
Free NIS2 Management Training Log (2026) — Article 20, Excel
Track management-body cybersecurity training for NIS2 Art 20 audits: sessions, hours, renewal dates. Free XLSX, no email gate.
Download this template
Version 1.0 · Updated Jul 21, 2026 · Free, no email required
Free NIS2 Management Training Log (Article 20, Excel)
This free NIS2 management training log is a downloadable Excel workbook (plus PDF field guide and machine-readable Markdown) that evidences the training duty Article 20(2) of Directive (EU) 2022/2555 places on management bodies of essential and important entities: a named register of management-body members, one training record per member per session — provider, date, hours, content mapped to the three Article 20(2) objectives, evidence reference — with computed next-due dates that flag overdue members automatically, a forward session catalogue, and a per-country quick reference for how national laws quantify "regularly". Ungated.
Article 20 is the part of NIS2 that auditors can check in five minutes. The measures in Article 21 take months to assess; whether every member of the management body has an in-date, evidenced training record is a yes/no question against a list of names — and in Germany it has been a live one since 6 December 2025, when the NIS2UmsuCG took effect with no transition period and personal, waiver-proof liability attached. The log exists so that the answer is always yes, on paper.
Key takeaways
- The training duty is real and personal. Article 20(2) says management-body members "are required to follow training" — required, not encouraged. In Germany's transposition (§ 38 Abs. 3 BSIG) the duty is explicitly personal and non-delegable: the Geschäftsführung cannot send the CISO in its place, and § 38 Abs. 2 makes culpable breaches a personal-liability matter with recourse waivers legally ineffective.
- "Regularly" is a national-law variable — the workbook tracks it per row. Germany's explanatory materials assume ~4 hours at least every 3 years; Latvia requires regular training with content reviewed at least annually (commonly implemented as annual); Czechia's Act No. 264/2025 requires governing bodies to be properly trained; Belgium's CCB deliberately prescribes nothing and leaves duration to the entity. The renewal interval is a column, not an assumption — set it per the strictest rule that applies.
- Keep governance training and staff training apart. Management training is Article 20(2); staff cyber-hygiene training is Article 21(2)(g) — a different duty with different evidence, tracked in your LMS. Mixing the two is the most common way entities end up unable to show either cleanly.
- Auditors sample individuals, not averages. Supervisory practice converges on per-member records: who, what, when, how long, by whom, evidenced how, due when — plus the programme document and the board minutes showing the trained body approving the Article 21 measure set. The workbook's register computes each member's latest session and next due date and highlights gaps.
- The evidence reference is the record. A training certificate that cannot be produced on request does not exist, as far as an audit is concerned. Every completed log row carries a pointer to a stored artefact — certificate ID, signed attendance sheet, LMS export.
What's inside the workbook
| Sheet | What it holds | Why it matters |
|---|---|---|
| 1. Management Body Register | One row per member: name, role, governing body, appointment date, Article 20 scope flag with justification, status, computed latest-session and next-due columns | The list auditors sample against — including departed members, who stay on it |
| 2. Training Log | One row per member per session: title, provider and type, date, duration in hours, format, Article 20(2) objectives covered, renewal interval, computed next-due date, evidence reference, completion status | The per-individual record supervisors actually ask for |
| 3. Session Catalogue | The forward programme: planned sessions, audience, objectives, frequency, delivery method, provider, effectiveness measure | The training-programme document that sits alongside the records |
| 4. Jurisdiction Reference | EU baseline plus Germany, Latvia, Czechia, Belgium, Norway and the UK: instrument, rule, quantification, status | "Regularly" decided per country, on one sheet |
Overdue members highlight in red automatically, dropdowns keep the enums consistent, and worked example rows show a completed record set for a fictional management board. The machine-readable Markdown variant carries the full field definitions, enums and agent workflow rules — coverage, onboarding, evidence and objective-completeness health checks — so an AI agent can maintain the log and produce an audit extract from the file alone.
How to use it
- List the management body first. One row per member, including non-executives where your national transposition scopes them in — and record the justification either way. Departures flip to
departed; they never leave the register, because historical approvals are audited against historical membership. - Log sessions per member, not per event. A governance session attended by five directors is five rows, each with its own evidence reference. Record the hours — supervisors expect duration per record, not per programme.
- Map content to the three Article 20(2) objectives. Identify risks, assess risk-management practices, impact on services. Across a member's in-date sessions the union should cover all three — a tabletop alone is supplementary, not sufficient.
- Set the renewal interval from national law, not preference. 12 months where Latvia-style annual rules apply, 36 months as the German benchmark, and document the reasoning where your country leaves it open. The next-due date computes from the interval and turns red when it passes.
- Close the loop in the minutes. The training exists so the body can competently approve the Article 21 measures — so make sure the approval minutes name the attendees and the measure-set version. Pair this log with our Article 21 compliance checklist for the measure side.
Legal basis
- Directive (EU) 2022/2555 (NIS2), Article 20(1) — management bodies of essential and important entities must approve the cybersecurity risk-management measures taken to comply with Article 21, oversee their implementation, and can be held liable for the entity's infringements.
- Article 20(2) — members of the management bodies are required to follow training, and entities are encouraged to offer similar training to their employees on a regular basis, so that they gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided.
- Article 21(2)(g) — basic cyber-hygiene practices and cybersecurity training as a mandatory risk-management measure: the separate, staff-level duty this log deliberately does not track.
- § 38 BSIG (Germany, NIS2UmsuCG) — Abs. 1: approval and oversight; Abs. 2: personal liability of Geschäftsleiter for culpable breaches, recourse waivers ineffective; Abs. 3: the personal, regular training duty. In force 6 December 2025 (BGBl. 2025 I Nr. 301), no transition period.
UK and Norway/EEA
UK: the Cyber Security and Resilience Bill — in the House of Lords as of July 2026, Royal Assent expected late 2026 — strengthens regulator scrutiny of board-level cyber governance but contains no Article 20-style statutory training duty; expectations ride on the voluntary Cyber Governance Code of Practice. UK entities selling into or operating in the EU should evidence against NIS2 anyway. Norway: the Digital Security Act (digitalsikkerhetsloven, in force 1 October 2025) makes management responsible for the security level and requires it to approve the security management system with an annual review; management training is expected in line with NIS2, with Nasjonal sikkerhetsmyndighet (NSM) as the supervising authority — even though NIS2 itself is not yet incorporated into the EEA Agreement.
From training log to buyer-visible evidence
The same governance evidence a supervisor samples is what enterprise buyers increasingly ask for in security questionnaires — "does senior management receive cybersecurity training?" is a standard row. Orbiq publishes governance evidence — training attestations, policy approvals, management-review cadence — in a governed Trust Center, so the record you keep for the NIS2 audit answers the customer too. For the wider evidence stack, see our guides to NIS2 compliance and internal vs external proof.
Sources & References
- Directive (EU) 2022/2555 (NIS2) — full text — Articles 20(1), 20(2), 21(2)(g).
- Taylor Wessing — Germany's implementation of NIS2 — NIS2UmsuCG, § 38 BSIG duties and personal liability; in force 6 December 2025.
- Heise — NIS2: Mandatory cyber security training for management boards — the § 38 Abs. 3 analysis and the "every 3 years / ~4 hours" explanatory-materials benchmark.
- Transferstelle Cybersicherheit — NIS2-Schulungspflicht für Geschäftsleitungen — the German benchmark as a Richtwert, not a statutory minimum.
- Centre for Cybersecurity Belgium — NIS2 brochure — Belgian management-training expectations and planning guidance.
- Schjødt — Norway's Digital Security Act now in effect — management approval and annual review of the security management system.
- Wikborg Rein — Five things you need to know about the Digital Security Act — Norwegian management duties.
- UK Parliament — Cyber Security and Resilience Bill — bill status; no NIS2-style management-training provision.
Related Reading
- NIS2 Compliance: Requirements, Deadlines & Implementation
- NIS2 Audit Readiness: Continuous Evidence Over Annual Scrambles
- NIS2 Internal Proof vs External Proof
- Free Template: NIS2 Supplier Evidence Request Checklist — the Article 21(2)(d) supply-chain sibling
- Free Template: NIS2 Incident Reporting Pack — the Article 23 reporting forms
Download this template
Version 1.0 · Updated Jul 21, 2026 · Free, no email required
Frequently Asked Questions
Is cybersecurity training mandatory for management under NIS2?
Yes. Article 20(2) of the NIS2 Directive states that members of the management bodies of essential and important entities are required to follow training — the wording is an obligation, not a recommendation. The training must give them sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the entity's services. Offering similar training to employees is encouraged in Article 20(2), but the mandatory staff-training duty sits separately in Article 21(2)(g).
How often must NIS2 management training be repeated?
The directive itself sets no frequency — national transpositions do. Germany's § 38 Abs. 3 BSIG requires regular participation, with the legislative explanatory materials assuming roughly a half-day (~4 hours) at least every three years as the benchmark. Latvia requires management training with regular staff training whose content is reviewed at least annually — commonly implemented as annual training. Belgium requires regular training but leaves scope, format and duration to the entity's discretion. Apply the strictest rule covering your entity and document the interval you chose.
Who counts as the management body under NIS2?
The executive organ that approves the entity's cybersecurity risk-management measures — managing directors, the management board, and equivalents. Whether supervisory organs (non-executive boards) fall in scope varies by member state transposition, so record a per-member scope justification. In Germany the duty covers all persons appointed to manage and represent an in-scope entity, and it is personal and non-delegable — sending the CISO instead does not discharge it.
What evidence do auditors expect for Article 20 training?
Individual records, not dashboards: per management-body member, the session, provider, date, duration in hours, content mapped to the Article 20(2) objectives, completion evidence (certificate, signed attendance sheet or LMS export) and the next due date — alongside a training-programme document and board minutes showing the trained body approving the Article 21 measures. In practice that means keeping the agenda, date, trainer and signed attendance for every management session, per record.
Can management be held personally liable under NIS2?
Article 20(1) requires member states to ensure management bodies can be held liable for the entity's infringements of Article 21. Germany goes furthest: § 38 Abs. 2 BSIG attaches personal civil liability for culpable breaches of the approval, oversight and training duties, assessed under the general corporate-law standards (§ 43 GmbHG, § 93 AktG), and a waiver of the company's recourse claims is legally ineffective.
Is employee cybersecurity training mandatory under NIS2?
Yes, but under a different article. Article 20(2) only encourages entities to offer management-style training to employees; Article 21(2)(g) makes basic cyber-hygiene practices and cybersecurity training a mandatory risk-management measure. Track staff training in your LMS or ISMS — this log deliberately covers only the governance-level Article 20(2) record.
Does the management training duty apply in the UK and Norway?
Norway: yes in substance — the Digital Security Act (digitalsikkerhetsloven, in force 1 October 2025) makes management responsible for the security level, requires it to approve the security management system with an annual review, and management training is expected in line with NIS2, even though the directive is not yet incorporated into the EEA Agreement. UK: no — the Cyber Security and Resilience Bill contains no NIS2-style statutory training duty; board expectations ride on regulator scrutiny and the voluntary Cyber Governance Code of Practice.