With NIS-2, the number of regulated companies in Germany grows to around 30,000 entities. You learn to check whether you are affected and to implement registration and reporting obligations.

55 min
Multimodal
Über 30 Sprachen
Teilnahmebescheinigung
With NIS-2 and the NIS-2 implementation act, the group of regulated companies in Germany is expanded to around 30,000 particularly important and important entities, far beyond the traditional KRITIS (critical infrastructure) operators. Affected companies must register with the BSI, submit an initial report on significant security incidents within 24 hours, implement risk management measures in line with the state of the art, and include the supply chain. Management is liable to its own entity for implementation and is obliged to undergo training.
00 Fundamentals: NIS-2 and the German implementation act
01 Applicability check and registration
02 Reporting obligations for security incidents
03 Risk management measures and supply chain
04 Management obligations, supervision, and sanctions
05 Summary
06 Knowledge check incl. certificate of completion
Management, IT security and compliance managers, and information security officers in potentially affected companies and KRITIS operators.
Leading organizations trust Bridgly
.png)

Our platform bundles all training management functions, from planning to reporting, in one place.
Training organization
Define who is trained on which content and when.
Training documentation
See at any time who completed which content and when.
Manage participants
CSV import, learning groups, and access rights in one place.
Automated
reminders
Deadlines and recurring training run automatically.
Here you will find the most important answers.
Yes — in practice, even though the GDPR does not set out an explicit training obligation for all employees. Article 39 (1) lit. b GDPR obliges the data protection officer to raise awareness among and train the staff involved in processing operations. In addition, there is Article 32 GDPR: it requires appropriate technical and organisational measures, and training is one of the key organisational measures. The accountability obligation under Article 5 (2) requires that compliance with the data protection principles can be demonstrated — without documented training, this proof is hardly possible. Supervisory authorities therefore regularly assess a lack of employee training as a separate violation, not merely as an aggravating circumstance.
The most common attack vectors target people, not technology. They include: Phishing and spear phishing — messages that harvest login credentials; CEO fraud — fake instructions from supposed superiors; Ransomware — encryption after clicking on an attachment or link; Social engineering — manipulation by phone, chat, or in person; weak and reused passwords; mobile devices, removable media, and open Wi-Fi networks. Effective training teaches the warning signs and safe behavior with emails, passwords, and data — and, above all, clear reporting channels. The time between incident and report determines the extent of the damage.
It aggravates the consequences considerably. Supervisory authorities regard missing training as a violation of the accountability obligation (Article 5 (2) GDPR) and of the obligation to take organisational measures (Article 32 GDPR). Violations of Article 32 are subject to the range of fines under Article 83 (4) GDPR: up to 10 million euros or 2% of worldwide annual turnover, whichever is higher. The frequently cited higher range of 20 million euros or 4% under paragraph 5 concerns other violations, for example of the processing principles or data subject rights. In addition, there are claims for damages by data subjects under Article 82 GDPR and reputational damage. In practice, the first question after an incident is almost always whether it can be proven that employees were trained.
The NIS-2 Directive has been transposed in Germany: the amended BSIG has been in force since December 6, 2025. Since then, the German provisions have been decisive, no longer the articles of the Directive. Section 30 (2) no. 7 BSIG lists "basic training and awareness measures in the field of information technology security" as one of ten risk management measures that the entities concerned must take. This obligation is subject to fines. In addition, Section 38 BSIG applies to management: they must implement the measures and monitor their implementation (subsection 1), are liable for breaches of duty under the rules of company law (subsection 2), and must themselves regularly participate in training (subsection 3). The range of fines is tiered: up to 10 million euros for particularly important entities, up to 7 million euros for important entities. Turnover-based fines only apply above a total turnover of 500 million euros.
At least once a year — even though neither the GDPR nor the BSIG prescribes a fixed interval. Supervisory authorities and the relevant standards ISO/IEC 27001 and BSI Grundschutz consistently assume an annual cycle. The reason lies in the content: attack methods and legal requirements change continuously, and one-off training quickly becomes outdated. In addition, training must be provided when specific occasions arise — when new IT systems are introduced, after security incidents, in the event of significant legal changes, and when new employees join. For particularly exposed areas such as IT administration, HR, and accounting, shorter intervals and in-depth modules are advisable.
In objective, depth, and target audience. Employee training is awareness raising: in around 20 to 45 minutes, it teaches the principles of the GDPR, data subject rights, handling personal data in day-to-day work, what to do in the event of data breaches, and the internal contact persons. Qualification as a data protection officer is specialist training over several days. It covers legal bases, technical and organisational measures, data protection impact assessment, processing on behalf of controllers, international data transfers, and communication with supervisory authorities. They also differ legally: the expert knowledge of the data protection officer is a prerequisite for designation under Article 37 (5) GDPR and is linked to an ongoing obligation of continuing professional development. In Germany, a data protection officer must be designated under Section 38 of the Federal Data Protection Act (BDSG) as soon as at least 20 persons are, as a rule, constantly engaged in automated processing.
Training and professional development for companies and public-sector clients – with audit-proof documentation and a practical focus.
Get in touch nowNote: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.