Skip to content

NIS2 Implementation: Executives Required to Complete Training by September

Key point: Executives are subject to mandatory NIS2 training starting in September to document their cybersecurity responsibility.

The German implementation of NIS2 requires mandatory training for business leaders, beginning in September. This requirement addresses the new cybersecurity liability of executives in critical infrastructure and companies within the scope.

With the implementation of the EU Directive NIS2 into national law, executives and management boards face concrete training obligations. These must be completed by September and document that management understands their new cybersecurity responsibilities.

Background: NIS2 significantly expands the scope of affected companies and grants management explicit duty of care obligations and liability responsibility for the first time. Executives are thus personally responsible for implementing appropriate cybersecurity governance. The mandatory training is intended to ensure they understand their new requirements.

For CISOs, this means: Training must be coordinated, compliance status must be documented, and management must concretely implement their security governance on the basis of the training. The CISO should proactively clarify what content is required and how evidence must be maintained.


Source: news.google.com · Published 30 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: