Skip to content

NIS-2 Management Training · Legally Required

Your NIS-2 Training Obligation –
Compliant, Industry-Specific, Certified.

Section 38 (3) BSIG requires executives of particularly important and important facilities to undergo regular cybersecurity training. We deliver exactly that – tailored to your industry and your organisation.

Based on BSI Guidance Version 1.0 (April 2026)
Sector-specific – not a one-size-fits-all product
Certificate for your compliance documentation
No technical background required

Request Training

Complimentary initial consultation. We respond within 24 hours.

Thank you!

We have received your request and will get back to you within 24 hours.

Or email us directly: nis2@muehlcyberconsulting.com

§ 38 (3) BSIG: Cybersecurity training is mandatory – no discretion.

With the NIS-2 Implementation Act (NIS-2UmsuG), in force since December 2025, management bears personal responsibility for implementing cybersecurity measures – and must demonstrably be trained to do so.

Who is affected?

Approximately 30,000 companies across 18 sectors – from energy and healthcare to food production and manufacturing. Affected are particularly important facilities (250+ employees or €50M+ annual revenue) and important facilities (50+ employees or €10M+ annual revenue).

What is required?

Management must undergo cybersecurity training regularly. The BSIG sets no fixed interval and no minimum duration – both must be chosen on a risk basis. The BSI recommends an in-depth initial training with regular follow-ups, for example on a change in management or significant changes to business processes, risk exposure, or measures. The obligation is non-delegable and typically applies to several members of management personally. Training must be sector-specific.

What are the penalties?

Fines of up to €10 million or 2% of global annual turnover (particularly important facilities) or up to €7 million or 1.4% (important facilities). Additionally, personal civil liability of management – a waiver by the company is excluded by law.

€10M
Maximum Fine
or 2% of global annual turnover (particularly important facilities)
€7M
Maximum Fine
or 1.4% of global annual turnover (important facilities)
The BSI updated its guidance to the final Version 1.0 in April 2026 (first issued 09/2025). It is not legally binding, but defines the BSI's authoritative understanding of what a compliant training must deliver. The basis: three interconnected competency areas – risk identification, risk management measures, and impact assessment. A focus on measures alone is considered insufficient by the BSI. Training must be "appropriate, current, and sector-specific."

Last updated: June 2026 · Source: BSI guidance „Schulung für Geschäftsleitungen", Version 1.0 (April 2026) BSI Guidance (German) →

A one-size-fits-all solution does not meet the legal requirement.

The BSI states it explicitly: training content must be "appropriate, current, and sector-specific." A generic online course for all industries is not legally sufficient.

Generic Online Training MuehlCyberConsulting Training
General cybersecurity topics Industry-specific threat scenarios
No reference to your risk exposure Analysis of your specific company situation
No sector reference (B3S, ISO sector standards) Incorporates sector-specific standards and requirements
Compliance proof legally questionable Documented training per BSI guidelines
No personal point of contact Experienced consultant, 30+ years of practical experience
Purely internal view – risk of structural blind spots Independent external expertise – explicitly recommended by the BSI
Technical jargon, hard to follow Management language, clear and practical
Only when training addresses your industry, your specific risks, and your regulatory environment can your management make well-founded decisions – and the legal obligation is considered fulfilled.

More than compliance – strategic security for your organisation.

The NIS-2 training delivers concrete value to your leadership team – far beyond meeting a legal obligation.

Legal Certainty

You demonstrably fulfil § 38 (3) BSIG. Your training certificate is documented in an audit-proof manner – ready for regulators, auditors, and insurers.

Personal Liability Protection

As a managing director or board member, you protect yourself from personal civil liability. Your participation in the training is your demonstrable protection.

Better Risk Decisions

You understand cyber risks in your industry context – without needing technical expertise. You delegate more effectively, prioritise better, and act more confidently in crisis situations.

Protection Against Business Disruption

Cyberattacks cost mid-sized companies hundreds of thousands of euros on average. Well-informed leadership teams respond faster, minimise downtime, and reduce damage.

Trust with Customers and Partners

NIS-2 compliance is increasingly required by suppliers, customers, and authorities. Your documented training strengthens your position in the supply chain and in tenders.

No Technical Background Required

Our training is designed for decision-makers, not IT professionals. Strategic, practical, in your language – without technical jargon. Ideal for the entire executive team.

Tailored in four steps.

From first contact to certificate – a structured, lean process that respects your schedule.

Free & non-binding

Initial Consultation

We gather information about your sector, company size, and the existing knowledge level of your management team to understand your specific requirements.

Individual

Content Preparation

We develop a tailored agenda that incorporates your sector standards, typical threat scenarios, and your specific regulatory obligations.

On-site or Remote

Training Delivery

Interactive live training for your management team – scope as needed (typically approx. 4 hours per session). Using the formats recommended by the BSI: tabletop and audit simulations, scenarios, and case studies from your industry – without technical jargon.

Audit-proof

Certificate & Documentation

You receive BSI-compliant documentation – including provider, participants (name, role), date and duration, and content referencing § 38 (3) BSIG – plus a participation certificate for your compliance archive. Ready for supervisory audits under §§ 61/62 BSIG. (A participant exam is not legally required.)

MuehlCyberConsulting – Cybersecurity with Experience.

Led by Gordon Mühl – Managing Director and ISO 19011 certified auditor with 30+ years of experience – we are an independent cybersecurity consulting firm with proven experience in critical infrastructure, regulated sectors, and executive advisory.

Our training is not designed for IT departments – it is designed for you as a decision-maker. Strategic, practical, jargon-free. The BSI explicitly highlights the value of independent external expertise to avoid internal blind spots.

Learn more → muehlcyberconsulting.com
30+
Years of cybersecurity experience
18
NIS-2 sectors covered
DE/EN
Training in German and English
100%
Independent advice, no product sales

NIS-2 training obligation: answers at a glance.

The key questions on the management training obligation under § 38 (3) BSIG – based on the BSI guidance "Schulung für Geschäftsleitungen", Version 1.0 (April 2026).

How often and how long must management be trained?

The BSIG prescribes no fixed interval and no minimum duration – it only refers to "regularly". The BSI recommends choosing interval and scope on a risk basis: according to the organisation's risk exposure and management's prior knowledge. It recommends an in-depth initial training with regular follow-ups – especially on a change in management or significant changes to business processes, risk exposure, or measures.

Is a generic online course for all industries sufficient?

No. The BSI requires sector- and entity-specific content. Training that covers only risk management measures falls short of the legal requirements and would be deemed insufficient in a supervisory audit. All three interconnected competency areas are mandatory: identification and assessment of risks, risk management measures, and assessment of their impact.

Who must attend the training?

All members of management as defined in § 2 (13) BSIG – i.e. persons appointed to manage and represent the organisation. In most companies this affects several people. The obligation is non-delegable. The BSI recommends additionally including supporting staff and other decision-makers.

What must be documented – and is an exam required?

Meaningful documentation contains at least: details of the training provider, the participants (name, role/function), date/time/duration, and the content covered with reference to § 38 (3) BSIG. It must be retained internally and presented on request to the BSI or the independent bodies under §§ 61/62 BSIG. A participant exam is required neither by law nor by the BSI.

What does the training cover in concrete terms?

In addition to the three core competencies, the ten risk management measures under § 30 (2) BSIG – including risk analysis, incident handling, backup & recovery, supply chain security, cryptography, access control, and multi-factor authentication – as well as sector-specific requirements (e.g. B3S, ISO 27001/27005). We prepare your management specifically to answer the BSI's "guiding questions".

What are the penalties for non-compliance?

Fines of up to €10 million or 2% of global annual turnover (particularly important facilities) or up to €7 million or 1.4% (important facilities). In addition, the personal civil liability of management for culpably caused damage; a waiver by the company is excluded by law.

Do non-regulated companies need to train their management too?

Not by law. However, the BSI explicitly recommends the training on a voluntary basis for non-regulated companies too – to strengthen steering capability, risk reduction, transparency, and competitiveness. The recommended content applies to all organisations equally.

Request training – complimentary initial consultation.

Fill in the form and we will get back to you within 24 hours to answer your questions without obligation.

Thank you!

We have received your request and will get back to you within 24 hours.