Skip to content

NIS-2 Management Training · Legally Required

Your NIS-2 Training Obligation –
Compliant, Industry-Specific, Certified.

Section 38 (3) BSIG requires executives of particularly important and important facilities to undergo regular cybersecurity training. We deliver exactly that – tailored to your industry and your organisation.

Based on BSI Guidelines September 2025
Sector-specific – not a one-size-fits-all product
Certificate for your compliance documentation
No technical background required

Request Training

Complimentary initial consultation. We respond within 24 hours.

Thank you!

We have received your request and will get back to you within 24 hours.

Or email us directly: nis2@muehlcyberconsulting.com

§ 38 (3) BSIG: Cybersecurity training is mandatory – no discretion.

With the NIS-2 Implementation Act (NIS-2UmsuG), in force since December 2025, management bears personal responsibility for implementing cybersecurity measures – and must demonstrably be trained to do so.

Who is affected?

Approximately 30,000 companies across 18 sectors – from energy and healthcare to food production and manufacturing. Affected are particularly important facilities (250+ employees or €50M+ annual revenue) and important facilities (50+ employees or €10M+ annual revenue).

What is required?

Management must undergo cybersecurity training regularly – at least every three years, minimum approximately four hours. The obligation is non-delegable: managing directors, board members, and authorised signatories must personally participate. Training must be sector-specific.

What are the penalties?

Fines of up to €10 million or 2% of global annual turnover (particularly important facilities) or up to €7 million or 1.4% (important facilities). Additionally, personal civil liability of management – a waiver by the company is excluded by law.

€10M
Maximum Fine
or 2% of global annual turnover (particularly important facilities)
€7M
Maximum Fine
or 1.4% of global annual turnover (important facilities)
The BSI published binding guidelines in September 2025 defining what a compliant training must deliver. The framework covers three competency areas: risk identification, risk management measures, and impact assessment. Training must be "appropriate, current, and sector-specific."

BSI Guidelines (German) →

A one-size-fits-all solution does not meet the legal requirement.

The BSI states it explicitly: training content must be "appropriate, current, and sector-specific." A generic online course for all industries is not legally sufficient.

Generic Online Training MuehlCyberConsulting Training
General cybersecurity topics Industry-specific threat scenarios
No reference to your risk exposure Analysis of your specific company situation
No sector reference (B3S, ISO sector standards) Incorporates sector-specific standards and requirements
Compliance proof legally questionable Documented training per BSI guidelines
No personal point of contact Experienced consultant, 30+ years of practical experience
Technical jargon, hard to follow Management language, clear and practical
Only when training addresses your industry, your specific risks, and your regulatory environment can your management make well-founded decisions – and the legal obligation is considered fulfilled.

More than compliance – strategic security for your organisation.

The NIS-2 training delivers concrete value to your leadership team – far beyond meeting a legal obligation.

Legal Certainty

You demonstrably fulfil § 38 (3) BSIG. Your training certificate is documented in an audit-proof manner – ready for regulators, auditors, and insurers.

Personal Liability Protection

As a managing director or board member, you protect yourself from personal civil liability. Your participation in the training is your demonstrable protection.

Better Risk Decisions

You understand cyber risks in your industry context – without needing technical expertise. You delegate more effectively, prioritise better, and act more confidently in crisis situations.

Protection Against Business Disruption

Cyberattacks cost mid-sized companies hundreds of thousands of euros on average. Well-informed leadership teams respond faster, minimise downtime, and reduce damage.

Trust with Customers and Partners

NIS-2 compliance is increasingly required by suppliers, customers, and authorities. Your documented training strengthens your position in the supply chain and in tenders.

No Technical Background Required

Our training is designed for decision-makers, not IT professionals. Strategic, practical, in your language – without technical jargon. Ideal for the entire executive team.

Tailored in four steps.

From first contact to certificate – a structured, lean process that respects your schedule.

Free & non-binding

Initial Consultation

We gather information about your sector, company size, and the existing knowledge level of your management team to understand your specific requirements.

Individual

Content Preparation

We develop a tailored agenda that incorporates your sector standards, typical threat scenarios, and your specific regulatory obligations.

On-site or Remote

Training Delivery

Live training for your management team, approximately 4 hours. Interactive, without technical jargon, with real-world case studies from your industry.

Audit-proof

Certificate & Documentation

You receive a participation certificate and all documents for your compliance archive – ready for regulatory authorities and auditors.

MuehlCyberConsulting – Cybersecurity with Experience.

We are an independent cybersecurity consulting firm with proven experience in critical infrastructure, regulated sectors, and executive advisory.

Our training is not designed for IT departments – it is designed for you as a decision-maker. Strategic, practical, jargon-free.

Learn more → muehlcyberconsulting.com
30+
Years of cybersecurity experience
18
NIS-2 sectors covered
DE/EN
Training in German and English
100%
Independent advice, no product sales

Request training – complimentary initial consultation.

Fill in the form and we will get back to you within 24 hours to answer your questions without obligation.

Thank you!

We have received your request and will get back to you within 24 hours.