NOUSEC is used by public bodies that must demonstrate a cyber-hygiene and training programme rather than merely run one. Under NIS2, central-government entities are in scope regardless of size, and Article 21(2)(g) makes cyber hygiene and cybersecurity training a minimum mandatory measure — while Article 34(7) leaves it to each member state to decide whether fines apply to public bodies at all. NOUSEC produces the artefacts an inspection asks for: policy acknowledgement with version tracking, a compliance scorecard showing raw and audit-adjusted completion, certificates with a public verification page, an audit log, and SIEM export in CSV, NDJSON or JSON — with no endpoint agents and data resident in Frankfurt.
The most targeted sector in the Union.
In this sector the fine is optional. The inspection is not.
Most vendors sell public bodies a penalty they may never face. Here is the accurate position, and the artefact list that actually matters.
NIS2 puts central-government public administration entities in scope regardless of size, and lets member states extend it to regional and local bodies. But the enforcement chapter is not symmetrical: the temporary ban on managerial functions under Article 32(5) applies to essential entities and expressly not to public administration, and under Article 34(7) each member state decides whether and to what extent administrative fines apply to public bodies at all.[3]
So the pressure on a public-sector security team is evidentiary rather than financial. You will be asked to show that a programme exists, that people completed it, that the record is defensible, and that it can be handed to an auditor without a spreadsheet reconciliation exercise.
That is a product problem, and it is the one we built for.
| Artefact | What it proves | How it is checkable | Tier |
|---|---|---|---|
| Policy acknowledgement with version tracking | Who accepted which version, when | Per-user record, exportable | Professional |
| Compliance scorecard — raw and audit-adjusted | Completion, and completion that survives a quality threshold | Both figures shown; the discount is triggered by a quiz score below 40% | Essentials |
| Completion evidence | Training taken, not training assigned | ≥ 90% unique-second watch coverage, computed server-side; a forged completion returns 403 | Essentials |
| Certificate with public verification page | The certificate is genuine | A third party can verify it without access to your tenant | Professional |
| Audit log | Who changed what in the programme | Immutable record | Enterprise |
| SIEM export | The record leaves the platform | CSV, NDJSON or JSON | Enterprise |
Nearly half the actors are already inside.
This is the finding that makes the public-sector page different, and it is also where we have to be careful about what we sell.
In Public Administration the DBIR records internal actors in 44% of breaches and Privilege Misuse as a top-three pattern — the only sector of the four where that is true. Espionage is the motive in a third of cases.[1]
Some of that is malice and some is error, and a security awareness platform is honest about which half it can touch. NOUSEC does not do user behaviour analytics, data loss prevention or insider-threat detection, and the components that would imply otherwise are not shipped. What it does is train and measure the behaviours that sit upstream of both: handling of sensitive records, policy acknowledgement, credential hygiene, and a reporting culture where flagging something raises your Human Risk Score rather than exposing you.
Reporting is subtractive by design. An employee who reports a suspicious message improves their own score. Exposure from a third-party breach is counted as exposure, not blame — a user in a 2017 credential dump did not choose to be there.
Scope, liability, and what an inspection asks for.
| Instrument | Article | What it requires | How NOUSEC evidences it |
|---|---|---|---|
| NIS2[3] | Art. 2(2)(f)(i) | Central-government public administration entities are in scope regardless of size. | — |
| NIS2 | Art. 2(2)(f)(ii), 2(5) | Regional entities in scope following a risk-based assessment; local bodies and education institutions at member-state discretion. | — |
| NIS2 | Art. 21(2)(g) | Cyber hygiene and cybersecurity training as a minimum mandatory measure. | Server-side completion gate; audit-adjusted scorecard. |
| NIS2 | Art. 20(1), 32(5), 34(7) | Management bodies approve, oversee and can be held liable — but the managerial ban does not reach public administration, and fines are at member-state discretion. | Board cohort evidence; audit log. |
| GDPR | Art. 39(1)(b) | Awareness-raising and training in the DPO's monitoring remit. | Policy acknowledgement with version tracking. |
| ISO/IEC 27001:2022[5] | Cl. 7.2 / 7.3, A 6.3 | Competence, awareness, training. | Certificate public verification page. |
Regulatory summaries are for orientation, not legal advice. Scope and classification depend on your member state's transposition.
The four questions a tender always asks.
No endpoint agents
Nothing is installed on any device. The report button is an optional mail-client add-in.
EU data residency
Frankfurt, with tenant-level export and erasure.
Full white-label
Your branding, in 30 languages — nine fully localised today, twenty-one more on request.
Published methodology
The 0–100 score shows its component breakdown. No black box.
Evidence that is not self-reported
A score that shows its working
Related reading: the Human Risk Score methodology, why NOUSEC, and the glossary entries for insider threat and pretexting. If your authority also runs plant or grid infrastructure, the same evidence chain has to satisfy two different NIS2 annexes at once. Our own posture is on Trust and Security.
Questions
What a public-body security team and its procurement office ask first.
Every figure on this page, and where it came from
Last reviewed: 11 August 2026. Regulatory citations are checked against the consolidated text at EUR-Lex on each review.
- 2026 Data Breach Investigations ReportVerizon Business — industry section, p. 84 for Financial and Insurance (NAICS 52). Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025 · 2026Used for: Public Administration (92) — 3,634 incidents; 69% human element; 44% internal actors; 33% espionage motive; 20% phishing against 40% vulnerability exploitation; Privilege Misuse in the top three patterns.
- Threat Landscape 2025ENISA — 13th edition, v1.2, 4,875 incidents, 1 Jul 2024 – 30 Jun 2025 · 2025Used for: 38.2% of identified EU incidents targeting public administration. 4,875 incidents, 1 Jul 2024 – 30 Jun 2025.
- Directive (EU) 2022/2555 (NIS2)Official Journal of the European Union, OJ L 333, 27.12.2022 · 2022Used for: Articles 2(2)(f), 2(5), 20(1), 21(2)(g), 32(5) and 34(7).
- ISO/IEC 27001:2022 and ISO/IEC 27002:2022International Organization for Standardization — 3rd edition · 2022Used for: Clauses 7.2 and 7.3; the title of Annex A control 6.3.