Obligations & standards

Which part of your obligations you can tick off with me.

Awareness is required by several sets of rules — and expected in contracts. Choose your context and see openly which requirements secureIT’s training and phishing simulations cover, where you need to add something, and what deliberately stays outside.

NIS2 Directive

Law

NIS2 requires the management bodies of entities in scope to attend training and calls for regular cybersecurity training for the workforce.

4 of 5 requirements you cover with me · 1 stay with your IT
In short
EU Directive 2022/2555, transposed in Germany by the NIS2 Implementation Act (BSIG, German BSI Act)
Minimum requirement
Management bodies must be trained; entities must provide, and be able to prove, basic cyber hygiene and regular training for employees.
Basis

Directive (EU) 2022/2555, Art. 20(2) (training of management bodies, training offered to employees) and Art. 21(2)(g) (basic cyber hygiene practices and cybersecurity training); national transposition in the German NIS2 Implementation Act (BSIG).

The requirements in detail

◐ partly
Members of the management bodies attend training. · Art. 20(2)

Suitable training content is available; management takes part themselves, and their participation is documented by a proof of training.

✓ covered
Regular cybersecurity training for all employees. · Art. 20(2) / 21(2)(g)

Recurring awareness courses for the entire workforce.

✓ covered
Basic cyber hygiene (phishing, passwords, safe behaviour). · Art. 21(2)(g)

Course content and phishing simulations on exactly these topics.

✓ covered
Proof and documentation of the measures carried out. · Art. 21, accountability

Automatic proof of training with timestamp and participation rate.

– your IT
Further risk management measures (incident handling, backup, access control, supply chain, etc.). · Art. 21(2)(a)–(j)

Technical and organisational measures outside awareness – for you or your IT.

ℹ️ Whether NIS2 applies to you depends on your sector and size – as a rule from 50 employees or €10 million turnover in regulated sectors.

Proof at the push of a button

Businesses generate confirmation of the training carried out in the Cockpit — with time stamp and reference to the chosen context.

Get started now

This overview is meant to create transparency and is not legal advice. Whether, and to what extent, a standard or obligation applies to you depends on your sector, your size and your contracts. What is covered in each case is the awareness part (training, simulation, proof) – not the technical measures.

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first