---
title: "Free NIS2 Management Training Log (2026) — Article 20, Excel"
description: "Track management-body cybersecurity training for NIS2 Art 20 audits: sessions, hours, renewal dates. Free XLSX, no email gate."
canonical: https://www.orbiqhq.com/templates/nis2-management-training-log
html: https://www.orbiqhq.com/templates/nis2-management-training-log
publisher: Orbiq GmbH
language: en
---
# Free NIS2 Management Training Log (2026) — Article 20, Excel

Track management-body cybersecurity training for NIS2 Art 20 audits: sessions, hours, renewal dates. Free XLSX, no email gate.


**This free NIS2 management training log is a downloadable Excel workbook (plus PDF field guide and machine-readable Markdown) that evidences the training duty [Article 20(2) of Directive (EU) 2022/2555](https://eur-lex.europa.eu/eli/dir/2022/2555/oj) places on management bodies of essential and important entities: a named register of management-body members, one training record per member per session — provider, date, hours, content mapped to the three Article 20(2) objectives, evidence reference — with computed next-due dates that flag overdue members automatically, a forward session catalogue, and a per-country quick reference for how national laws quantify "regularly". Ungated.**

Article 20 is the part of NIS2 that auditors can check in five minutes. The measures in Article 21 take months to assess; whether every member of the management body has an in-date, evidenced training record is a yes/no question against a list of names — and in Germany it has been a live one since **6 December 2025**, when the [NIS2UmsuCG](https://www.taylorwessing.com/en/insights-and-events/insights/2025/11/germanys-implementation-of-nis2) took effect with no transition period and personal, waiver-proof liability attached. The log exists so that the answer is always yes, on paper.

## Key takeaways

1. **The training duty is real and personal.** Article 20(2) says management-body members "are required to follow training" — required, not encouraged. In Germany's transposition (§ 38 Abs. 3 BSIG) the duty is explicitly personal and non-delegable: the Geschäftsführung cannot send the CISO in its place, and § 38 Abs. 2 makes culpable breaches a personal-liability matter with recourse waivers legally ineffective.
2. **"Regularly" is a national-law variable — the workbook tracks it per row.** Germany's explanatory materials assume ~4 hours at least every 3 years; Latvia requires regular training with content reviewed at least annually (commonly implemented as annual); Czechia's Act No. 264/2025 requires governing bodies to be properly trained; Belgium's CCB deliberately prescribes nothing and leaves duration to the entity. The renewal interval is a column, not an assumption — set it per the strictest rule that applies.
3. **Keep governance training and staff training apart.** Management training is Article 20(2); staff cyber-hygiene training is Article 21(2)(g) — a different duty with different evidence, tracked in your LMS. Mixing the two is the most common way entities end up unable to show either cleanly.
4. **Auditors sample individuals, not averages.** Supervisory practice converges on per-member records: who, what, when, how long, by whom, evidenced how, due when — plus the programme document and the board minutes showing the *trained* body approving the Article 21 measure set. The workbook's register computes each member's latest session and next due date and highlights gaps.
5. **The evidence reference is the record.** A training certificate that cannot be produced on request does not exist, as far as an audit is concerned. Every completed log row carries a pointer to a stored artefact — certificate ID, signed attendance sheet, LMS export.

## What's inside the workbook

| Sheet | What it holds | Why it matters |
|---|---|---|
| **1. Management Body Register** | One row per member: name, role, governing body, appointment date, Article 20 scope flag with justification, status, computed latest-session and next-due columns | The list auditors sample against — including departed members, who stay on it |
| **2. Training Log** | One row per member per session: title, provider and type, date, duration in hours, format, Article 20(2) objectives covered, renewal interval, computed next-due date, evidence reference, completion status | The per-individual record supervisors actually ask for |
| **3. Session Catalogue** | The forward programme: planned sessions, audience, objectives, frequency, delivery method, provider, effectiveness measure | The training-programme document that sits alongside the records |
| **4. Jurisdiction Reference** | EU baseline plus Germany, Latvia, Czechia, Belgium, Norway and the UK: instrument, rule, quantification, status | "Regularly" decided per country, on one sheet |

Overdue members highlight in red automatically, dropdowns keep the enums consistent, and worked example rows show a completed record set for a fictional management board. The [machine-readable Markdown variant](/downloads/templates/nis2-management-training-log.md) carries the full field definitions, enums and agent workflow rules — coverage, onboarding, evidence and objective-completeness health checks — so an AI agent can maintain the log and produce an audit extract from the file alone.

## How to use it

1. **List the management body first.** One row per member, including non-executives where your national transposition scopes them in — and record the justification either way. Departures flip to `departed`; they never leave the register, because historical approvals are audited against historical membership.
2. **Log sessions per member, not per event.** A governance session attended by five directors is five rows, each with its own evidence reference. Record the hours — supervisors expect duration per record, not per programme.
3. **Map content to the three Article 20(2) objectives.** Identify risks, assess risk-management practices, impact on services. Across a member's in-date sessions the union should cover all three — a tabletop alone is supplementary, not sufficient.
4. **Set the renewal interval from national law, not preference.** 12 months where Latvia-style annual rules apply, 36 months as the German benchmark, and document the reasoning where your country leaves it open. The next-due date computes from the interval and turns red when it passes.
5. **Close the loop in the minutes.** The training exists so the body can competently approve the Article 21 measures — so make sure the approval minutes name the attendees and the measure-set version. Pair this log with our [Article 21 compliance checklist](/eu-regulations/nis2-compliance-checklist-article-21) for the measure side.

## Legal basis

- **[Directive (EU) 2022/2555](https://eur-lex.europa.eu/eli/dir/2022/2555/oj) (NIS2), Article 20(1)** — management bodies of essential and important entities must approve the cybersecurity risk-management measures taken to comply with Article 21, oversee their implementation, and can be held liable for the entity's infringements.
- **Article 20(2)** — members of the management bodies are required to follow training, and entities are encouraged to offer similar training to their employees on a regular basis, so that they gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided.
- **Article 21(2)(g)** — basic cyber-hygiene practices and cybersecurity training as a mandatory risk-management measure: the separate, staff-level duty this log deliberately does not track.
- **§ 38 BSIG (Germany, NIS2UmsuCG)** — Abs. 1: approval and oversight; Abs. 2: personal liability of Geschäftsleiter for culpable breaches, recourse waivers ineffective; Abs. 3: the personal, regular training duty. In force 6 December 2025 (BGBl. 2025 I Nr. 301), no transition period.

## UK and Norway/EEA

**UK:** the [Cyber Security and Resilience Bill](https://bills.parliament.uk/bills/4035) — in the House of Lords as of July 2026, Royal Assent expected late 2026 — strengthens regulator scrutiny of board-level cyber governance but contains **no Article 20-style statutory training duty**; expectations ride on the voluntary Cyber Governance Code of Practice. UK entities selling into or operating in the EU should evidence against NIS2 anyway. **Norway:** the Digital Security Act ([digitalsikkerhetsloven](https://www.wr.no/en/news/five-things-you-need-to-know-about-the-digital-security-act), in force 1 October 2025) makes management responsible for the security level and requires it to approve the security management system with an annual review; management training is expected in line with NIS2, with [Nasjonal sikkerhetsmyndighet (NSM)](https://nsm.no/) as the supervising authority — even though NIS2 itself is not yet incorporated into the EEA Agreement.

## From training log to buyer-visible evidence

The same governance evidence a supervisor samples is what enterprise buyers increasingly ask for in security questionnaires — "does senior management receive cybersecurity training?" is a standard row. [Orbiq](/platform/trust-updates) publishes governance evidence — training attestations, policy approvals, management-review cadence — in a governed [Trust Center](/trust-center/what-is-a-trust-center), so the record you keep for the [NIS2 audit](/eu-regulations/nis2-audit-readiness-continuous-evidence) answers the customer too. For the wider evidence stack, see our guides to [NIS2 compliance](/eu-regulations/nis2-compliance) and [internal vs external proof](/eu-regulations/nis2-internal-proof-vs-external-proof).

## Sources & References

1. [Directive (EU) 2022/2555 (NIS2) — full text](https://eur-lex.europa.eu/eli/dir/2022/2555/oj) — Articles 20(1), 20(2), 21(2)(g).
2. [Taylor Wessing — Germany's implementation of NIS2](https://www.taylorwessing.com/en/insights-and-events/insights/2025/11/germanys-implementation-of-nis2) — NIS2UmsuCG, § 38 BSIG duties and personal liability; in force 6 December 2025.
3. [Heise — NIS2: Mandatory cyber security training for management boards](https://www.heise.de/en/background/NIS2-Mandatory-cyber-security-training-for-management-boards-10282487.html) — the § 38 Abs. 3 analysis and the "every 3 years / ~4 hours" explanatory-materials benchmark.
4. [Transferstelle Cybersicherheit — NIS2-Schulungspflicht für Geschäftsleitungen](https://transferstelle-cybersicherheit.de/nis2-schulungspflicht-fuer-geschaeftsleitungen-das-muessen-sie-wissen/) — the German benchmark as a Richtwert, not a statutory minimum.
5. [Centre for Cybersecurity Belgium — NIS2 brochure](https://atwork.safeonweb.be/sites/default/files/2024-10/NIS2%20Brochure%20EN.pdf) — Belgian management-training expectations and planning guidance.
6. [Schjødt — Norway's Digital Security Act now in effect](https://schjodt.com/news/norways-digital-security-act-now-in-effect) — management approval and annual review of the security management system.
7. [Wikborg Rein — Five things you need to know about the Digital Security Act](https://www.wr.no/en/news/five-things-you-need-to-know-about-the-digital-security-act) — Norwegian management duties.
8. [UK Parliament — Cyber Security and Resilience Bill](https://bills.parliament.uk/bills/4035) — bill status; no NIS2-style management-training provision.

## Related Reading

- [NIS2 Compliance: Requirements, Deadlines & Implementation](/eu-regulations/nis2-compliance)
- [NIS2 Audit Readiness: Continuous Evidence Over Annual Scrambles](/eu-regulations/nis2-audit-readiness-continuous-evidence)
- [NIS2 Internal Proof vs External Proof](/eu-regulations/nis2-internal-proof-vs-external-proof)
- [Free Template: NIS2 Supplier Evidence Request Checklist](/templates/nis2-supplier-evidence-request-checklist) — the Article 21(2)(d) supply-chain sibling
- [Free Template: NIS2 Incident Reporting Pack](/templates/nis2-incident-reporting-pack) — the Article 23 reporting forms