Article 20(2) β workforce + management body training is a direct legal requirement, not best practice
Loading...
We deliver mandatory NIS2 training across your workforce and management body β Article 20 governance, Article 21 risk-management measures, incident reporting, and supply-chain obligations. Managed rollout, audit-ready evidence. Live for your team in under a week.
NIS2 Article 20(2) explicitly requires essential and important entities to ensure that members of their management body and their employees follow regular cybersecurity training. Article 20(1) makes the management body personally liable for non-compliance. Article 21 mandates a documented set of risk-management measures including awareness training, incident handling, and supply-chain security β all of which require workforce training to operate. Supervisory authorities across EU member states have begun audits and the first fines have already landed.
Article 20(2) β workforce + management body training is a direct legal requirement, not best practice
Article 20(1) β management bodies are personally liable for cybersecurity governance failures, including training gaps
Article 21 β risk-management measures (incident handling, supply chain, encryption, access control) all depend on trained staff
Article 23 β incident reporting within 24 hours; staff must know how to escalate or you miss the window
Different roles face different risks. Training tailored to job responsibilities.
A 60-min working session with a specialist. We map your obligations, current training gaps, and regulator priorities in your jurisdiction.
Your processes, contacts, and policies go into the modules. We brand the LMS, wire SSO, and connect HRIS so enrolment is automatic.
Roll out to all staff. Automated nudges hit non-completers. Manager dashboards in real time. Audit-ready records when regulators ask.
Ready to scope your programme?
Book a 30-min discovery call β no slides, no pitch, just specifics.
Dedicated customer success manager handles enrolment, role mapping, kickoff communications, and reminder cadence.
Dated certificates per learner, exportable completion logs, and management-body training records that meet supervisory authority documentation expectations.
Track completion across teams, departments, and entities. Export evidence packages for supervisory authorities and customer security questionnaires.
SAML 2.0, OIDC, and SCIM provisioning. New joiners enrolled automatically. Leavers de-provisioned. Zero admin overhead.
Multi-year licensing rolls learners forward each year with content updates as member-state transposition guidance evolves.
Your logo on certificates, co-branded learner emails, and the option to attach your incident response plan or vendor risk policy to any module.
NIS2 made annual security training a board-level obligation. The managed rollout meant we hit the deadline without burning internal capacity, and the management-body briefing got our directors aligned in 45 minutes β exactly what Article 20(2) asks for.
Don't see your question? Send us a note β we usually reply same day.
Ask a questionTell us your entity classification (essential or important), your sector, and your headcount. We'll come back with a curriculum proposal, pricing, and a rollout plan within 1 business day.