Bottom line: NIS2 requires approximately 30,000 German companies to provide systematic cybersecurity training to their management boards.
Approximately 30,000 companies in Germany are required to train their management boards on cybersecurity governance matters. This requirement stems from the implementation of the NIS2 Directive.
The European Network and Information Security 2 (NIS2) Directive has anchored requirements for cybersecurity governance that are binding for operators of critical infrastructure and other companies above a certain size. A key component is the obligation for management board members and supervisory bodies to complete training on cybersecurity risks.
For CISOs, this represents a concrete organizational task: Management must not only be informally briefed on IT security matters, but must complete formalized training programs. This typically includes fundamentals of cyber risks, regulatory requirements, reporting obligations, and the role of the management board in information security governance.
The implementation effort is substantial: Approximately 30,000 affected companies must establish, document, and be able to demonstrate such training programs. This requires collaboration between security functions, HR, and top management, as well as traceable proof of training participation.
Source: news.google.com · Published 24 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.