Knowledge base › Compliance

NIS2 and security awareness: what you need to arrange

NIS2 is the European cybersecurity directive that requires organisations in designated sectors to demonstrably get their digital resilience in order. Security awareness training for employees is not a side issue here but an explicit part of the mandatory measures.

What is NIS2?

NIS2 stands for the second Network and Information Security Directive of the European Union (Directive EU 2022/2555). It is the successor to the original NIS Directive from 2016 and is a response to the sharply increased cyber threat and the mutual dependence of digital services in Europe. Where the first NIS Directive was limited to a small group of essential-service providers, NIS2 significantly broadens the scope and tightens the requirements.

A directive does not apply directly: each EU member state must transpose NIS2 into national legislation. In the Netherlands this happens through the Cyberbeveiligingswet (Cybersecurity Act), which replaces the current Network and Information Systems Security Act. The Dutch legislative process was delayed relative to the original European deadline of October 2024. Always check the current status and the exact entry-into-force date of the applicable national law before drawing conclusions about hard deadlines.

Key point: NIS2 moves cybersecurity from an IT topic to a board responsibility. The board is liable, must be trained itself and must demonstrably oversee the measures, including employee training.

Who does NIS2 apply to?

NIS2 distinguishes between two categories of organisations, with comparable obligations but a different supervisory regime:

Essential entities

Organisations in sectors of very high criticality, such as energy, transport, banking, financial market infrastructure, healthcare, drinking water, waste water, digital infrastructure, government and space. They are subject to proactive supervision.

Important entities

Organisations in other critical sectors, such as postal and courier services, waste management, chemicals, food, manufacturing of certain goods, digital providers and research. They are subject to reactive supervision, upon indications of a breach.

In most cases a size threshold also applies: NIS2 targets, in principle, medium-sized and large organisations (roughly from fifty employees or more than ten million euros in annual turnover). For some sectors, however, there are exceptions where smaller organisations also fall under the directive, for example because they play a unique or critical role. Whether your organisation falls under NIS2 exactly depends on sector, size and role; have this assessed legally if in doubt.

Knock-on effect for suppliers and SMEs

Even if your business does not fall directly under NIS2, you often cannot escape it. NIS2 explicitly requires entities to secure their supply chain. Large clients translate that obligation to their suppliers: they impose contractual cybersecurity requirements on everyone who has access to their systems or data. For an SME that supplies a hospital, energy company or government body, this means that demonstrable awareness training and clear incident agreements increasingly become a condition for being allowed to carry out the work. See also our page on security awareness for SMEs.

What requirements does NIS2 set for training and awareness?

NIS2 does not prescribe a ready-made training programme, but it does explicitly name awareness and training as part of the mandatory risk measures. Two elements are decisive here:

  • Basic cyber hygiene and cybersecurity training for employees. The directive counts the teaching of safe digital behaviour - strong passwords, multi-factor authentication, recognising phishing and correctly reporting incidents - among the measures organisations must take.
  • Training and responsibility of the board. Directors and managers must approve the cybersecurity measures, oversee them and undergo training themselves so they can assess risks. Under NIS2, cybersecurity has emphatically become a management responsibility.

In practice this means you must be able to demonstrate that employees are trained structurally and that awareness is measured and maintained. A one-off presentation is not enough: supervisors and auditors look for an ongoing, repeatable programme with registration of participation and progress. A good security awareness training provides exactly that evidence.

Note: NIS2 does not prescribe a specific form or frequency of training but applies the principle of proportionality. The measures must suit the size of your organisation and the risks you face. A small business therefore does not have to run the same programme as an energy company, but it must be able to justify why the chosen approach is appropriate. So document not only that you train, but also why you chose that form and frequency.

What happens if you do not comply?

NIS2 gives supervisors substantial powers and attaches significant sanctions to them. The directive mentions, among other things:

Fines

For essential entities up to 10 million euros or 2% of global annual turnover, for important entities up to 7 million euros or 1.4% of turnover - always the higher of the two amounts.

Director liability

Directors can be held personally responsible for shortcomings. In extreme cases, supervisors can impose a temporary ban on holding a management role.

Supervisory measures

Think of audits, binding instructions, warnings and making breaches public. The exact implementation follows from national cybersecurity legislation.

Reputational and chain damage

Besides legal consequences, non-compliance leads to lost contracts when clients assess their suppliers for NIS2 conformity.

The exact level, procedure and enforcement of sanctions are set out in national cybersecurity legislation. Treat the amounts above as the frameworks from the European directive and check the current national implementation.

A step-by-step plan to comply with NIS2

A practical route towards NIS2 conformity, with awareness as a fixed component:

  1. Determine whether and how NIS2 applies to you. Map out sector, size and your role in the chain. Do you fall under it directly, or indirectly via your clients? Record this and have it assessed legally if in doubt.
  2. Carry out a risk analysis. Map your most important digital processes, data and vulnerabilities. This is the basis for all further measures.
  3. Place responsibility with the board. Ensure that management approves the measures, oversees them and undergoes training itself. Document this.
  4. Take technical and organisational measures. Think of multi-factor authentication, backups, access management, incident handling and supply chain security.
  5. Start an ongoing awareness programme. Train employees structurally in recognising phishing and safe digital behaviour, and measure the effect with, for example, phishing simulations. Register participation and progress as evidence.
  6. Set up incident reporting. NIS2 has strict reporting deadlines. Ensure employees know how and where to report an incident and that your organisation can report to the supervisor in time.
  7. Evaluate, repeat and document. Compliance is not a snapshot. Repeat training and measurements periodically and keep documentation current for audits.

NIS2, ISO 27001 and GDPR: how do they relate?

NIS2 does not stand alone. Many organisations already deal with other frameworks for information security and privacy, and the good news is that they largely reinforce each other. Anyone who has things in order in one of these areas is already well on the way with the others.

ISO 27001

The international standard for information security requires a management system (ISMS) with risk analysis, measures and awareness training. Much of what ISO 27001 requires links directly to the NIS2 obligations. An existing ISO certification forms a strong basis for NIS2 conformity.

GDPR

Privacy legislation requires "appropriate technical and organisational measures" to protect personal data. Awareness training is a direct way to meet that. In the event of a data breach, the supervisor checks whether those measures were demonstrably taken - exactly what NIS2 asks for too.

The difference lies mainly in the angle. The GDPR is about protecting personal data, ISO 27001 is a voluntary standard you can be certified against, and NIS2 is legislation with mandatory supervision and sanctions for designated sectors. For the human element - awareness and training - they all point in the same direction, however: employees must recognise threats and know how to act, and you must be able to demonstrate that. One well-considered awareness programme therefore serves all three frameworks at once in practice, which avoids duplicate work and makes the investment more efficient.

How Lumyo helps with this

Lumyo focuses on the part of NIS2 where most organisations can make the biggest gains: people. We help you meet the awareness requirements demonstrably with:

  • Interactive security awareness training that teaches employees to recognise phishing and social engineering
  • Realistic phishing simulations to measure awareness and demonstrate improvement
  • Registration of participation and progress, so you can prove the training during audits
  • An ongoing programme instead of a one-off session, in line with the NIS2 philosophy
  • Attention to the board, so that managers meet their own training obligation

Want to know how awareness fits into a broader approach? Also read how to build a cybersecurity awareness culture. Lumyo does not provide legal compliance advice, but ensures that the human part of your NIS2 measures becomes concrete and demonstrable.

Discuss your situation Security awareness training

Frequently asked questions about NIS2

What is NIS2 in short?

NIS2 is a European directive intended to increase the digital resilience of organisations in designated sectors, with mandatory measures, incident reporting and training. Transposed into national law per member state; check the current status.

Who does NIS2 apply to?

To medium-sized and large organisations in designated sectors (essential and important entities) and, indirectly, to their suppliers via supply chain requirements.

Does NIS2 require security awareness training?

Yes. Cyber hygiene and cybersecurity training are part of the required measures, and the board must undergo training itself and oversee implementation.

What are the possible fines under NIS2?

Up to 10 million euros or 2% of turnover for essential entities and up to 7 million euros or 1.4% for important entities, with possible personal liability of directors.

Does NIS2 also apply to my SME as a supplier?

Often yes, indirectly. Clients that fall under NIS2 impose security requirements on their suppliers, including demonstrable awareness training.