Skip to main content
Back to overview

NIS2 Security Awareness Training: What Article 21(2)(g) Actually Requires

By NIS2Certify
nis2article-21security-awareness-trainingcyber-hygienemsp
NIS2 Security Awareness Training: What Article 21(2)(g) Actually Requires

A Belgian entity paid €185,000 this year. The Italian regulator issued €450,000. Hungary added €78,000. None of those fines came from a firewall gap. They came from failures auditors could see on paper — and the fastest way to fail a NIS2 audit is a workforce that has never been trained.

Article 21(2)(g) of NIS2 requires "basic cyber hygiene practices and cybersecurity training." One line in the directive. But it is the control regulators check first, because it is the cheapest to verify and the hardest to fake. This is the measure your clients will underestimate — and the one you, as their MSP or vCISO, should sell hardest.

Article 21(2)(g) is the measure with no technical excuse

Most of the ten Article 21 risk-management measures let an organisation hide behind budget. Cryptography, network segmentation, endpoint tooling — all cost money, and a supervisor understands that a small essential entity cannot deploy the same stack as a bank.

Cyber hygiene and training carry no such excuse. Enforcing MFA, patching on a schedule, running phishing simulations, and teaching staff to recognise social engineering are low-cost, well-documented, and expected of every entity regardless of size. When a supervisor finds untrained staff, they read it as negligence, not a resourcing problem.

That is why (g) sits where it does in the framework: it is the baseline that makes every other measure work. Encryption does not help when an employee hands over their password on a spoofed login page.

Article 21 — 10 NIS2 Cybersecurity Measures

Article 21

10 Cybersecurity Measures

Governance & Strategy

1Risk analysis & information security policies
6Effectiveness assessment of security measures

Incident & Continuity

2Incident handling & notification
3Business continuity & disaster recovery

Supply Chain & Systems

4Supply chain security
5Security in network & information systems development

Technical Controls

8Cryptography & encryption
10Multi-factor authentication & secure communications

People & Assets

7Cyber hygiene & training
9HR security & access control

For a full walkthrough of how (g) relates to the other nine controls, see our Article 21 ten measures guide.

"Basic" does not mean "annual e-learning"

The word "basic" misleads people. It does not mean a once-a-year slide deck with a completion checkbox. Commission Implementing Regulation (EU) 2024/2690 — the technical rulebook for a large group of digital-sector entities — spells out awareness and training as a measurable, recurring control with evidence requirements.

ENISA's guidance follows the same logic: outcomes over paperwork. A supervisor does not want to see that training happened. They want to see that it changed behaviour — lower phishing click rates, faster reporting, fewer repeat mistakes.

Practically, "basic cyber hygiene" means the boring fundamentals done consistently: enforced MFA, disciplined patch management, tested backups, least-privilege access, and staff who know what a phishing email looks like. If your client cannot demonstrate these five, the sophistication of the rest of their programme is irrelevant.

Everyone with system access is in scope — including the board

The most common scoping mistake is treating training as an IT-department exercise. It is not. Under NIS2, anyone with access to company systems or business data is in scope: permanent staff, fixed-term contractors, remote workers, and third parties with logins.

The board is explicitly included. Article 20 requires management bodies to follow cybersecurity training and to ensure it is offered to employees. This is not symbolic. In several member states, directors carry personal liability for oversight failures — a topic we cover in NIS2 and board liability. A management team that skipped its own training is handing the supervisor a finding and handing itself a liability exposure.

For MSPs, this is the upsell that writes itself. The board wants a defensible position. Training the board — and documenting it — is a small deliverable that removes a large risk.

Untrained staff turn a 24-hour clock into a missed deadline

NIS2 incident reporting runs on a tight schedule: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. The clock starts at "awareness" — and awareness depends entirely on staff recognising and escalating an incident.

An employee who does not know a ransomware note when they see it, or who assumes "someone else will report it," burns hours that the entity cannot get back. Training is what makes the reporting obligation survivable. It is the human sensor network feeding the timeline.

NIS2 Incident Reporting Timeline

24h

Early Warning

Notify the competent authority (CSIRT/NCA) within 24 hours of becoming aware of a significant incident.

72h

Incident Notification

Submit a detailed notification within 72 hours with an initial assessment of severity, impact and indicators of compromise.

1mo

Final Report

Deliver a comprehensive final report within one month covering root cause, remediation taken and cross-border impact.

Build the escalation path into the training itself: who to call, which channel, and what "significant" means for that client. Then test it. A tabletop exercise that surfaces a broken escalation chain is worth more than ten completed e-learning modules. For the full deadline mechanics, see NIS2 incident reporting deadlines.

Evidence is the deliverable, not the training

Here is where MSPs win or lose the audit. The training itself is commodity. The evidence that it happened, reached everyone, and produced results is the compliance artefact — and it is what most in-house teams fail to produce on demand.

A defensible training record includes attendance and completion logs mapped to the full workforce, dated content covering the current threat landscape, phishing-simulation results over time showing a downward trend, board training records, and a documented escalation procedure that staff have actually practised.

Notice the pattern: every item is something a supervisor can request and timestamp. If your client cannot pull this in an afternoon, they are exposed — regardless of how good their actual security culture is. This is the same evidence-first logic that governs backup and business continuity under CIR 2024/2690: the control is only worth what you can prove.

The enforcement pattern rewards the cheap wins first

Look at where the early fines landed in 2026. Belgium, Italy, and Hungary did not open with forensic teardowns of encryption schemes. They started with the visible, documentable basics — governance, registration, and whether entities could show they had done the obvious things.

Cyber hygiene and training are the obvious things. They are also the measures where a supervisor's finding escalates fastest, because "we never trained our staff" reads as a governance failure, and governance failures are what trigger personal liability and the steeper end of the penalty scale.

NIS2 Penalty Escalation — Beyond the Fine

!

Trigger event

Non-Compliance Detected or Incident Occurs

A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements

Authorities can impose
Non-Monetary Penalties
1

Compliance orders with binding deadlines

2

Mandatory security audits at your expense

3

Public disclosure of violations

4

Binding instructions on specific security measures

Escalates to
Operational & Personal Consequences
1

Suspension of certifications or operating licences

2

Temporary ban on management functions for individuals

3

Public naming of responsible natural persons

Trigger
Non-monetary
Operational / personal

The lesson for consultants advising essential and important entities: sequence the cheap, high-visibility controls first. You reduce the client's audit exposure faster by fixing training and hygiene than by spending the same weeks on an expensive technical project no supervisor has yet asked about. For the numbers behind this, see NIS2 fines: what your board needs to know.

What to deliver to a client this quarter

If you run security programmes for essential or important entities, treat Article 21(2)(g) as a productised service, not an afterthought. A workable package: a role-based training curriculum refreshed against current threats, quarterly phishing simulations with trend reporting, a documented and tested escalation procedure, dedicated board training with its own record, and an evidence pack ready for supervisor request.

That package is low-cost to run, high-margin to sell, and directly removes the finding regulators reach for first. It is the clearest example in NIS2 of a control where doing the basics well beats doing the advanced work at all. MSPs who understand this — and we go deeper on the model in NIS2 for MSPs — turn a compliance obligation into recurring revenue.

The directive gave this measure one line. Regulators are giving it their first look. Make sure your clients are ready for it.

Not sure where a client's cyber hygiene gaps are? Run a free NIS2 quick scan to get a prioritised readiness snapshot in minutes.

    NIS2 Security Awareness Training: What Article 21(2)(g) Actually Requires — NIS2Certify