What is the compliance reality for DACH CISOs?
With the revised BSI Act (BSIG), the number of regulated entities in Germany rises from roughly 4,500 to around 29,000. For Chief Information Security Officers across the DACH region, this legal mandate does not exist in a vacuum. Organizations that already run a mature Information Security Management System (ISMS) certified under ISO/IEC 27001 very likely meet roughly 70 to 80 percent of the basic IT security requirements of the German NIS2 implementation. Treating these frameworks as separate regulatory silos creates immense administrative overhead, duplicated audit preparation, and fragmented employee training schedules.
Running a separate awareness track for every framework produces severe training fatigue without lowering actual human risk. ENISA's AR-in-a-Box toolbox sets out how to build a custom awareness programme, pick the right tools and channels for each audience, and define key performance indicators to evaluate whether the programme actually works. Instead of maintaining redundant tracks, CISOs need a single awareness strategy that answers the legal mandate, the international ISMS audit, and the national baseline controls at once.
- Duplicated reporting lines and fragmented completion logs across HR and IT management systems
- Inability to map static training completion to concrete operational risk reduction
- Works council friction caused by opaque tracking mechanisms
- Misalignment between executive liability obligations and general workforce training
To eliminate administrative friction, security leaders must dissect what each framework actually demands regarding workforce education and human risk mitigation. For a detailed breakdown of local regulatory mandates, review our guide on NIS2 awareness training requirements in Germany.
NIS2 and BSIG: The new legal mandate
The German transposition of the NIS2 Directive through the BSIG introduces legally binding cybersecurity obligations for essential and important entities, applying immediately from 6 December 2025 with no transitional period. Unlike voluntary standards, the BSIG imposes direct corporate obligations and personal accountability on executive leadership: under Section 38 (3) BSIG, the management bodies of essential and important entities must regularly attend training so they can recognise and assess IT security risks and risk management practices. Workforce security awareness is therefore a mandated risk management measure, not an optional best practice.
Two provisions in the BSIG carry the statutory weight for training and governance, one aimed at the general workforce and one at executive leadership:
- BSIG Section 30 (Risk Management Measures): Requires in-scope entities to implement appropriate, effective and proportionate technical and organizational measures protecting the availability, integrity and confidentiality of their IT systems, including workforce security awareness against social engineering and phishing.
- BSIG Section 38 (Management Responsibility): Requires management bodies to implement the Section 30 risk management measures and supervise their implementation, makes them personally liable for culpably caused damage, and obliges them to attend regular cybersecurity training. The explanatory memorandum recommends training at least every three years, documented with participants, speakers, content and duration for audit purposes.
- Enforcement and fine caps: Non-compliance can trigger fines of up to EUR 10 million or 2 percent of total worldwide annual turnover for essential entities, and up to EUR 7 million or 1.4 percent for important entities, whichever is higher.
In practice that means demonstrable proof of effective training and risk reduction, plus audit-ready documentation. For management training, the BSI expects participation to be recorded so that participants, speakers, content and duration remain available for potential audits, which means a simple attendance certificate may not be enough.
ISO 27001:2022: Clause 7.3 and Annex A 6.3
While NIS2 provides statutory enforcement, ISO/IEC 27001:2022 establishes the structural management framework for information security. Within an accredited ISMS, employee competence is treated as a vital control layer. The 2022 revision explicitly shifted the focus from annual attendance records toward demonstrable behavioral capabilities.
ISO 27001 addresses workforce security across two core components: Clause 7.3 governs organizational awareness, while Control Annex A 6.3 defines practical education requirements.
- Clause 7.3 (Awareness): Personnel performing work under the organization's control must understand the information security policy, their contribution to ISMS effectiveness, and the security implications of non-conformity.
- Annex A Control 6.3 (Information Security Awareness, Education and Training): Personnel must receive appropriate awareness training and regular updates in organizational security policies relevant to their job function.
- Behavioral Verification: Auditors require objective evidence that personnel possess practical competence to operate securely when exposed to social engineering techniques.
Modern ISMS implementations achieve compliance by integrating interactive security training directly into employee workflows, ensuring continuous verification rather than passive compliance logging.
BSI IT-Grundschutz ORP.3: Role-specific sensitization
BSI IT-Grundschutz serves as the national baseline defense methodology developed by Germany's Federal Office for Information Security. Standardized in the IT-Grundschutz Compendium, module ORP.3 ('Sensibilisierung und Schulung zur Informationssicherheit') provides granular, operational guidelines for building an effective security culture.
IT-Grundschutz ORP.3 sorts its requirements into basic, standard and elevated-protection tiers, and it rules out generic one-size-fits-all presentations. The module puts the weight on role-based instruction and on correct behavior during an actual incident.
- Role-Specific Targeting: Tailored training modules designed specifically for high-risk cohorts, IT administrators, financial operators, and executive leadership.
- Scenario-Based Simulation: Exposure to realistic attack vectors including multi-channel phishing, vishing, and voice impersonation.
- Incident Response Readiness: Clear instruction on correct reporting procedures during active security incidents, turning employees into an active detection layer.
Operationally, that pushes teams toward continuous, practical drills that test human responses against current threat vectors, including OSINT-driven targeting scenarios.
Comparing the frameworks: A unified requirement matrix
To construct a streamlined compliance posture, CISOs must map the overlapping expectations of NIS2, ISO 27001:2022, and BSI IT-Grundschutz ORP.3. Understanding where legal enforcement, structural management, and operational execution align enables security teams to deploy a single awareness engine across the enterprise.
| Compliance Dimension | NIS2 / BSIG | ISO 27001:2022 | BSI IT-Grundschutz ORP.3 |
|---|---|---|---|
| Legal Nature & Enforcement | Mandatory EU regulation transposed into German law (BSIG) | Voluntary international management standard | National baseline methodology and certification framework |
| Executive Management Mandate | Explicit training obligation & personal liability (§38 BSIG) | General leadership commitment (Clause 5) | Role-based awareness for management roles |
| Awareness Scope & Depth | Risk management measure (§30 BSIG) across workforce | Continuous awareness & competence (7.3, Annex A 6.3) | Granular, role-specific operational sensitization |
| Verification & Audit Evidence | Audit-ready reporting to BSI; fine cap up to €10M | Third-party ISMS audit logs & competence records | Formal Grundschutz audit evidence & protection modeling |
| Primary Strategic Role | Regulatory obligation & legal compliance | Structural management framework & external trust | Operational security measures & granular defense execution |
As the matrix illustrates, these three frameworks are complementary rather than contradictory. ISO 27001 and BSI IT-Grundschutz supply the methods and proven practices for implementing NIS2 requirements in a structured, auditable way, but they do not replace the directive itself: NIS2 creates the binding legal duties, addresses the management body, and comes with supervision and sanctions. An organization that operationalizes BSI IT-Grundschutz ORP.3 within an ISO 27001 ISMS is therefore well positioned to evidence the statutory risk management requirements of NIS2.
Fulfilling all three with continuous simulations
Unifying NIS2, ISO 27001, and BSI IT-Grundschutz requires moving away from static annual videos toward continuous, automated threat simulations delivered in the flow of work. The revel8 Platform delivers personalized attack simulations across email, SMS, voice vishing, messenger, and deepfake video scenarios enriched with open-source intelligence (OSINT) data. By adapting to each employee's exact role and risk profile, organizations replace passive compliance checkboxes with measurable human resilience.
Continuous multi-channel simulations turn employees into an active detection layer while satisfying strict European data protection standards. Hosted on sovereign cloud infrastructure at STACKIT in Germany, the revel8 Platform ensures complete GDPR compliance and localized data sovereignty. Learn more about our sovereign infrastructure availability on the STACKIT Marketplace.
Crucially, European enterprises must address employee privacy and works council requirements (Betriebsvereinbarung / BetrVG) early in the onboarding process. To protect worker privacy, reporting metrics utilize configurable group-level anonymization with a strict default minimum group size of five employees. Audit-ready logs, real-time SIEM exports, and benchmarks via the Human Firewall Index allow CISOs to prove compliance across NIS2, ISO 27001, and BSI Grundschutz from a single pane of glass.
- Multi-channel attack coverage across email, SMS, vishing, and deepfake video
- Sovereign German cloud hosting on STACKIT with zero customer data model training
- Worker council compliance via automated group-level reporting anonymization (minimum group size of 5)
- Audit-ready NIS2, DORA, and ISO 27001 compliance logging and SIEM integration

.avif)


