Skip to content
CertMapCertMap

VERTIEFUNG

NIS2 Training Records for the Workforce: From Obligation to Audit-Ready Documentation

Training the executive management is an appointment. Training the workforce is a permanent state: § 30 BSIG makes it a mandatory measure, § 38 requires the management to monitor its implementation. What has to be documented for that, where spreadsheets hit their limits, and when personnel certifications are the stronger form of evidence.

By Daniel Thomas HeesselLast updated: August 4, 20266 min read

Much is written about the NIS2 training obligation of the executive management. The larger part of the work, however, sits in § 30: training and awareness measures for the workforce are one of the ten mandatory measures whose implementation the management must monitor. Having attended a seminar is an appointment. Being able to prove that the right workforce is trained and qualified at the right time is a state, and that is exactly what audit situations ask about: from the ISO 27001 audit through customer questionnaires to the insurer in a claims case.


This article is aimed at the people who have to produce that state: information security officers, CISOs, compliance managers and the HR side of professional development. For the duties of the executive management itself, including its own training obligation, see our article on § 38 BSIG.

Where workforce training sits in the law

§ 30 Absatz 2 BSIG (subsection 2 of § 30 of the German BSI Act, the law implementing NIS2 in Germany) lists the risk management measures that particularly important and important entities must take. Number 7 reads, in the original wording: "grundlegende Schulungen und Sensibilisierungsmaßnahmen im Bereich der Sicherheit in der Informationstechnik" (basic training and awareness measures in the field of information technology security). That is not a recommendation but part of the catalogue of obligations, on the same level as backup management, supply chain security or multi-factor authentication.

Then there is the second layer: under § 38 Absatz 1, the executive management must monitor the implementation of these measures, and its personal liability is attached to that duty. In practice this means: someone in the organisation must be able to show at any time that the training measure is running, not just that it ran once.

What "evidence" means in practice

The law does not define what the documentation has to look like. There is still one hard anchor: anyone operating an ISMS under ISO/IEC 27001 in parallel already owes documented evidence of competence there, the standard explicitly requires it in clause 7.2. And independently of the standard, audit situations in practice keep asking the same four questions, which robust documentation should be able to answer:

  • Who was trained? By named person, not "the department".
  • What was the content? An awareness briefing is something different from a specialist training for administrators.
  • When, and when again? One-off measures go stale; repetition cycles and expiry dates belong in the documentation.
  • Does the qualification fit the role? An incident responder needs different knowledge than sales. Role linkage is the difference between an attendance list and evidence of competence.

The occasions for this are rarely an unprompted BSI inspection: more likely, ISO 27001 auditors ask in the certification audit, in the financial sector the supervisory authority asks along the DORA requirements, cyber insurers ask at application or in a claims case, and business customers ask in their security questionnaires. Anyone who keeps the documentation clean answers all of these requests from the same source.

Why spreadsheets eventually tip over here

Most organisations start with an Excel training matrix, and initially that is sensible: for a handful of people and an annual briefing, it is enough. It tips over at three predictable points: at expiry dates (nobody checks the spreadsheet daily to see whether a qualification or a certificate is running out), at role linkage (as soon as different roles have different requirements, the matrix turns into a mountain range) and at multiple requirements (the same person counts towards NIS2, ISO 27001, in the financial context towards DORA and additionally towards customer contracts at the same time, but the spreadsheet only knows one dimension). From that point on, the upkeep itself becomes a risk: an outdated matrix looks worse in an audit than none at all, because it documents that the monitoring is not working.

From attendance list to competence overview

For the basic level, awareness for the entire workforce, documented briefings with date and participants are sufficient. The specialist level is where it gets interesting: for key roles such as administrators, incident responders or the information security officer, personnel certifications are the most robust form of evidence, because they prove examined competence through an independent body, not just attendance. They are not mandatory under NIS2, but whoever has them on the team holds the strongest evidence of competence there is, and many of them bring their renewal logic with them. What distinguishes a personnel certification from a certificate of attendance is explained in our fundamentals article.

This is exactly where we work ourselves, and in all honesty with a clear boundary: CertMap for organisations is not a training provider and not a learning system, no briefings take place there. What it does: keep the workforce's certificates, expiry dates, continuing education obligations and role linkage in one overview; internally issued credentials can also be recorded as their own entries. It answers the monitoring question "Who is qualified for what, and how will we still know that in a year?" with a click instead of spreadsheet archaeology. Delivering the training remains the providers' job; its verifiability does not.

The training is an appointment, the evidence is a state. What gets audited is not whether training took place, but whether you can prove it at any time.

Frequently asked questions

Is one annual awareness training for everyone enough?

For the basic level of awareness, a regular, documented briefing is the usual route. § 30, however, requires measures that match the risk: roles with special responsibilities in information security need specialist qualification beyond that. A single annual training for everyone does not, as a rule, cover this.

Do the records have to be reported to the BSI?

There is no ongoing reporting obligation for training records. The documentation must, however, be available when it is needed, whether towards the supervisory authority, in an audit, towards customers or the insurer. Verifiability is the yardstick, not unsolicited reporting.

Are personnel certifications mandatory for NIS2?

No. The law requires training and awareness, not specific credentials. Personnel certifications are the voluntary next level: the strongest evidence of competence for key roles, with a built-in currency requirement through their renewal cycles.

This article provides general information on the legal situation based on the promulgated text of the law and does not replace legal advice in individual cases.

Read next:NIS 2 Training Obligation for Management: What § 38 BSIG Actually RequiresWhat is Personnel Certification under ISO/IEC 17024?