NIS-2 Management Training · Legally Required
Section 38 (3) BSIG requires executives of particularly important and important facilities to undergo regular cybersecurity training. We deliver exactly that – tailored to your industry and your organisation.
Complimentary initial consultation. We respond within 24 hours.
We have received your request and will get back to you within 24 hours.
Or email us directly: nis2@muehlcyberconsulting.com
With the NIS-2 Implementation Act (NIS-2UmsuG), in force since December 2025, management bears personal responsibility for implementing cybersecurity measures – and must demonstrably be trained to do so.
Approximately 30,000 companies across 18 sectors – from energy and healthcare to food production and manufacturing. Affected are particularly important facilities (250+ employees or €50M+ annual revenue) and important facilities (50+ employees or €10M+ annual revenue).
Management must undergo cybersecurity training regularly. The BSIG sets no fixed interval and no minimum duration – both must be chosen on a risk basis. The BSI recommends an in-depth initial training with regular follow-ups, for example on a change in management or significant changes to business processes, risk exposure, or measures. The obligation is non-delegable and typically applies to several members of management personally. Training must be sector-specific.
Fines of up to €10 million or 2% of global annual turnover (particularly important facilities) or up to €7 million or 1.4% (important facilities). Additionally, personal civil liability of management – a waiver by the company is excluded by law.
The BSI states it explicitly: training content must be "appropriate, current, and sector-specific." A generic online course for all industries is not legally sufficient.
| Generic Online Training | MuehlCyberConsulting Training |
|---|---|
| ✕ General cybersecurity topics | ✓ Industry-specific threat scenarios |
| ✕ No reference to your risk exposure | ✓ Analysis of your specific company situation |
| ✕ No sector reference (B3S, ISO sector standards) | ✓ Incorporates sector-specific standards and requirements |
| ✕ Compliance proof legally questionable | ✓ Documented training per BSI guidelines |
| ✕ No personal point of contact | ✓ Experienced consultant, 30+ years of practical experience |
| ✕ Purely internal view – risk of structural blind spots | ✓ Independent external expertise – explicitly recommended by the BSI |
| ✕ Technical jargon, hard to follow | ✓ Management language, clear and practical |
The NIS-2 training delivers concrete value to your leadership team – far beyond meeting a legal obligation.
You demonstrably fulfil § 38 (3) BSIG. Your training certificate is documented in an audit-proof manner – ready for regulators, auditors, and insurers.
As a managing director or board member, you protect yourself from personal civil liability. Your participation in the training is your demonstrable protection.
You understand cyber risks in your industry context – without needing technical expertise. You delegate more effectively, prioritise better, and act more confidently in crisis situations.
Cyberattacks cost mid-sized companies hundreds of thousands of euros on average. Well-informed leadership teams respond faster, minimise downtime, and reduce damage.
NIS-2 compliance is increasingly required by suppliers, customers, and authorities. Your documented training strengthens your position in the supply chain and in tenders.
Our training is designed for decision-makers, not IT professionals. Strategic, practical, in your language – without technical jargon. Ideal for the entire executive team.
From first contact to certificate – a structured, lean process that respects your schedule.
We gather information about your sector, company size, and the existing knowledge level of your management team to understand your specific requirements.
We develop a tailored agenda that incorporates your sector standards, typical threat scenarios, and your specific regulatory obligations.
Interactive live training for your management team – scope as needed (typically approx. 4 hours per session). Using the formats recommended by the BSI: tabletop and audit simulations, scenarios, and case studies from your industry – without technical jargon.
You receive BSI-compliant documentation – including provider, participants (name, role), date and duration, and content referencing § 38 (3) BSIG – plus a participation certificate for your compliance archive. Ready for supervisory audits under §§ 61/62 BSIG. (A participant exam is not legally required.)
Led by Gordon Mühl – Managing Director and ISO 19011 certified auditor with 30+ years of experience – we are an independent cybersecurity consulting firm with proven experience in critical infrastructure, regulated sectors, and executive advisory.
Our training is not designed for IT departments – it is designed for you as a decision-maker. Strategic, practical, jargon-free. The BSI explicitly highlights the value of independent external expertise to avoid internal blind spots.
Learn more → muehlcyberconsulting.comThe key questions on the management training obligation under § 38 (3) BSIG – based on the BSI guidance "Schulung für Geschäftsleitungen", Version 1.0 (April 2026).
The BSIG prescribes no fixed interval and no minimum duration – it only refers to "regularly". The BSI recommends choosing interval and scope on a risk basis: according to the organisation's risk exposure and management's prior knowledge. It recommends an in-depth initial training with regular follow-ups – especially on a change in management or significant changes to business processes, risk exposure, or measures.
No. The BSI requires sector- and entity-specific content. Training that covers only risk management measures falls short of the legal requirements and would be deemed insufficient in a supervisory audit. All three interconnected competency areas are mandatory: identification and assessment of risks, risk management measures, and assessment of their impact.
All members of management as defined in § 2 (13) BSIG – i.e. persons appointed to manage and represent the organisation. In most companies this affects several people. The obligation is non-delegable. The BSI recommends additionally including supporting staff and other decision-makers.
Meaningful documentation contains at least: details of the training provider, the participants (name, role/function), date/time/duration, and the content covered with reference to § 38 (3) BSIG. It must be retained internally and presented on request to the BSI or the independent bodies under §§ 61/62 BSIG. A participant exam is required neither by law nor by the BSI.
In addition to the three core competencies, the ten risk management measures under § 30 (2) BSIG – including risk analysis, incident handling, backup & recovery, supply chain security, cryptography, access control, and multi-factor authentication – as well as sector-specific requirements (e.g. B3S, ISO 27001/27005). We prepare your management specifically to answer the BSI's "guiding questions".
Fines of up to €10 million or 2% of global annual turnover (particularly important facilities) or up to €7 million or 1.4% (important facilities). In addition, the personal civil liability of management for culpably caused damage; a waiver by the company is excluded by law.
Not by law. However, the BSI explicitly recommends the training on a voluntary basis for non-regulated companies too – to strengthen steering capability, risk reduction, transparency, and competitiveness. The recommended content applies to all organisations equally.
Fill in the form and we will get back to you within 24 hours to answer your questions without obligation.
We have received your request and will get back to you within 24 hours.