Training Requirements Under NIS-2: Stay on the Safe Side with sam® and G DATA
Together with our partner G DATA, we have developed modules in sam® that address two key aspects of the NIS 2 requirements: the obligation to provide guidance to all employees and the obligation to provide training to management.
NIS-2 is no longer an issue that can be put off until later. The NIS-2 Implementation Act (NIS2UmsuCG) has been in effect in Germany since December 6, 2025 —and is therefore binding on all affected companies. Anyone working in one of the regulated sectors now has a responsibility.
Together with our partner G DATA, we have developed sam® to include exactly the modules that address two key aspects of the NIS 2 requirements: the obligation to provide guidance to all employees and the obligation to provide training to management.
What NIS-2 Specifically Requires
The NIS 2 Directive applies to companies in critical and important sectors—including energy, transportation, healthcare, digital infrastructure, mechanical engineering, and the chemical industry. It sets out extensive requirements for cybersecurity, risk management, reporting obligations, and supply chain security.
Two of these requirements directly pertain to training and awareness:
- All employees must receive regular training and be made aware of cybersecurity issues.
- Management itself is required to participate in such training—not just to order it.
Neither of these is a discretionary provision. These are legally mandated obligations that require documentation.
How sam® and G DATA Security Awareness Training Address This Issue
secova and G DATA share a close partnership with a clear goal: to provide training in a simple, structured, and legally compliant manner—without unnecessary administrative burden. The G DATA Security Awareness Training, which is available directly through sam®, has now been specifically expanded to include content that addresses these two NIS 2 requirements.
Specifically, this means:
- For Employees: If you already use sam® for training sessions, you are largely prepared to meet the awareness-raising requirement. The licensed G DATA training covers most of this area.
- For Executive Management: With the new executive training module, management can now fulfill its training obligations completely, verifiably, and in a manner that is audit-proof.
All supporting documentation is recorded in the same way that es sam® generally does: transparently, in a traceable manner, and in a way that allows for verification if necessary.
A sincere note
With this enhancement, the G DATA Security Awareness Training in sam® addresses two specific aspects of the NIS 2 requirements. It does not replace full NIS 2 compliance—issues such as risk management, reporting, and supply chain security require additional measures within the organization.
However, when it comes to training and awareness, sam®—in collaboration with G DATA—now offers a solid, structured foundation—exactly where the law specifically requires it.
Would you like to find out more?
If you’d like to know how to systematically address the training requirements under NIS-2 using sam®, simply fill out the form and we’ll get back to you as soon as possible!
Teilen:
That could also be interesting :)