Skip to content
CertMapCertMap

VERTIEFUNG

NIS 2 Training Obligation for Management: What § 38 BSIG Actually Requires

The training obligation for management bodies is the most heavily advertised part of NIS 2 and at the same time the easiest to fulfil. What the law literally requires, what it deliberately leaves open, and why the real liability question sits one line above the training obligation.

By Daniel Thomas HeesselLast updated: August 4, 20267 min read

Anyone searching for the NIS 2 training obligation mainly finds two kinds of results: law firms warning about liability, and academies selling the matching seminar. Both have their place. What gets lost along the way: the training obligation is the easiest obligation in § 38 BSIG (the German BSI Act) to fulfil. Things get serious one line above it, with the oversight obligation, which is where personal liability attaches.


CertMap does not sell NIS 2 training. That is why we can afford to describe the provision as it is actually written: with a training obligation that can be fulfilled without drama, and with two other obligations that form the real core.

Who the obligation applies to in the first place

The obligations under § 38 BSIG apply to the management bodies of particularly important entities ("besonders wichtige Einrichtungen") and important entities ("wichtige Einrichtungen") within the meaning of § 28 BSIG. Simplified: a company from the affected sectors counts as an important entity from 50 employees or more than 10 million euros in annual turnover and balance sheet total; as a particularly important entity from 250 employees or more than 50 million euros in turnover and 43 million euros in balance sheet total, and additionally, among others, operators of critical facilities. Which sectors are affected is governed by Annexes 1 and 2 of the act; the BSI offers an applicability check that lets you verify your own classification.

If you are not affected, you can stop reading here. If you are, you should know the three obligations that § 38 actually consists of.

The three obligations in § 38, and which one hurts

The provision is short, and its structure is half the answer:

  1. Implement and oversee (paragraph 1): Management is obliged to implement the risk management measures under § 30 BSIG and to oversee their implementation. This is not a delegable year-end formality but an ongoing leadership task spanning ten measure areas, from risk analysis through the supply chain to multi-factor authentication.
  2. Be liable (paragraph 2): If management culpably breaches these obligations under paragraph 1 and damage results, it is liable to its entity under the company-law rules of its legal form. What is notable is what is NOT in the law: the government draft still contained an express prohibition on waiving such claims for compensation. In the promulgated version of § 38 paragraph 2, this waiver prohibition does not appear. Many older articles still cite the draft version here.
  3. Attend training (paragraph 3): Management must regularly attend training in order to gain sufficient knowledge and skills to identify and assess risks and risk management practices in information security.

The liability rule in paragraph 2 expressly ties into the obligations under paragraph 1. That does not mean the training obligation could be ignored without consequence; it too is a statutory duty of management, the breach of which can become relevant under general principles of company law. But the centre of gravity of the liability risk clearly lies where the law places it: with implementing and overseeing the measures. Training is the obligation with the clearest path to fulfilment, not the one with the greatest risk.

What the training obligation specifically requires, and what it does not

The law makes exactly two stipulations about the training: it must take place regularly, and it must serve one goal, namely being able to identify and assess risks and risk management practices. Everything else the legislator leaves open:

  • No prescribed format: In-person seminar, online training or an in-house session, the law does not distinguish.
  • No prescribed provider: Whether TÜV, IHK, an academy or a specialised trainer, no body is designated by law, no accreditation is prescribed.
  • No prescribed certificate: The law requires attendance and the acquisition of knowledge, not an exam and not a specific credential.
  • No defined frequency: "Regularly" is not quantified. All that is discernible: a one-off does not satisfy the wording. Choosing a fixed interval, say annually, and documenting it makes the regularity demonstrable; a binding requirement on this does not currently exist.

That is the honest de-dramatisation: regular attendance of training that fits the subject matter, plus documentation, covers exactly what the wording of the training obligation names. Honesty also includes the second half of the sentence in the law: the goal is the acquisition of sufficient knowledge, so the training is supposed to fit the entity and its risks, not merely take place. Panic, however, is not a legal concept but a sales argument.

To put the forms of evidence in context, a look at the terms is worthwhile: a certificate of attendance proves presence. A certificate issued after an exam proves tested knowledge. An accredited personnel certification proves examined competence under a supervised scheme. For § 38 paragraph 3, none of these levels is prescribed; documented regular attendance suffices. If you want to understand the differences between forms of evidence in more detail: Certification or certificate, what is the difference?

The obligation above the training obligation: oversight

Why does the law require the training at all? Paragraph 3 names the purpose itself: management is supposed to be able to identify and assess risks and risk management practices. It must assess them because paragraph 1 assigns it the oversight of the measures. The training is the admission ticket to a task, not its completion.

That task is concrete. § 30 paragraph 2 BSIG lists ten measure areas whose implementation management must oversee, including risk analysis concepts, handling of security incidents, backup and crisis management, supply chain security, effectiveness assessment of the measures, cryptography concepts, access control and multi-factor authentication. And at position seven: basic training and awareness measures in the area of information technology security, meaning training for the workforce, not just for management.

This closes the loop, and it does so without drama: management's own training is an appointment in the calendar and a certificate in the binder. Overseeing the ten measures, including the training and awareness measures for staff, is by contrast an ongoing state that you must be able to evidence. How organisations manage this evidence for the workforce in practice is covered separately: NIS 2 training records for the workforce.

The training is an obligation, but not the risk. Regular, suitable training plus documentation covers paragraph 3. The centre of gravity of liability lies in paragraph 1, with the oversight of the measures.

Not the only training obligation: DORA, ISO 27001 and sector regimes

This assessment applies to § 38 BSIG, and only to it. If you operate under a different regime, do not transfer it:

  • DORA (financial sector): Financial entities are subject to the European DORA regulation, and it plays stricter. The management body must actively keep its knowledge of ICT risk up to date, including through regular specific training (Article 5), and training on digital operational resilience is a mandatory component of the programmes, for employees as well as for management (Article 13). Financial entities also largely fall outside the NIS 2 regime as a special case; for them, DORA is the benchmark, not § 38.
  • ISO/IEC 27001: Not a statutory obligation, but anyone who is certified or owes it contractually must maintain documented evidence of competence (clause 7.2) and demonstrate awareness across the organisation (clause 7.3). These requirements reach the organisation through audits, not through authorities.
  • Sector regimes such as TISAX impose comparable requirements in the automotive environment through customers' audit catalogues.

Anyone subject to several regimes at once does not have a training problem but a record-keeping problem, which is exactly what the article on training records for the workforce is about.

Frequently asked questions

Must every member of the management body attend training?

§ 38 paragraph 3 addresses the obligation to the management bodies of particularly important and important entities, without exempting individual members. The law does not provide for delegating one's own attendance to other persons.

How often is "regularly"?

The law does not quantify it. All that is discernible: a one-off does not satisfy the wording. A self-chosen, documented interval, say annually, makes the regularity demonstrable and keeps knowledge current with the changing threat landscape. A binding frequency does not currently exist.

Does the law prescribe a specific provider or certificate?

No. Neither provider nor format nor a specific credential is prescribed. What matters is regular attendance, content that serves the assessment of risks and risk management practices, and documentation that can evidence both.

This article provides general information on the legal situation based on the promulgated text of the act and does not replace legal advice in individual cases.

Read next:NIS2 Training Records for the Workforce: From Obligation to Audit-Ready DocumentationCertification vs. Certificate: What's the Difference?