Which part of your obligations you can tick off with me.
Awareness is required by several sets of rules — and expected in contracts. Choose your context and see openly which requirements secureIT’s training and phishing simulations cover, where you need to add something, and what deliberately stays outside.
ISO/IEC 27001
StandardA certified ISMS requires that staff are made aware of and trained for their tasks – in a planned, recurring and verifiable way.
ISO/IEC 27001:2022 – clauses 7.2 (Competence), 7.3 (Awareness) and Annex A 6.3 (Information security awareness, education and training); implementation guidance in ISO/IEC 27002:2022, section 6.3.
The requirements in detail
Structured awareness courses with lessons that build on each other, suitable for every role.
Phishing simulations train and measure how well real attacks are recognised.
Proof of participation and completion with a timestamp for each person.
The content conveys principles and consequences; you add your own company policy yourself.
Repeatable training and campaigns with evaluation (click and completion rates).
Not part of awareness training – an organisational/technical matter for you or your IT.
NIS2 Directive
LawNIS2 requires the management bodies of entities in scope to attend training and calls for regular cybersecurity training for the workforce.
Directive (EU) 2022/2555, Art. 20(2) (training of management bodies, training offered to employees) and Art. 21(2)(g) (basic cyber hygiene practices and cybersecurity training); national transposition in the German NIS2 Implementation Act (BSIG).
The requirements in detail
Suitable training content is available; management takes part themselves, and their participation is documented by a proof of training.
Recurring awareness courses for the entire workforce.
Course content and phishing simulations on exactly these topics.
Automatic proof of training with timestamp and participation rate.
Technical and organisational measures outside awareness – for you or your IT.
ℹ️ Whether NIS2 applies to you depends on your sector and size – as a rule from 50 employees or €10 million turnover in regulated sectors.
GDPR
EU regulationThe GDPR requires appropriate technical and organisational measures to protect personal data. An aware, well-trained team is one such organisational measure – and the factor that prevents most data breaches from happening in the first place.
Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) – in particular Art. 32 (security of processing), Art. 39(1)(b) (awareness-raising and training by the data protection officer) and Art. 5(2) and Art. 24 (accountability).
The requirements in detail
Awareness courses and phishing simulations are an appropriate organisational measure within the meaning of Art. 32.
This is exactly the awareness-raising and training the offer provides – including documentation.
Content on data handling and social engineering; the formal confidentiality undertaking is something you arrange yourself.
Proof of participation and completion with a timestamp documents the awareness measures.
Not part of awareness – to be implemented by you or your IT.
ℹ️ The GDPR applies to almost every business that processes personal data – regardless of size or sector.
EU AI Act
EU regulationThe AI Act requires companies that use AI to ensure a sufficient level of AI literacy among their staff. Anyone using AI needs to understand its opportunities and risks – from deepfakes and AI-assisted phishing to careless sharing of data with AI tools.
Regulation (EU) 2024/1689 (Artificial Intelligence Act / AI Act) – in particular Art. 4 (AI literacy), applicable since 2 February 2025.
The requirements in detail
Training content on AI fundamentals, AI literacy and the safe use of AI tools.
Course topics and phishing simulations with AI fake and deepfake scenarios.
Automatic proof of training with a timestamp for each participant.
Regulatory and technical obligations outside awareness – an organisational matter for you.
ℹ️ The scope and further obligations depend on your role (provider/deployer) and the risk class of the AI system; the AI literacy obligation under Art. 4, however, applies broadly.
For AI literacy under Art. 4: my online course “Using AI safely at work” with a certificate per person and company proof, plus templates for an AI policy and a works agreement.
View the AI courseCyber insurance
ContractInsurers regularly expect staff to receive ongoing awareness training. A lack of awareness training can reduce the payout in the event of a claim.
Not a law, but contractual obligations. Guided by the GDV (German Insurance Association) model terms for cyber insurance; the terms of your own insurer are what count.
The requirements in detail
The core offer: awareness courses and phishing simulations.
Documented proof with date and timestamp for each session.
Integrated, repeatable phishing campaigns with evaluation.
Not part of awareness – to be implemented by you or your IT.
ℹ️ Check the obligations in your own policy – cover and requirements differ from insurer to insurer.
Your own sense of security
VoluntaryNot a legal obligation, but your own standard. The yardstick is effectiveness: regular, close to everyday work, without blame and with visible progress.
No legal basis – guided by proven awareness practice (continuous, measurable, positive).
The building blocks of the ideal programme
Training can be assigned when someone joins.
Repeatable, compact course units.
Plannable, recurring campaigns with realistic scenarios.
Training can be repeated as often as needed.
Evaluations in the Cockpit for each campaign and team.
Debriefs explain rather than accuse; team reports stay anonymised.
A course library plus a wide range of phishing, quishing and AI scenarios.
Proof at the push of a button
Businesses generate confirmation of the training carried out in the Cockpit — with time stamp and reference to the chosen context.
This overview is meant to create transparency and is not legal advice. Whether, and to what extent, a standard or obligation applies to you depends on your sector, your size and your contracts. What is covered in each case is the awareness part (training, simulation, proof) – not the technical measures.