← All posts
GuideAugust 25, 2026 · 7 min read

NIS2 and Human Risk: What the Directive Requires

NIS2 makes management liable for cybersecurity training and gives you 24 hours to report incidents. What Articles 20, 21 and 23 mean for the human layer.

EU stars beside a NIS2 enforcement timeline card on a navy NOUSEC-branded background

The NIS2 Directive spent its first two years as a compliance abstraction — a deadline that kept slipping as member states argued over transposition. That phase is over. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the directive, asking the Court for a lump sum plus daily penalties until each state's law is in force. Roughly two-thirds of member states have now transposed, national regulators are registering entities and opening supervision, and the remaining laggards are being dragged across the line by litigation.

For security teams, NIS2 is worth reading closely for a reason that has nothing to do with deadlines: it is the first EU-wide security law that names the human layer explicitly. Where the GDPR forces regulators to read training into "appropriate organisational measures", NIS2 writes cybersecurity training into the text — twice — and attaches personal accountability for it to the management body. Given that the Verizon DBIR still attributes 62% of breaches to the human element and ENISA's Threat Landscape 2025 found phishing to be the initial intrusion vector in 60% of analysed EU incidents, that emphasis is not decorative. This guide maps where the human-risk obligations sit in the directive, what enforcement looks like in 2026, and how to build a program that satisfies both the letter and the intent.

Where the human layer sits in the directive text

Three provisions do most of the work, and they are worth quoting precisely, because each one lands on a different part of the organization.

Provision What it says What it means for your program
Art. 20(1) Management bodies must approve cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements Security is board business by statute — sign-off and oversight must be documented
Art. 20(2) Members of management bodies are required to follow training, and entities are encouraged to offer similar training to their employees on a regular basis Board-level training is mandatory; workforce training is the stated expectation
Art. 21(2)(g) Minimum risk-management measures include "basic cyber hygiene practices and cybersecurity training" A training program is a baseline control, like backups or access management — its absence is a compliance gap
Art. 23(4) Significant incidents: early warning within 24 hours, incident notification within 72 hours, final report within one month The clock starts when the entity becomes aware — employee reporting speed determines whether the deadline is survivable
Art. 34 Fines up to €10M or 2% of worldwide turnover (essential), €7M or 1.4% (important) The ceiling sits in GDPR territory — and applies to security failures, training included
Recital 89 Cyber hygiene means "zero-trust principles, software updates, device configuration…" and user awareness Hygiene is framed as a shared practice across the workforce, not an IT-only duty

Two structural points follow. First, NIS2 splits the training obligation by audience. For the management body, training is not optional — Article 20(2) makes following it a requirement, and the same people are personally on the hook under Article 20(1) for the measures they approve. For everyone else, the directive's "encourage" phrasing is softer, but Article 21(2)(g) closes the loop: cybersecurity training is on the list of minimum measures the entity must implement, alongside incident handling and supply-chain security. An entity that trains nobody below board level has an Article 21 problem regardless of how the encouragement clause is read.

Second, the reporting regime quietly turns employee behavior into a legal deadline. NIS2's early-warning window is 24 hours — tighter than the GDPR's 72 — and it runs from awareness of a significant incident. Most social-engineering incidents become known because an employee says something. If your workforce's median time-to-report on simulated attacks is measured in days, your 24-hour clock is broken before the incident starts.

The GDPR made regulators read training between the lines. NIS2 stops the guessing: it names cybersecurity training in the text, prices failure at up to 2% of turnover — and makes the management body personally accountable for it.

The enforcement picture in mid-2026

The Commission's infringement track has moved in three steps: letters of formal notice in November 2024, reasoned opinions to 19 member states in May 2025, and the July 2026 referral of the last four holdouts to the Court of Justice. The direction is one-way, and companies in late states get the least preparation time: the Netherlands approved its implementing law the day before the referral was announced, with entry into force barely a month later.

Supervision is also getting more specific about sectors. ENISA's NIS360 report assesses maturity across the NIS2 sectors and places electricity, telecoms and banking at the top — while flagging health, public administration, maritime, gas, space and ICT service management as sectors where maturity lags criticality, citing among other things talent shortages and upskilling gaps. If you operate in one of those six, assume your national authority has read the same report.

The teeth are real on paper even where enforcement is young. Beyond the Article 34 fine ceilings, essential entities face escalating supervisory measures up to a temporary prohibition on individuals exercising managerial functions — the kind of sanction that concentrates board attention in a way no security budget line ever has.

Building a NIS2-ready human risk program

The directive tells you what must exist; it does not tell you how to run it well. The steps below map the legal text onto an operating program.

1. Establish scope and classification first

Confirm whether you are an essential or important entity, in which member state(s), and under which national law — transpositions differ in registration duties, deadlines and sector detail. If you are a supplier to in-scope entities rather than in scope yourself, expect the obligations to arrive contractually through your customers' Article 21(2)(d) supply-chain assessments.

2. Put the management body through documented training — first

Article 20(2) makes this the one unambiguous training mandate, so treat it as the program's opening move, not an afterthought. Use a format that lets directors genuinely "identify risks and assess cybersecurity risk-management practices" — a tabletop exercise built on real attack scenarios does this far better than a slide deck, and produces documentation of both attendance and engagement.

3. Make workforce training a standing minimum measure

Satisfy Article 21(2)(g) the way you would any other baseline control: onboarding training before access, a regular cadence afterwards, and role-based depth for the groups attackers actually target — finance, IT admins, help desk, executive assistants. Pair it with the cyber-hygiene basics Recital 89 lists, from patching discipline to password-manager adoption. Our security awareness training platform automates the cadence and the record-keeping.

4. Engineer the 24-hour reflex

Map the internal chain from "employee notices something" to "entity submits early warning" and remove every step that adds hours. That means a one-click report channel, a no-blame policy stated in writing, and an on-call path that works at 2 a.m. on a Saturday. Then measure it: phishing simulations give you a hard number for median time-to-report, which is the leading indicator for whether Article 23's clock is realistic.

5. Measure and document like a defendant

Article 20(1) liability plus supervisory audits mean the program must be provable, not just present. Track completion, simulated-attack outcomes, reporting speed and risk trends per team, and roll them into a metric leadership can own — a human risk score gives the management body exactly the oversight instrument Article 20 assumes they have.

6. Do not wait for your national law

Every obligation above is knowable today from the directive text, and the enforcement history shows late states legislate with short runways. Financial-sector firms should also note the direction of travel: DORA, already applicable since January 2025, makes ICT security awareness programmes compulsory modules in staff training for all employees and senior management — the strictest version yet of the same idea. Regulators are converging on the view that a trained workforce is infrastructure.

The bottom line

NIS2 does for the human layer what earlier EU law did for data protection: it converts good practice into legal baseline. The organizations that will clear supervision comfortably are the ones that treat Articles 20, 21 and 23 not as three compliance line-items but as one system — leadership that understands the risk, a workforce trained and measured against real attack techniques, and a reporting reflex fast enough to beat a 24-hour clock. Everything in that system is buildable now, before your national regulator asks to see it.

Frequently asked questions

Does NIS2 make security awareness training mandatory?

For management bodies, yes: Article 20(2) requires members of the management body to follow cybersecurity training. For the wider workforce, the same article says entities should be encouraged to offer similar training regularly — but Article 21(2)(g) separately lists 'basic cyber hygiene practices and cybersecurity training' among the minimum risk-management measures every in-scope entity must implement. In practice, an entity with no employee training program cannot show it has met its Article 21 obligations, and several national transpositions state the requirement even more directly.

Who falls under NIS2?

Essential and important entities across 18 sectors — including energy, transport, health, digital infrastructure, ICT service management, public administration, manufacturing of critical products, and postal services. As a rule of thumb the directive captures organizations in those sectors with 50 or more employees or over €10 million in annual turnover, with some entities (such as certain digital infrastructure providers) covered regardless of size. Smaller suppliers are also pulled in indirectly: Article 21(2)(d) makes supply-chain security a minimum measure, so in-scope customers must assess the security of their vendors.

What are the penalties for non-compliance with NIS2?

Essential entities face administrative fines of up to €10 million or 2% of worldwide annual turnover, whichever is higher; important entities up to €7 million or 1.4%. Beyond fines, Article 20(1) provides that management bodies can be held liable for infringements, and for essential entities supervisory authorities can go further — including requesting a temporary prohibition on individuals exercising managerial functions at CEO or legal-representative level until deficiencies are remedied.

My country has not fully transposed NIS2 yet. Should we wait?

No. By mid-2026 roughly two-thirds of member states had transposed the directive, and in July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice over the delay, requesting lump-sum and daily penalties. Late-transposing states tend to enact the rules with little additional runway for companies, and the core obligations — management training, workforce training, 24-hour reporting — are already knowable from the directive text. Building the program now is cheaper than retrofitting it under a national deadline.

See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo