Blog

NIS2 employee training in 2026: what SMBs must document

What NIS2 requires for workforce cybersecurity training by the 2026 deadline — fines, SMB examples at 45 and 120 employees, and audit-ready evidence.

·5 min read·Mentor Team

NIS2 is first a documentation question. Directive (EU) 2022/2555 requires "basic cyber hygiene practices and cybersecurity training" for the entire workforce. Most Member States have now transposed it into national law, with organisational controls due through 2026 and technical controls a year later.

If nobody in your team tracks training today, you will build that evidence trail from scratch in the coming months.

This article covers three things. First, what NIS2 actually asks of HR. Second, which timelines apply. Third, two concrete programs — for an SMB of 45 and one of 120 employees.

What NIS2 requires on training

The directive splits obligations in two:

  • Article 21(2)(g) — "basic cyber hygiene practices and cybersecurity training" as one of ten mandatory risk-management measures. Content is not prescribed. The entity itself must prove it is proportionate to size and risk.
  • Article 20(2) — training for management-body members. Management must complete training and offer similar content to employees on a regular basis.

Personal accountability of management is new. For essential entities, the competent national authority can temporarily bar an executive from a management role. Training is no longer only an HR item. The CEO signs it as a personal duty.

Deadlines to plan against

Most Member States finished transposition through 2024 and 2025. National laws follow the same shape:

  • Registration — entities in scope must self-register with the national supervisory authority. In several Member States this deadline has already passed.
  • Organisational controls (by late 2026) — policies, risk register, documented training, incident-response procedure.
  • Technical controls (by late 2027) — MFA, network segmentation, cryptography, vulnerability management.

Scope is broad. National estimates typically put thousands of organisations per country in scope, including many mid-sized firms that fell outside the original NIS1 rules.

Registration is more than paperwork. The entity submits its sector, main services, contact points and a named security lead. Supervisors can reclassify an important entity as essential later if a risk review points that way. Each reclassification opens new obligations, training included.

Fines

NIS2 splits regulated entities in two:

  • Essential entities: up to EUR 10 million or 2 % of global annual turnover, whichever is higher.
  • Important entities: up to EUR 7 million or 1.4 % of global annual turnover.

On top of the fine, the authority can order an independent security audit at the entity's expense. For essential entities it can also publish the breach and, in extreme cases, temporarily bar named executives.

What HR must document

For an audit you need three record types:

  • Content record. What was taught, material version, author, date of last update.
  • Attendance record. Who, when, with what knowledge-check result.
  • Management training record. A separate folder. Article 20 requires deeper content for management-body members.

Three moments training programs frequently miss:

  • New hire — a module before first access to production systems.
  • Role change — a fresh module when access rights or systems change.
  • Refresh — at least once a year, even when nothing else changed.

Core topics cover: phishing recognition, password hygiene and MFA, personal-data handling, incident-reporting path to the national CSIRT or an internal owner, safe work with remote and third-party partners.

Two concrete programs

Program 1: important entity of 45 employees (accounting services firm)

The firm handles personal and financial data for hundreds of clients. It counts as an important entity. Program:

  • Onboarding module (30 min) — cyber hygiene, MFA, phishing.
  • A short refresher quiz (5 min) every two months. Content rotates with the current threat landscape.
  • One tabletop exercise per year (45 min) — ransomware incident simulation.
  • Management module (60 min) for the CEO and finance director — legal duty, 24-hour incident reporting timeline.

Roughly 4 hours per employee per year. Evidence: PDF report from the LMS, separate folder for management training. Retention: two years after completion.

Program 2: essential entity of 120 employees (IoT sensor manufacturer)

Products run inside critical infrastructure, so the firm is an essential entity. The program is deeper and split by role:

  • Onboarding module (45 min) — includes OT/ICS specifics for production staff.
  • Role-tailored modules — developers get secure coding (2 hours), operators cover physical access and supplier controls, sales handles social engineering.
  • Quarterly phishing simulation with an automatic microlearning module after a failed click.
  • One management workshop per year (2 hours) with an outside legal advisor.

Roughly 6–8 hours per employee per year, more for engineering. Separate record for contractors who touch the development environment.

Three myths HR keeps hearing

  • "Let IT handle it." The directive assumes HR, management and IT work together. Personal accountability of management means the CEO cannot fully delegate it.
  • "One webinar is enough." It is not. Supervisors expect regular, documented repetition, not a single attendance certificate.
  • "We are too small." The threshold is sector and risk, not headcount alone. Small IT service providers and accounting firms are often important entities.

For the wider view of overlapping training laws see Compliance training in 2026.

Where to start this week

If nothing is set up yet, four steps take about five working days:

  • Confirm your entry in the national supervisory register and update the security-lead contact.
  • List existing training by employee and role. Mark the gaps.
  • Assign a content owner — usually HR lead and the information-security officer together.
  • Book the first management session before the month closes. Personal accountability of management is easiest to prove when executives go first.

What documentation actually solves

A NIS2 audit is not a knowledge test; it is a proof test. An LMS such as Mentor consolidates content, confirms attendance and exports a report an inspector can validate in half an hour. Without evidence, even the best training does not count at inspection.

Ready to try Mentor?

14-day free trial, no card. Set-up in under 5 minutes.

Start trial