Abstract illustration of a connected network of employees linked to a central security shield, representing NIS2 cybersecurity training

NIS2 Training Cost: €0 to €25,000 Compared (Free vs. LMS vs. Custom Programmes)

Article 21(2)(g) of the NIS2 Directive requires “basic cyber hygiene practices and cybersecurity training” as one of ten minimum security measures. Article 20(2) separately requires management-body members to be trained. Neither provision specifies a curriculum, a delivery method, or a budget — that’s a design decision the entity makes itself, and the cost swings from €0 to well over €25,000 depending on which tier you pick.

This isn’t another article restating that training is mandatory. It’s a cost comparison: what free materials actually cover, what LMS platforms charge per employee, what a custom programme costs to build, what phishing simulation adds on top, and what board-level training runs — with real vendor and consultant figures, not vague ranges.

Who Must Provide NIS2 Training — and Who Approves the Budget

The training obligation applies to every essential and important entity in scope of NIS2, regardless of size, but who signs off on the spend differs by role. If you’re not sure your organisation is in scope at all, check our NIS2 scope test before budgeting anything.

Role What they need from a training budget Typical decision
Compliance officer Auditable proof of completion, dated and role-mapped Picks the platform or the paperwork template
SME owner (non-technical) Lowest cost that still satisfies Article 21(2)(g) Often starts at the free tier
CISO / IT security manager Content depth matching real attack patterns (phishing, credential theft) Pushes toward LMS or custom tier
Board / management body Personal, non-delegable training under Article 20(2) Approves a separate, smaller line item

What Article 21(2)(g) and Article 20(2) Actually Require You to Pay For

Article 21(1) says measures must be “appropriate and proportionate,” taking into account “the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity” — and the directive’s proportionality language explicitly factors in the cost of implementation. In plain terms: a 12-person managed service provider and a 4,000-person energy operator are not expected to spend the same amount on training, and no auditor should expect otherwise.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

What the directive does not do is prescribe a curriculum, a vendor, or a minimum spend. Article 21(2)(g) lists “basic cyber hygiene practices and cybersecurity training” as one of ten required measures, without specifying format. That silence is precisely why prices in this market range across three orders of magnitude — from a free ENISA download to a five-figure custom build — and why what content the training must cover matters more than what it costs.

Cost Tier 1 — Free: ENISA and National-Authority Materials

Start here regardless of budget, because it costs nothing and sets the content floor. ENISA publishes a free NIS2 awareness package — infographics covering scope, the ten risk-management measures, and incident-reporting obligations, bundled as a single downloadable ZIP, no registration required.

Several national competent authorities go further. Germany’s BSI, for example, publishes a free guidance document (a “Handreichung”) specifically on the management-body training obligation under national implementing law, covering who must train, how often, and what format options work — explicitly usable by both training providers and management bodies as a reference, even though following it isn’t itself a legal requirement. Check whether your own national competent authority publishes an equivalent before paying for anything.

The catch: free materials are content, not infrastructure. Nothing tracks who opened the file, when, or whether they understood it. For a five-person entity that can log completion in a spreadsheet, that’s a non-issue. For anything larger, the missing tracking layer is exactly what pushes budget into Tier 2.

Cost Tier 2 — LMS-Based Awareness Platforms (€500–€5,000/year)

This is where most mid-sized entities land, because per-employee LMS pricing buys the thing free materials can’t: automated assignment, completion tracking, and a timestamped report you can hand an auditor. Market pricing for 2026 clusters into three bands, and the spread is wide enough that shopping around matters.

Vendor tier Typical price Commitment
Modern SaaS ~$0.60–$2.00 per employee/month Monthly, flexible
Legacy enterprise ~$1.30–$4.00 per employee/month Annual or multi-year
Specialist / boutique ~$3.00–$6.00 per employee/month Usually annual

Volume discounts are steep and worth negotiating: organisations over 100 employees typically see roughly 40% off list price, rising toward 60–70% past 500–1,000 seats. Paying annually instead of monthly commonly saves another 20–60% on top of that. For a 50-person important entity, that puts a realistic annual bill somewhere between €600 and €3,600 — comfortably inside the €500–5,000 range this tier is known for once discounts are applied.

What you’re actually buying at this tier isn’t the training content itself — most vendors license similar baseline modules — it’s the audit trail. If your compliance officer’s real problem is proving completion rather than sourcing content, this tier solves it more cheaply than building anything custom.

Cost Tier 3 — Custom-Built Programmes (€5,000–€25,000+)

Custom makes sense when generic modules don’t match your risk profile — sector-specific attack scenarios, a workforce split across languages, or a board that wants training tied directly to your actual incident-response plan rather than a stock example.

Independent information-security consultants typically bill €800–€2,500 per day in the EU market. A focused training-programme build — content design, role-based tracks, one delivery round — usually falls in the low-to-mid five figures once you include instructional design and a facilitated pilot session, which is consistent with the €5,000–€25,000 range this tier commands. Larger or multi-language builds, or programmes bundled into a wider ISMS engagement, can run past that ceiling; smaller entities with a narrow scope can land near the bottom of it.

The honest trade-off: a custom programme costs roughly 5–10x an LMS subscription for a single year, but it’s a one-time-ish build you refresh rather than a recurring per-seat bill. For an entity of 200+ employees on a multi-year horizon, the economics can actually favour custom over LMS once you run the numbers past year two or three.

Phishing Simulation Platforms: A Separate Line Item

Phishing simulation is not explicitly named in Article 21(2)(g) — the text says “cybersecurity training,” not “simulated phishing campaigns” — but it’s become the de facto evidence most auditors and consultants expect alongside training, because phishing remains the most common initial access vector in real incidents. Budget for it separately; some LMS vendors bundle it, many don’t.

Dedicated phishing-simulation pricing runs roughly $12–$36 per user per year for self-service platforms, with entry-level tools starting near $1 per user per month and enterprise contracts often carrying a minimum annual spend (commonly around $1,500 regardless of headcount). Fully managed simulation services — someone else designs and runs the campaigns — start around $1,500–$5,000 for a small programme and can reach $15,000+ a year for larger, more frequent campaigns with detailed reporting.

A practical rule of thumb: if your LMS quote doesn’t mention phishing simulation by name, assume it’s not included and price it separately before you commit to an annual contract.

Management and Board-Level Training Cost (Article 20(2))

Article 20(2) is stricter than Article 21(2)(g) in one specific way: it requires management-body members personally to be trained, not just “the organisation” generically. German compliance-law commentary on the national implementing act describes this training duty as personal and non-delegable to a deputy, even though the operational cybersecurity work itself can be delegated.

Board and executive training is typically bought differently from staff awareness training, and the pricing reflects that:

Delivery format Typical cost Best fit
External seminar (per person) ~€500–€1,500 1–3 board members, standard content acceptable
In-house workshop (per session) ~€2,000–€5,000 Full board/management team, content tailored to your sector
vCISO-led / fractional-executive briefing Folded into a €2,000–€9,000/month retainer Entities already paying for fractional CISO support

One area where sources genuinely disagree: cadence. The directive itself only says training must happen, without a fixed interval. Compliance advisers interpreting Germany’s BSI guidance aren’t unanimous either — some describe an annual expectation, others read the underlying guidance as a three-year minimum. Where your own national competent authority hasn’t published a specific number, treat “at least annually” as the safer default rather than waiting for the regulatory floor. See our dedicated board training requirements guide for the full breakdown by obligation.

A recurring theme across every BSI-adjacent commentary we reviewed: training that only covers “measures” — the technical controls — doesn’t satisfy the requirement on its own. Boards are expected to understand risk identification and impact assessment too, not just tick a compliance box. A €500 generic webinar that skips those two areas is cheap and non-compliant at the same time.

Is It Worth It? ROI Against the Penalty Exposure

Training spend at any tier — even the €25,000 custom-programme ceiling — is a rounding error against NIS2’s maximum penalties: up to €10 million or 2% of global annual turnover for essential entities, up to €7 million or 1.4% for important entities, whichever is higher. That comparison alone doesn’t prove ROI, though, because untrained staff don’t directly cause fines — incidents and documentation gaps do, and training reduces the likelihood of both.

The more defensible ROI argument is evidentiary, not actuarial: when a competent authority investigates after an incident, a dated training register showing who was trained, on what, and when is one of the concrete artefacts examiners look for to assess whether “appropriate measures” were genuinely in place. No template or training log guarantees a favourable outcome, but their absence is a documented, recurring finding in early NIS2 enforcement activity across member states. Spending €600 on an LMS subscription to close that specific gap is a materially easier decision than spending nothing and hoping it doesn’t come up.

The practical budgeting logic, in order: cover the legal floor free where a national authority publishes materials, add an LMS once headcount makes tracking necessary, add phishing simulation once training alone isn’t producing measurable behaviour change, and reserve custom builds for genuine sector-specific risk that generic content can’t address.

FAQ

Is NIS2 training actually free?
The content can be — ENISA and some national authorities publish free materials. Delivering it at scale with auditable tracking usually isn’t, once you’re past a handful of employees.

How often does NIS2 training have to happen?
The directive requires “regular” training without fixing an interval. Annual refreshers are the safest practical default in the absence of a published number from your national competent authority.

Does board training cost more than staff training per person?
Yes, substantially — €500–€1,500 per board member for a seminar versus roughly €10–€65 per employee per year for an LMS subscription, because board training is delivered in small, high-touch sessions rather than at scale.

Do the NIS2 Complete Toolkit templates replace a training platform?
No — the toolkit’s Training Plan and Training Tracker document who was trained and on what; they don’t deliver the training content itself or run phishing simulations.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: