements and retain the relevant evidence.

Expand image · Game screenshot · English interface
- Match controls to failures
Choose controls that address the failure being considered, rather than assuming the most expensive option fits every problem.
- Consider cost and time
Compare cost, time and operational tradeoffs; the game's money and outcomes are fictional teaching aids, not investment forecasts.
Translate risk into employee actions
For employees, replace abstract topic headings with responsibilities. “Incident handling” might mean recognising a suspicious message, reporting it through the approved channel, and describing whether an attachment was opened. It should not imply that every employee must investigate the incident or determine a regulatory reporting threshold.
Ask the security team to approve the expected response in each scenario. A finance employee may hold a payment change; a receptionist may contact the named host; an engineer may follow an approved removable-media process. Training should make those boundaries easy to remember. Where the procedure is unclear, fix the procedure before testing whether people follow it.
Build your role-to-evidence matrix
Use this original matrix as a working document. Replace the example roles with your own, attach the relevant procedure, and set an owner for each row. The records listed are useful programme evidence; they are not represented as a complete list demanded by NIS2. Keep a version so a later reviewer can identify exactly what participants saw.
| Audience | Decision to practise | Suggested activity | Useful record |
|---|---|---|---|
| Management body | Evaluate a risk decision and the resources needed | Facilitated supplier-risk discussion | Agenda, attendance, materials, questions and actions |
| All personnel | Recognise uncertainty and use the reporting route | Message scenario plus reporting walkthrough | Assigned version, participation and follow-up |
| Finance and procurement | Verify changed payment details independently | Supplier-change role play | Scenario, answer rationale and process owner |
| IT and operational specialists | Apply authorised technical procedures | Role-specific practical training | Competence objective and assessed task |
| New starters and contractors | Find local rules before requesting access | Onboarding scenario and contact check | Coverage, exceptions and completion record |
Make one training record interpretable
A useful record explains the event without requiring someone to reconstruct it from screenshots. For a supplier-verification session, record the audience, date, objective, content version, facilitator or delivery method, participation status, assessment method, and any unresolved process questions. If no assessment took place, say so; attendance alone should not be renamed competence.
Keep individual data proportionate to the purpose. Decide who can see detailed responses and how long they are needed, then communicate those arrangements to staff. A management summary usually needs coverage, observed gaps and accountable actions. It rarely needs a public ranking of individual mistakes. Retention and access decisions belong in the organisation’s normal governance process.

Expand image · Game screenshot · English interface
- Compare the changed details
Check which payment details changed and whether the request matches the expected invoice and work.
- Compare with trusted records
Compare with a trusted invoice, then verify changed bank details through the supplier contact already on record.
Practise reviewing an incomplete evidence pack
Give a programme owner the following fictional situation. Ask them to identify what the evidence supports, what remains unknown, and the smallest useful next action. This can be run as a ten-minute discussion at a quarterly programme review.
Choose a cadence and explain why
Set timing around induction, changes in responsibility, relevant threats, incidents and scheduled refreshers. NIST’s learning-programme guidance supports continuing evaluation and improvement. Use that approach to explain your training cadence instead of assuming one annual event fits every role.
A practical starting pattern is onboarding, a focused periodic exercise, and a later revisit of a high-priority decision. Your organisation may need a different frequency. Record the reason, ensure people on leave or working shifts have a route to participate, and reserve time for follow-up. Repetition is useful only when the task remains relevant and the feedback addresses a real learning need.
Section sources: Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1
Check the stronger Romanian wording where relevant
Romania’s consolidated OUG 155/2024, amended by Law 124/2025, requires accredited management training and regular training for all personnel of essential and important entities in Article 14(2). A game-completion record does not establish that an accredited-course requirement has been met.
For a Romanian programme, keep the management training route and the broader workforce activities clearly identified. The programme-selection guide in this collection explains general buying criteria; its Romanian edition also covers local examples. Use the current national text and applicable guidance when approving your programme; an English summary of the EU directive is insufficient to settle every Romanian requirement.
Section sources: OUG nr. 155/2024, consolidated text including Law nr. 124/2025
Review whether people can use the process
At the next review, sample a few realistic decisions. Can a new starter locate the reporting route? Can finance verify a supplier change when its usual contact is absent? Can a manager identify the owner of a risk decision? Record the answer and assign responsibility for any gap. A missing contact or an unusable approval workflow is a programme finding, even when everyone passed the quiz.
CyberPlay can provide game-based practice for everyday awareness decisions. Select an appropriate topic, connect it to the local procedure, and retain activity evidence with a precise description. Continue to manage legal scope, accredited requirements, specialist competence and governance through the organisation’s wider programme. That makes each learning activity easier to justify and review.

Expand image · Game screenshot · English interface
- Include time and device
Report the observed symptoms, when they appeared, and the affected device through the organisation's approved reporting route.
- Distinguish observation from diagnosis
Separate direct observations from suspected causes so responders can investigate without treating an early guess as fact.
Put the decision into practice
Explore the relevant CyberPlay games, choose a suitable challenge, and discuss how its decisions connect to your own workplace procedures.
Explore practice gamesSources and further reading
- Directive (EU) 2022/2555, Articles 20 and 21 — EUR-Lex. Accessed 2026-09-13
- Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50r1 — NIST. Accessed 2026-09-13
- OUG nr. 155/2024, consolidated text including Law nr. 124/2025 — Portal Legislativ, Ministry of Justice of Romania. Accessed 2026-09-13
Keep exploring
- Security awareness training for employees: how to choose a programme
Choose security awareness training for employees with practical scenarios, accessible delivery and a clear pilot that checks learning, reporting and programme fit.
EN · 9 min read - Security awareness training plan: a 12-month calendar with practical activities
Use an editable 12-month security awareness training calendar with decision objectives, role-based activities, debrief questions, owners and useful review measures.
EN · 8 min read - Security awareness training metrics: measure more than completion
Measure security awareness with a practical metric dictionary covering participation, decisions, retention and reporting, plus fair comparisons and clear limits.
EN · 8 min read - Security awareness games for employees: how to choose and use them
Choose security awareness games that teach useful workplace decisions. Compare formats, run a sample session, and use a practical evaluation checklist.
EN · 8 min read - Phishing training games: practise the decisions behind a suspicious message
Use phishing training games to rehearse inspection, independent verification and reporting. Includes a fictional supplier message and a practical session plan.
EN · 8 min read - Security awareness for manufacturing: training for shifts and shared devices
Build manufacturing security awareness around shifts, shared terminals, suppliers and escalation. Includes a workforce matrix and a safe discussion exercise.
EN · 8 min read