< Back to all clusters
[TECHNOLOGY] · Germany · 2 sources

Germany enforces NIS-2 cybersecurity training for firms

The EU’s NIS‑2 directive has been transposed into German law as the NIS‑2 Umsetzungsgesetz, effective 6 December 2025. It applies to companies in critical and important sectors such as energy, transport, health, digital infrastructure, machinery and chemicals.

The legislation makes two specific obligations compulsory: regular cybersecurity awareness training for all employees and a dedicated training programme for senior management. The original German implementation deadline of October 2024 was postponed because of a coalition crisis, and further compliance steps are expected throughout 2026.

G DATA and secova offer a practical response through the G DATA Security Awareness Training integrated into the secova sam® platform. The training covers risk‑management fundamentals, incident response, technical and organisational measures and regulatory oversight. Dr. Matthias Zuchowski, Regulatorik Experte at G DATA CyberDefense, explains: “Die Geschäftsleitung übernimmt unter NIS‑2 die Rolle eines Steuerungsgremiums für Cyberrisiken. Ohne grundlegendes Verständnis lässt sich diese Rolle aber kaum ausfüllen.” The solution enables companies to deliver, document and verify the required training for staff and executives.