Back to Blog

Security Awareness Training for NIS2 and DORA: Requirements and Platform Criteria

What does NIS2 and DORA require for cybersecurity awareness training? Learn about regular training, role relevance, reporting and how leading security awareness platforms compare.

NIS2 includes cybersecurity training among its cybersecurity risk-management measures and requires training for management bodies of essential and important entities. DORA requires ICT (Information and Communication Technology) security awareness programs and digital operational resilience training for employees and senior management of covered financial entities. Neither regulation names a security awareness vendor or sets one universal monthly training schedule.

For organizations evaluating security awareness training, the important question is not simply whether training is available. It is whether awareness activities are relevant, regular, measurable, documented and practical to maintain over time.

This article explains what NIS2 and DORA require for cybersecurity awareness training, what to look for in a security awareness platform, and how different approaches from Nimblr, SoSafe, KnowBe4 and MetaCompliance compare.

Does NIS2 require cybersecurity training?

Yes.

Article 21(2)(g) of NIS2 includes basic cyber hygiene practices and cybersecurity training among the cybersecurity risk-management measures that essential and important entities must address.

Article 20(2) specifically addresses management. It requires members of the management bodies of essential and important entities to follow training and says Member States shall encourage those entities to offer similar training to employees on a regular basis.

That distinction matters. NIS2 explicitly requires management training, while regular employee training is framed differently in Article 20.

Organizations should also check the national legislation implementing NIS2 and any additional sector-specific or implementing requirements that apply to them.

Is annual cybersecurity training enough for NIS2?

A once-a-year training session should not be treated as sufficient evidence of an effective NIS2 security awareness program.

NIS2 places cybersecurity training within broader cybersecurity risk management, while Article 20 calls for employees to be offered similar training to management on a regular basis.

For entities covered by the Commission's NIS2 Implementing Regulation, the expectations are more explicit: awareness activities must be scheduled over time so that they are repeated and cover new employees. The awareness program must also be updated and offered at planned intervals, taking into account changes in cyber hygiene practices, the threat landscape and current risks.

This supports a move away from treating security awareness as a once-a-year compliance exercise toward a program that reinforces awareness regularly and evolves as risks change.

The exact frequency should be determined by the organization's regulatory requirements, risk profile and circumstances. NIS2 does not establish one universal monthly or quarterly training schedule for every organization.

Does DORA require cybersecurity awareness training?

Yes.

Article 13(6) of DORA requires financial entities within its scope to develop ICT (Information and Communication Technology) security awareness programs and digital operational resilience training as compulsory modules within their staff training schemes.

These programs and training apply to employees and senior management.

DORA also states that their level of complexity should be commensurate with the remit of people's functions.

This makes role relevance particularly important.

A Finance employee, IT administrator and senior executive may face very different cyber risks and therefore need different examples, scenarios and levels of detail.

Does DORA require role-relevant training?

DORA does not prescribe a specific commercial model called "role-based training."

It does, however, require the complexity of ICT security awareness programs and digital operational resilience training to reflect people's functions.

Role-Based Learning is one way an organization can make security training relevant to those differences.

For example:

  • Finance
    • Payment fraud
    • Invoice manipulation
    • Executive impersonation
  • HR
    • Payroll manipulation
    • Personal data theft
    • Employee-related social engineering
  • IT
    • Credential theft
    • Privileged access
    • MFA-related social engineering
  • Executives
    • Targeted phishing
    • Impersonation
    • Sensitive information requests

The organization remains responsible for determining what training is appropriate for its employees, responsibilities and risks.

Do NIS2 or DORA require monthly phishing tests?

Neither NIS2 nor DORA sets a universal requirement to run monthly phishing simulations.

A suitable simulation cadence depends on the organization's risk assessment, applicable requirements and security-awareness objectives.

Phishing simulations can nevertheless provide practical experience and behavioral information that training completion alone cannot.

For example, organizations can measure:

  • Whether employees interact with simulated threats
  • Whether they recognize and report suspicious messages
  • Whether risky behavior is repeated
  • Whether behavior changes over time

Simulations should therefore be viewed as one part of a broader security awareness and risk-management program, not as proof of compliance by themselves.

What should a security awareness program be able to show?

When evaluating a security awareness program, organizations should consider both evidence of delivery and evidence of behavior.

Evidence of delivery can include:

  • Who was assigned training
  • Who completed it
  • When awareness activities took place
  • Which roles received specialized training
  • What simulations or practical exercises were conducted

Behavioral evidence can include:

  • How employees responded to simulations
  • Whether suspicious messages were reported
  • Whether risky behaviors were repeated
  • Whether behavior changed over time
  • How results influenced subsequent training or interventions

Training completion is useful evidence that an activity occurred.

It does not, by itself, show whether employees are becoming better prepared to recognize and respond to cyber threats.

What should you look for in a NIS2 or DORA security awareness platform?

A security awareness platform cannot make an organization compliant by itself.

It can, however, make it easier to deliver, repeat, measure and document awareness activities.

When evaluating a platform, consider these six areas.

1. Regular and repeatable training

Can awareness activities run regularly without the security team having to continually build new campaigns?

Consider how easily the organization can maintain training, simulations and reinforcement over time and respond as threats change.

2. Role relevance

Can training reflect differences in responsibility and risk?

This is particularly relevant when employees in Finance, HR, IT or management encounter different threats.

3. Reporting and evidence

Can the organization easily document:

  • Training activity and completion
  • Role-based learning
  • Simulations
  • Employee responses
  • Reporting behavior
  • Behavioral development over time

Ready-to-use reports can make it easier for security teams to provide evidence for internal reviews, audits and compliance documentation without manually compiling information from different parts of the program.

4. Behavioral feedback

Does the platform simply record completion, or does it also help employees learn from their security decisions?

Immediate feedback after an interaction with a simulated attack can connect learning directly with the behavior that triggered it.

5. Administrative effort

How much work is required to keep the program active?

A platform may have extensive functionality but still require administrators to continually select content, configure campaigns and schedule simulations.

For organizations with limited security resources, automation can be an important evaluation criterion.

6. Data handling

Security awareness platforms process information about employees and their security behavior.

Organizations should verify how that data is processed, stored and protected, and whether the platform fits their privacy, security and internal policy requirements.

How do Nimblr, SoSafe, KnowBe4 and MetaCompliance compare?

Different platforms can support security awareness and compliance programs in different ways.

The important question is not whether a vendor describes itself as "NIS2 compliant" or "DORA ready." Organizations should evaluate the actual capabilities they need.

Nimblr

Nimblr is built around continuous, automated Human Risk Management.

Continuous phishing simulations and Micro Training provide repeated awareness activity throughout the year, while Instant Learning provides feedback directly after an employee interacts with a simulated phishing attack.

Role-Based Learning adds training relevant to different functions and responsibilities.

Nimblr also measures employee behavior over time, including both risky and positive security behaviors such as clicking and reporting. Ready-to-use reports provide an overview of training, simulations and behavioral development, helping organizations document their security awareness activities for internal and compliance reporting.

The approach is particularly relevant for organizations looking for:

  • Continuous awareness activity
  • Role-Based Learning
  • Behavioral measurement
  • Immediate reinforcement
  • Automated simulations and training
  • Ready-to-use reporting for compliance documentation
  • Lower ongoing campaign administration

Rather than requiring security teams to continually build and schedule individual awareness campaigns, the program is designed to keep running and adapt based on employee behavior.

SoSafe

SoSafe approaches security awareness through behavioral science and adaptive Human Risk Management.

Its platform combines awareness training, simulations, behavioral analytics and role-based learning.

This can be relevant for organizations looking for an adaptive Human Risk Management approach with a strong European focus.

KnowBe4

KnowBe4 combines a large security awareness content ecosystem with phishing simulations and reporting.

Its campaign-oriented approach gives administrators extensive control over training assignment, audience segmentation and simulation campaigns.

This can suit organizations with dedicated resources that want significant control over how their security awareness program is configured and managed.

MetaCompliance

MetaCompliance combines security awareness training and phishing simulations with policy and compliance-management capabilities.

This can be relevant for organizations that want employee awareness connected more closely with broader compliance, policy management and governance processes.

Which security awareness platform is suitable for NIS2 or DORA?

There is no single platform prescribed by either NIS2 or DORA.

Organizations should start with their regulatory scope, risks and operating model.

  • Nimblr: Relevant for organizations prioritizing continuous awareness, automation, Role-Based Learning, behavioral measurement and ready-to-use reporting with limited ongoing administration.
  • SoSafe: Relevant for organizations looking for behavioral science, adaptive Human Risk Management and a European-focused offering.
  • KnowBe4: Relevant for organizations wanting a broad content ecosystem and extensive administrator control over training and simulation campaigns.
  • MetaCompliance: Relevant for organizations wanting security awareness closely connected with compliance and policy management.

These are differences in platform approach, not assessments of whether using a particular vendor makes an organization compliant.

Can a security awareness platform make an organization NIS2 or DORA compliant?

No.

Security awareness is one part of much broader cybersecurity and operational-resilience requirements.

A platform can help organizations deliver, repeat, measure and document awareness activities, but the organization remains responsible for determining its obligations and implementing the appropriate technical, operational, organizational and governance measures.

A vendor label such as "NIS2 ready" should therefore not replace an assessment of what the organization actually needs.

Why does continuous security awareness matter?

Cyber threats do not appear once a year, and security behavior is not built through a single training session.

Regular training, realistic simulations and timely reinforcement give employees repeated opportunities to recognize threats and practice safer security behavior.

A continuous approach also gives organizations more information about how behavior develops over time.

Instead of asking only:

"Did employees complete their annual training?"

organizations can also ask:

"Are employees getting better at recognizing and reporting threats?"

This is where security awareness starts moving beyond training completion toward Human Risk Management.

Frequently asked questions

Does NIS2 require cybersecurity awareness training?

Yes. Article 21(2)(g) includes basic cyber hygiene practices and cybersecurity training among the cybersecurity risk-management measures for essential and important entities.

Article 20(2) also requires members of management bodies to follow training and says Member States shall encourage essential and important entities to offer similar training to employees regularly.

Is annual cybersecurity training enough for NIS2?

Organizations should not treat one annual training session as sufficient evidence of an effective NIS2 awareness program.

NIS2 addresses regular employee training, while the Commission's Implementing Regulation requires repeated awareness activities at planned intervals for the entities it covers.

NIS2 does not, however, establish one universal monthly or quarterly training frequency for every organization.

Does DORA require cybersecurity awareness training?

Yes. DORA requires covered financial entities to develop ICT security awareness programs and digital operational resilience training as compulsory parts of staff training for employees and senior management.

What does ICT mean in DORA?

ICT stands for Information and Communication Technology.

DORA uses the term because the regulation addresses how financial entities manage risks related to their information and communication technology systems and digital operational resilience.

Does DORA require role-based cybersecurity training?

DORA requires the complexity of awareness programs and training to be commensurate with people's functions.

Role-Based Learning can help organizations make training relevant to different responsibilities and risks, although DORA does not mandate a particular commercial training model.

Is phishing simulation mandatory under NIS2 or DORA?

Neither regulation establishes a universal requirement to use a specific phishing simulation platform or run phishing tests at a fixed frequency.

Simulations can support a broader awareness program by providing practical experience and behavioral evidence.

Is training completion enough to measure security awareness?

Training completion is useful for showing that training was delivered.

Organizations can gain a broader view by also measuring how employees respond to simulated threats, whether they report suspicious messages and whether security behavior changes over time.

Which security awareness platforms can support NIS2 and DORA awareness programs?

Platforms including Nimblr, SoSafe, KnowBe4 and MetaCompliance provide security awareness capabilities that can support parts of an organization's NIS2 or DORA program.

Their approaches differ. Nimblr focuses on continuous, automated Human Risk Management, Role-Based Learning, behavioral measurement and ready-to-use reporting. SoSafe emphasizes behavioral science and adaptive Human Risk Management. KnowBe4 provides a broad content ecosystem and extensive campaign controls. MetaCompliance combines awareness with compliance and policy-management capabilities.

No platform alone makes an organization NIS2 or DORA compliant.

What is the difference between compliance training and Human Risk Management?

Compliance training can help an organization deliver and document required awareness activities.

Human Risk Management goes further by using behavioral information to understand where human-related cyber risk exists, how behavior changes over time and where additional intervention may be needed.

For a deeper explanation, see our guide to Human Risk Management platforms.

This article provides general information and is not legal advice. Organizations should consult the official NIS2 Directive, DORA Regulation, applicable implementing legislation and national or sector-specific requirements for their circumstances.

Author

Nimblr Security Awareness

Nimblr Security Awareness

The Nimblr team is made up of people who are passionate about cyber security, developing training for real people, and tracking behavioral change.