NIS2 Training Audit Checklist: 22 Controls — and the 5 That Fail Most Audits
Most NIS2 training guidance stops at “train your staff and keep records.” That’s not what a competent-authority auditor actually tests. Article 20 and Article 21(2)(g) create two separate, differently-evidenced obligations — one for the management body, one for the workforce — and auditors check them with different working papers. This checklist breaks both into 22 named controls, grouped the way an auditor groups them, plus the 5 controls that fail first-cycle audits most often.
Every control below traces to Article 20 or Article 21(2)(g) of Directive (EU) 2022/2555, the corresponding technical detail in Commission Implementing Regulation (CIR) 2024/2690, or documented audit-evidence patterns from a national competent authority. Use it as a working paper, not a reading list.
Who This Checklist Applies To (and Who’s Exempt)
Short version: if your organisation is in scope for NIS2 as an essential or important entity, both Article 20 (management training) and Article 21(2)(g) (staff training) apply — there’s no size or sector carve-out for the training obligation specifically, only for NIS2 scope itself.
| Question | If yes |
|---|---|
| Is your organisation classified as an essential or important entity under NIS2 (by sector and size threshold)? | Article 20 + Article 21(2)(g) both apply — no exemption for smaller “important” entities |
| Do you have a management body (board, executive committee, or equivalent governance layer)? | Article 20(2) training duty applies to every member personally, not just the appointed NIS2/security officer |
| Do any staff, contractors, or third parties have access to your network and information systems? | They fall inside the Article 21(2)(g) / CIR Annex Section 8 awareness-programme scope, or their exclusion needs a documented risk decision (Control 14) |
If you’re still working out whether your organisation is in scope at all, that’s a separate, prior question — see our NIS2 compliance checklist before applying the controls below.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The Legal Basis: Article 20 vs Article 21(2)(g) — and Why Auditors Treat Them as Two Checks
Article 20 is a governance obligation. It requires management bodies of essential and important entities to approve the cybersecurity risk-management measures taken by the entity and to oversee their implementation — and it makes members personally liable for violations of that duty [1]. As part of that duty, management body members must receive training, and entities are encouraged to extend regular cybersecurity training to employees generally, so they “gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices” [1].
Article 21(2)(g) sits inside a different list entirely: the ten mandatory cybersecurity risk-management measures every essential and important entity must implement under Article 21(2). Point (g) requires “basic cyber hygiene practices and cybersecurity training” [2] — a workforce-facing control, proportionate to the entity’s risk exposure, size, and cost of implementation.
Commission Implementing Regulation (CIR) 2024/2690 adds the technical layer beneath Article 21(2)(g). Its Annex splits the obligation across two of its thirteen thematic sections: Section 8 covers basic cyber hygiene practices and a security awareness programme for all personnel, with role-specific training for staff who have security tasks and for management, and Section 10 covers human-resources security across the employment lifecycle [3]. ENISA’s Technical Implementation Guidance, published to mirror the CIR Annex, adds a further layer for each of those sections: practical guidance, examples of evidence, and mappings to recognised standards [4] — which is the same evidence-first logic this checklist follows.
That’s why an auditor working through a training review pulls two separate files: a governance file for Article 20 (minutes, personal management-body training records) and a workforce file for Article 21(2)(g) (programme design, completion logs, phishing results). Blending the two into one “training folder” is itself one of the five failure patterns below.
The 22-Control NIS2 Training Audit Checklist
Twenty-two controls, grouped the way an auditor works through them: management governance first, workforce delivery second, evidence and audit-readiness third.
For the full governance picture beyond training alone, see our board training requirements guide.
Group A — Management Training Controls (Article 20)
| # | Control | Evidence auditors want |
|---|---|---|
| 1 | A management-body training programme exists and is documented | Written programme description, not a verbal policy |
| 2 | Every management-body member has a personal, named training record | Individual completion records — not one line for “the board” |
| 3 | Training content covers risk identification and assessment of risk-management practices, per Article 20(2) wording | Course syllabus or agenda mapped to that specific language |
| 4 | Approval of the cybersecurity risk-management measures is minuted and signed by the management body | Board minutes or a signed resolution referencing Article 20(1) |
| 5 | Management training is refreshed at least annually, with a logged review date | Dated re-training record, not just the original induction date |
| 6 | New management-body members complete training promptly after appointment, with the gap tracked | Appointment date vs. training-completion date, both logged |
For programme design beyond the audit checklist itself, see our full NIS2 training requirements guide.
Group B — Staff Cyber Hygiene & Awareness Controls (Article 21(2)(g))
| # | Control | Evidence auditors want |
|---|---|---|
| 7 | A documented, role-based training programme covers all staff — not IT alone | Programme document naming the roles/departments in scope |
| 8 | General awareness content covers phishing, password hygiene, safe use of email/removable media, and incident reporting | Course content outline or LMS module list |
| 9 | Role-specific technical training exists for staff with security tasks, beyond the general programme | Separate curriculum for security/IT roles (CIR Annex Section 8 requirement) |
| 10 | New joiners complete baseline security training within a defined window of their start date | Start-date-to-completion tracking per new hire |
| 11 | Phishing simulations run on a recurring schedule, not a single annual test | Simulation calendar and run history |
| 12 | Phishing results are logged as report rate, click/failure rate, and mean-time-to-report, trended over time | Trend dashboard, not one snapshot metric |
| 13 | Staff training is refreshed at least annually with content updated for current threats | Version history showing content updates, not a static deck reused for years |
| 14 | Contractors and third parties with system access are inside the awareness programme, or their exclusion is a documented risk decision | Contractor training log, or a signed risk-acceptance note |
| 15 | Assessment or quiz results exist, proving comprehension rather than attendance alone | Pass/fail scores per module, per person |
| 16 | Awareness content is mapped to the specific Article 21(2) measures it supports | A short cross-reference table linking training modules to measures (e.g., phishing module → incident handling) |
Group C — Evidence & Audit-Readiness Controls
| # | Control | Evidence auditors want |
|---|---|---|
| 17 | Training records are timestamped and exportable, showing who, what module, and when | A single exportable log, not records scattered across inboxes and spreadsheets |
| 18 | Management training records are segregated from general staff records | Two distinct evidence sets, not one blended “training folder” |
| 19 | Training documentation is retained long enough to survive a retrospective audit | A defined retention period, applied consistently |
| 20 | Records show a trend or improvement, not just a point-in-time completion percentage | Multi-period comparison, not a single “100% complete” snapshot |
| 21 | A named owner is accountable for maintaining and producing the training evidence file | Role assignment documented (see the responsibility map below) |
| 22 | The training record set is cross-referenced in the internal audit checklist before an external auditor asks for it | Internal audit working papers that already reference the training evidence file |
The 5 Controls That Fail Audits Most
Not all 22 controls carry equal audit risk. Based on documented audit-evidence patterns, these five are where organisations most often have a training programme in place but no evidence that survives review.
1. Management training records blended into the general staff log (Controls 2 & 18)
Current state: One shared training spreadsheet lists everyone, board members included, alongside general staff. Required state: A segregated, personal record for each management-body member. Documented in Kymatio’s NIS2 audit evidence guide, organisations “often fail to segregate leadership training from general awareness programmes” [6] — auditors treat this as a governance gap, not a formatting issue, because Article 20 places the training duty on management personally. Fix effort: Low — split one log into two and start dating management sessions separately.
2. Phishing results reported as a single click-rate number (Control 12)
Current state: A once-a-year phishing test with a headline click-rate percentage. Required state: Report rate, mean-time-to-report, and click-rate trended across multiple simulations — a high report rate is a stronger signal of an active defence than a low click rate alone [6]. Fix effort: Medium — requires a recurring simulation schedule and a simple trend log, not new tooling in most cases.
3. Annual refresh evidence missing (Controls 5 & 13)
Current state: Training happened once, typically at rollout, with no logged repeat. Required state: A dated annual review, in line with the national competent authority guidance to supplement onboarding training with “annual updates on current developments” [5]. Fix effort: Low to Medium — the content usually exists; what’s missing is a second dated delivery record.
4. New-joiner training window undocumented (Control 10)
Current state: New hires eventually complete security training, but nothing tracks the gap between their start date and completion. Required state: A logged start-date-to-completion window for every new hire, so an auditor can see the policy was actually applied, not just written. Fix effort: Low — usually an HR onboarding checklist update, not a new programme.
5. Completion-only reporting (Controls 15 & 20)
Current state: A 100% completion rate is presented as proof the training worked. Required state: Assessment or competency evidence alongside completion, and a trend showing behavioural change over time — documented audit findings note that a 100% completion rate alone is no longer accepted as sufficient compliance evidence [6]. Fix effort: Medium — add a short quiz or scored module to existing training rather than rebuilding the programme.
Who Owns Each Control: A Role-Responsibility Map
The same 22 controls land differently depending on who’s reading this. A compliance officer preparing for an audit needs a different working paper than a CISO building the phishing programme, and both need something different from what the board needs to see.
| Role | Owns | Primary controls |
|---|---|---|
| Management body / Board | Approving risk-management measures; completing personal training; signing off the training policy | 1–6 |
| CISO / IT Security Manager | Designing role-based content, running phishing simulations, technical training for security staff | 7, 9, 11, 12, 16 |
| HR | New-joiner onboarding windows, contractor inclusion, employment-lifecycle records (CIR Annex Section 10) | 10, 14 |
| Compliance Officer / NIS2 Coordinator | Evidence file structure, retention, segregation, cross-referencing to the internal audit checklist | 17–22 |
For SME owners running all four roles at once, the practical order is: fix the record segregation first (it’s free), then close the new-joiner tracking gap, then build the phishing trend log — in that order, matched to the fix-effort ratings above.
Building an Evidence File Auditors Won’t Reject
Documentation isn’t a nice-to-have layered on top of training — under national competent authority guidance, it’s presented as a condition of meeting the requirement in the first place, not a separate administrative step [5]. Three practical rules follow from that framing and from the failure patterns above.
Keep it exportable, not distributed. An auditor asking “show me who completed phishing training in the last two quarters” needs a single export, not a request to check three different systems. If your LMS, HR system, and phishing tool don’t share a common export format, build the cross-reference log manually rather than skip it.
Retain longer than feels necessary. Audits and inspections by a competent authority can review historical records retrospectively, not just the current year [5] — a training log you deleted after twelve months can’t help you in a review that looks back further than that.
Dashboard it, don’t dump it. Raw, uncontextualised logs handed to leadership or an auditor read as an unprocessed data dump rather than evidence of an active programme [6]. A one-page summary — completion trend, phishing trend, outstanding gaps — sitting on top of the raw logs turns the same data into something an auditor (or your own board) can actually use.
If you’re building this evidence file from scratch, our internal auditor’s guide and audit preparation checklist walk through the wider working-paper set this training file sits inside.
FAQ
Does Article 20 training apply to every member of the management body, or just the security lead?
Every member. Article 20 places the approval and training duty on the management body as a whole, and Germany’s national implementation is explicit that this is a personal, non-delegable duty for each member — not something one appointed officer can complete on the board’s behalf [5].
Note: national implementing laws vary; the personal-duty framing described here reflects Germany’s transposition and is a documented pattern, not a guarantee of identical wording in every member state.
How often does NIS2 require training to be refreshed?
The Directive itself doesn’t set a fixed interval — Article 21(2)(g) requires the measure to be proportionate to risk, size, and cost [2]. In practice, annual refresh plus event-driven updates (a major incident, a new threat pattern) has become the working standard cited by national competent authority guidance [5].
Do phishing simulation results actually get checked in an audit?
Documented audit-evidence patterns treat phishing metrics as a core Article 21(2)(g) evidence type — specifically the trend in report rate, click rate, and time-to-report, not just whether a test was run [6]. Treat it as an audited control, not an optional extra.
What’s the single fastest control to fix if we’re behind?
Segregating management training records from general staff records (Control 18). It requires no new programme or tooling — splitting one spreadsheet into two — and it directly addresses the most commonly cited audit gap [6].
Legal Disclaimer
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS2 Directive (EU) 2022/2555 — Article 20 (Governance)
- NIS2 Directive (EU) 2022/2555 — Article 21 (Cybersecurity risk-management measures)
- Commission Implementing Regulation (EU) 2024/2690 — Annex, Section 8 (Basic cyber hygiene practices and security training) and Section 10 (Human resources security)
- ENISA — NIS2 Technical Implementation Guidance (June 2025)
- BSI (Bundesamt für Sicherheit in der Informationstechnik) — NIS-2 Schulungen und Sensibilisierungsmaßnahmen, official German national competent authority guidance
- Kymatio — NIS2 Audit Evidence Guide: Logs, Training Records & KPIs
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
