NIS2 includes cybersecurity training among its cybersecurity risk-management measures and requires training for management bodies of essential and important entities. DORA requires ICT (Information and Communication Technology) security awareness programs and digital operational resilience training for employees and senior management of covered financial entities. Neither regulation names a security awareness vendor or sets one universal monthly training schedule.
For organizations evaluating security awareness training, the important question is not simply whether training is available. It is whether awareness activities are relevant, regular, measurable, documented and practical to maintain over time.
This article explains what NIS2 and DORA require for cybersecurity awareness training, what to look for in a security awareness platform, and how different approaches from Nimblr, SoSafe, KnowBe4 and MetaCompliance compare.
Yes.
Article 21(2)(g) of NIS2 includes basic cyber hygiene practices and cybersecurity training among the cybersecurity risk-management measures that essential and important entities must address.
Article 20(2) specifically addresses management. It requires members of the management bodies of essential and important entities to follow training and says Member States shall encourage those entities to offer similar training to employees on a regular basis.
That distinction matters. NIS2 explicitly requires management training, while regular employee training is framed differently in Article 20.
Organizations should also check the national legislation implementing NIS2 and any additional sector-specific or implementing requirements that apply to them.
A once-a-year training session should not be treated as sufficient evidence of an effective NIS2 security awareness program.
NIS2 places cybersecurity training within broader cybersecurity risk management, while Article 20 calls for employees to be offered similar training to management on a regular basis.
For entities covered by the Commission's NIS2 Implementing Regulation, the expectations are more explicit: awareness activities must be scheduled over time so that they are repeated and cover new employees. The awareness program must also be updated and offered at planned intervals, taking into account changes in cyber hygiene practices, the threat landscape and current risks.
This supports a move away from treating security awareness as a once-a-year compliance exercise toward a program that reinforces awareness regularly and evolves as risks change.
The exact frequency should be determined by the organization's regulatory requirements, risk profile and circumstances. NIS2 does not establish one universal monthly or quarterly training schedule for every organization.
Yes.
Article 13(6) of DORA requires financial entities within its scope to develop ICT (Information and Communication Technology) security awareness programs and digital operational resilience training as compulsory modules within their staff training schemes.
These programs and training apply to employees and senior management.
DORA also states that their level of complexity should be commensurate with the remit of people's functions.
This makes role relevance particularly important.
A Finance employee, IT administrator and senior executive may face very different cyber risks and therefore need different examples, scenarios and levels of detail.
DORA does not prescribe a specific commercial model called "role-based training."
It does, however, require the complexity of ICT security awareness programs and digital operational resilience training to reflect people's functions.
Role-Based Learning is one way an organization can make security training relevant to those differences.
For example:
The organization remains responsible for determining what training is appropriate for its employees, responsibilities and risks.
Neither NIS2 nor DORA sets a universal requirement to run monthly phishing simulations.
A suitable simulation cadence depends on the organization's risk assessment, applicable requirements and security-awareness objectives.
Phishing simulations can nevertheless provide practical experience and behavioral information that training completion alone cannot.
For example, organizations can measure:
Simulations should therefore be viewed as one part of a broader security awareness and risk-management program, not as proof of compliance by themselves.
When evaluating a security awareness program, organizations should consider both evidence of delivery and evidence of behavior.
Evidence of delivery can include:
Behavioral evidence can include:
Training completion is useful evidence that an activity occurred.
It does not, by itself, show whether employees are becoming better prepared to recognize and respond to cyber threats.
A security awareness platform cannot make an organization compliant by itself.
It can, however, make it easier to deliver, repeat, measure and document awareness activities.
When evaluating a platform, consider these six areas.
Can awareness activities run regularly without the security team having to continually build new campaigns?
Consider how easily the organization can maintain training, simulations and reinforcement over time and respond as threats change.
Can training reflect differences in responsibility and risk?
This is particularly relevant when employees in Finance, HR, IT or management encounter different threats.
Can the organization easily document:
Ready-to-use reports can make it easier for security teams to provide evidence for internal reviews, audits and compliance documentation without manually compiling information from different parts of the program.
Does the platform simply record completion, or does it also help employees learn from their security decisions?
Immediate feedback after an interaction with a simulated attack can connect learning directly with the behavior that triggered it.
How much work is required to keep the program active?
A platform may have extensive functionality but still require administrators to continually select content, configure campaigns and schedule simulations.
For organizations with limited security resources, automation can be an important evaluation criterion.
Security awareness platforms process information about employees and their security behavior.
Organizations should verify how that data is processed, stored and protected, and whether the platform fits their privacy, security and internal policy requirements.
Different platforms can support security awareness and compliance programs in different ways.
The important question is not whether a vendor describes itself as "NIS2 compliant" or "DORA ready." Organizations should evaluate the actual capabilities they need.
Nimblr is built around continuous, automated Human Risk Management.
Continuous phishing simulations and Micro Training provide repeated awareness activity throughout the year, while Instant Learning provides feedback directly after an employee interacts with a simulated phishing attack.
Role-Based Learning adds training relevant to different functions and responsibilities.
Nimblr also measures employee behavior over time, including both risky and positive security behaviors such as clicking and reporting. Ready-to-use reports provide an overview of training, simulations and behavioral development, helping organizations document their security awareness activities for internal and compliance reporting.
The approach is particularly relevant for organizations looking for:
Rather than requiring security teams to continually build and schedule individual awareness campaigns, the program is designed to keep running and adapt based on employee behavior.
SoSafe approaches security awareness through behavioral science and adaptive Human Risk Management.
Its platform combines awareness training, simulations, behavioral analytics and role-based learning.
This can be relevant for organizations looking for an adaptive Human Risk Management approach with a strong European focus.
KnowBe4 combines a large security awareness content ecosystem with phishing simulations and reporting.
Its campaign-oriented approach gives administrators extensive control over training assignment, audience segmentation and simulation campaigns.
This can suit organizations with dedicated resources that want significant control over how their security awareness program is configured and managed.
MetaCompliance combines security awareness training and phishing simulations with policy and compliance-management capabilities.
This can be relevant for organizations that want employee awareness connected more closely with broader compliance, policy management and governance processes.
There is no single platform prescribed by either NIS2 or DORA.
Organizations should start with their regulatory scope, risks and operating model.
These are differences in platform approach, not assessments of whether using a particular vendor makes an organization compliant.
No.
Security awareness is one part of much broader cybersecurity and operational-resilience requirements.
A platform can help organizations deliver, repeat, measure and document awareness activities, but the organization remains responsible for determining its obligations and implementing the appropriate technical, operational, organizational and governance measures.
A vendor label such as "NIS2 ready" should therefore not replace an assessment of what the organization actually needs.
Cyber threats do not appear once a year, and security behavior is not built through a single training session.
Regular training, realistic simulations and timely reinforcement give employees repeated opportunities to recognize threats and practice safer security behavior.
A continuous approach also gives organizations more information about how behavior develops over time.
Instead of asking only:
"Did employees complete their annual training?"
organizations can also ask:
"Are employees getting better at recognizing and reporting threats?"
This is where security awareness starts moving beyond training completion toward Human Risk Management.
Yes. Article 21(2)(g) includes basic cyber hygiene practices and cybersecurity training among the cybersecurity risk-management measures for essential and important entities.
Article 20(2) also requires members of management bodies to follow training and says Member States shall encourage essential and important entities to offer similar training to employees regularly.
Organizations should not treat one annual training session as sufficient evidence of an effective NIS2 awareness program.
NIS2 addresses regular employee training, while the Commission's Implementing Regulation requires repeated awareness activities at planned intervals for the entities it covers.
NIS2 does not, however, establish one universal monthly or quarterly training frequency for every organization.
Yes. DORA requires covered financial entities to develop ICT security awareness programs and digital operational resilience training as compulsory parts of staff training for employees and senior management.
ICT stands for Information and Communication Technology.
DORA uses the term because the regulation addresses how financial entities manage risks related to their information and communication technology systems and digital operational resilience.
DORA requires the complexity of awareness programs and training to be commensurate with people's functions.
Role-Based Learning can help organizations make training relevant to different responsibilities and risks, although DORA does not mandate a particular commercial training model.
Neither regulation establishes a universal requirement to use a specific phishing simulation platform or run phishing tests at a fixed frequency.
Simulations can support a broader awareness program by providing practical experience and behavioral evidence.
Training completion is useful for showing that training was delivered.
Organizations can gain a broader view by also measuring how employees respond to simulated threats, whether they report suspicious messages and whether security behavior changes over time.
Platforms including Nimblr, SoSafe, KnowBe4 and MetaCompliance provide security awareness capabilities that can support parts of an organization's NIS2 or DORA program.
Their approaches differ. Nimblr focuses on continuous, automated Human Risk Management, Role-Based Learning, behavioral measurement and ready-to-use reporting. SoSafe emphasizes behavioral science and adaptive Human Risk Management. KnowBe4 provides a broad content ecosystem and extensive campaign controls. MetaCompliance combines awareness with compliance and policy-management capabilities.
No platform alone makes an organization NIS2 or DORA compliant.
Compliance training can help an organization deliver and document required awareness activities.
Human Risk Management goes further by using behavioral information to understand where human-related cyber risk exists, how behavior changes over time and where additional intervention may be needed.
For a deeper explanation, see our guide to Human Risk Management platforms.
This article provides general information and is not legal advice. Organizations should consult the official NIS2 Directive, DORA Regulation, applicable implementing legislation and national or sector-specific requirements for their circumstances.