CyberPlay

NIS2 training requirements: map courses to controls and evidence

Map NIS2 Articles 20, 21 and 23 to security awareness courses, game practice and evidence. See where training helps and which obligations need separate work.

CyberPlay editorial team · Published · Updated · 8 min read

Guide and exercises in English

A staged mailbox-warning email in CyberPlay’s incident-reporting course.

Expand image · Course video frame · English interface

Actual CyberPlay course video frame with English on-screen text. Reporting a suspicious action is a skill to practise within the organisation’s wider incident process.

Security awareness courses can support a NIS2 programme by teaching the decisions behind hygiene, access, recovery and reporting. A useful mapping names the requirement, the learning activity and the evidence still needed outside training. Completing a course cannot establish that the organisation’s controls work or that all NIS2 obligations are met.

This guide is an editorial mapping for programme owners, reviewed on 3 October 2026. Confirm applicability and national requirements with your responsible legal or compliance owner. CyberPlay articles and the interface support nine languages; video narration and course lesson content currently support English and Romanian.

What you’ll take away

  • Separate management-body learning from general employee awareness.
  • Map each course to a decision and an owner, not a compliance percentage.
  • Keep internal reporting practice separate from statutory notification duties.
  • Pair learning records with technical, operational and governance evidence.

1. Confirm the applicable rules before mapping content

NIS2 covers defined types of entities across critical sectors, with size rules and exceptions. The European Commission explains that Member States transpose the directive into national law. Scope, authority and applicable national measures therefore matter before a course catalogue can be assessed. An article language does not determine the legal jurisdiction of its reader.

Start your mapping sheet with the legal entity, the services it provides, the responsible authority, the internal owner and the date of the applicability review. Keep proposals separate from enacted requirements: the Commission’s NIS2 overview describes targeted amendments proposed in January 2026. A training plan should not silently treat a proposal as the rule already in force.

Section sources: NIS2 Directive: securing network and information systems

2. Distinguish the two training provisions

Article 20(2) requires Member States to ensure management-body members receive training to identify risks and assess risk-management practices and service impacts; it encourages similar regular employee training. Article 21(2)(g) separately includes cyber hygiene and cybersecurity training among risk-management measures.

For your programme, this suggests two learning plans. Employees rehearse decisions in their work. Management studies how a service could fail, which controls deserve resources and what evidence justifies accepting residual risk. A phishing lesson can introduce a concrete case for both audiences, but it does not provide the full management curriculum. Add a facilitated discussion using the organisation’s services and decision responsibilities.

Section sources: Directive (EU) 2022/2555: Articles 20, 21 and 23

3. Map a course to its contribution and its gap

The table covers the ten Article 21(2) categories and the management provisions, at learning-programme level. It is not a control assessment. The middle column describes a possible learning contribution; the final column identifies separate organisational work. Some requirements have no direct course equivalent. Do not turn the number of matches into a NIS2 compliance score.

3. Map a course to its contribution and its gap
NIS2 referenceCourse and practical contributionSeparate evidence or work
20(1): approval and oversightUse a case to discuss which management decision is needed.Actual approval, oversight and accountable governance.
20(2): management learningUse a payment or ransomware case to discuss business impact.A management curriculum, participation and a record of decisions.
21(2)(a): risk and system policiesUse course cases to make policy choices understandable.Documented risk analysis and owned security policies.
21(2)(b): incident responseI clicked. What now? practises explaining what happened.An owned response plan, reachable contacts and exercises.
21(2)(c): continuityA cloud icon is not a backup teaches recoverability questions.Backup operation, restoration tests and service recovery plans.
21(2)(d): supplier securityWho gets your screen? supports checking a support request.Supplier risk assessment, contracts and assurance.
21(2)(e): system lifecycle securityReal updates and security warnings explains trusted update routes.Vulnerability management and controlled technical deployment.
21(2)(f): effectiveness evaluationLearning reviews reveal questions needing more explanation.Defined criteria and evidence for evaluating actual controls.
21(2)(g): hygiene and trainingModern email phishing and Who gets your screen? rehearse verification.Role coverage, local procedures and review of learning needs.
21(2)(h): cryptographic practicesNo direct course equivalent is claimed.Cryptography policy, appropriate encryption and key management.
21(2)(i): people, access and assetsName the people before you share supports careful recipient choices.Access reviews, asset records and joiner/leaver procedures.
21(2)(j): authentication and communicationsDeny it if you did not start it rehearses an unexpected MFA prompt.Authentication configuration and appropriate secure communications.

Section sources: Directive (EU) 2022/2555: Articles 20, 21 and 23

4. Use a management debrief to expose missing decisions

After the MFA lesson, ask management to consider a fictional critical-service administrator who approved an unexpected request. Which services depend on that account? Who can revoke access? Is there a tested emergency contact route? What would management need to see before concluding that the problem was resolved? These questions connect the example with service decisions rather than asking directors to become incident handlers.

Keep the record specific: the scenario considered, the decisions made, the unanswered questions and the person responsible for each follow-up. A completion certificate can sit beside this record. It cannot replace the reasoning or establish that a management body exercised effective oversight. The facilitator should distinguish what learners understood from what the organisation actually implemented.

Repeated unexpected sign-in approval notifications in a staged authentication lesson.

Expand image · Course video frame · English interface

  1. Connect the prompt to your action

    An approval request should correspond to a sign-in you initiated.

  2. Repeated pressure is still unrequested

    Deny unexpected requests and use the reporting route your organisation provides.

Actual frame from Deny it if you did not start it, with English on-screen text. Employee recognition supports the use of authentication controls; it does not establish that those controls are correctly deployed.

5. Connect rapid internal reports with Article 23

For significant incidents, Article 23 generally requires an early warning within 24 hours of awareness, notification within 72 hours, and a final report within one month after notification. The first two also require action without undue delay. If the incident is ongoing when the final report is due, a progress report is followed by a final report within one month of handling the incident. Significant incidents affecting a provider’s trust services have a 24-hour notification deadline.

Teach employees to report promptly through the internal route, not to wait for a legal deadline or decide alone whether a statutory threshold is met. The response and legal owners assess significance, apply the correct rules and manage external notifications. Practise the hand-off: a useful message says what happened and when, then preserves the information the response team requests.

A requirement is mapped to learning and separate control evidence before a review records the remaining gaps.

Expand image

Original CyberPlay editorial mapping. It is not a compliance assessment or a certification scheme.

Section sources: Directive (EU) 2022/2555: Articles 20, 21 and 23

6. Add game practice without claiming a control test

Pair the backup course with Backup or Lose It. The game’s workstation scenarios make the learner choose which work needs protection and recover files from copies that survive a simulated ransomware event. Use the debrief to ask where approved work belongs and who can help restore it. Record unfamiliar terminology or an unclear responsibility as a learning gap.

Then assign a different owner to verify actual backups and restorations in the organisation’s environment. A successful game recovery has no access to that infrastructure. Likewise, Phishing Detective 3D can support a discussion about altered payment information and compromised accounts; its fictional investigation cannot verify your supplier checks or identity controls.

A staged file browser shows local and cloud sync indicators in CyberPlay’s backups lesson.

Expand image · Course video frame · English interface

  1. Available locally is not a recovery test

    A green check describes this file’s sync status, not a tested independent backup.

  2. Ask where the recoverable copy is

    Know what is backed up, who owns recovery and when restoration was last tested.

Actual frame from A cloud icon is not a backup, with English on-screen text. A sync icon is useful teaching material; the organisation still needs backup controls and tested recovery.

7. Assemble evidence that another reviewer can inspect

ENISA’s 2025 technical implementation guidance provides examples of evidence for entities covered by Implementing Regulation 2024/2690, including specified digital infrastructure, ICT service and digital-provider categories. It is non-binding guidance and does not replace national requirements. Its separation of requirements, guidance and evidence is a useful way to organise a review, provided you retain that scope limitation.

For a learning record, retain the intended audience, objective, course title and version or review date, lesson language, participation record, assessment context and follow-up. Keep the retention period and access permissions appropriate to your organisation. Separately link the control owner’s procedures, test results or decision records. An empty evidence field should remain a visible gap, not be filled with a course certificate because one is available.

Section sources: NIS2 Technical Implementation Guidance

8. Exercise: does the certificate close the control?

Review the following fictional entry as if you were checking a colleague’s mapping sheet. The task is to say what the evidence supports and choose the next action; no real employee record is needed.

9. Keep the platform’s evidence boundary visible

CyberPlay Courses uses five video checkpoints and offers a certificate of completion when the learner and plan meet the claiming conditions. Game knowledge checks are separate written activities unlocked after passing their games. A game or course result is training evidence; none of these artefacts is a declaration of NIS2 compliance.

Maintain the mapping and programme review through your governance process, using the learning records available in your workspace. Start with a few relevant decisions, attach the learning evidence honestly, and give every remaining organisational requirement an accountable owner. A progress indicator can guide follow-up; it cannot establish that a control works.

Connect continuity learning with a recovery scenario

Play Backup or Lose It in English, then discuss which evidence would be needed to verify your organisation’s real recovery arrangements. Game access depends on your plan.

Open Backup or Lose It

Sources and further reading

  1. Directive (EU) 2022/2555: Articles 20, 21 and 23 — European Parliament and Council. Accessed 2026-10-03
  2. NIS2 Directive: securing network and information systems — European Commission. Accessed 2026-10-03
  3. NIS2 Technical Implementation Guidance — ENISA. Accessed 2026-10-03

Keep exploring

All articles

Contact · About