Home
Magazine
NIS2, ISO 27001, BSI Grundschutz: Awareness Requirements
NIS2, ISO 27001, BSI Grundschutz: Awareness Requirements

NIS2, ISO 27001, BSI Grundschutz: Awareness Requirements

August 20, 2026
7 min read
Lana Kuzmina
Cyber Threat Analyst
lana

DACH enterprises must navigate overlapping security awareness rules under NIS2, ISO 27001, and BSI IT-Grundschutz. Unifying these frameworks into a single, OSINT-driven simulation program ensures continuous compliance without duplicating administrative effort.

Table of contents

Get started
with revel8

  • NIS2 BSIG Paragraph 30 mandates regular cyber training, with fines of up to EUR 10 million or 2 percent of worldwide turnover for essential entities.
  • ISO 27001 Annex A 6.3 requires personnel to demonstrate practical competence, not just acknowledge policies.
  • BSI IT-Grundschutz ORP.3 focuses on role-specific sensitization, teaching employees how to react during incidents.
  • ENISA's AR-in-a-Box toolbox provides guidelines, channel selection advice, and KPIs for building an awareness programme.
  • Unifying these frameworks with multi-channel simulations satisfies compliance while respecting BetrVG rules.

What is the compliance reality for DACH CISOs?

With the revised BSI Act (BSIG), the number of regulated entities in Germany rises from roughly 4,500 to around 29,000. For Chief Information Security Officers across the DACH region, this legal mandate does not exist in a vacuum. Organizations that already run a mature Information Security Management System (ISMS) certified under ISO/IEC 27001 very likely meet roughly 70 to 80 percent of the basic IT security requirements of the German NIS2 implementation. Treating these frameworks as separate regulatory silos creates immense administrative overhead, duplicated audit preparation, and fragmented employee training schedules.

Running a separate awareness track for every framework produces severe training fatigue without lowering actual human risk. ENISA's AR-in-a-Box toolbox sets out how to build a custom awareness programme, pick the right tools and channels for each audience, and define key performance indicators to evaluate whether the programme actually works. Instead of maintaining redundant tracks, CISOs need a single awareness strategy that answers the legal mandate, the international ISMS audit, and the national baseline controls at once.

  • Duplicated reporting lines and fragmented completion logs across HR and IT management systems
  • Inability to map static training completion to concrete operational risk reduction
  • Works council friction caused by opaque tracking mechanisms
  • Misalignment between executive liability obligations and general workforce training

To eliminate administrative friction, security leaders must dissect what each framework actually demands regarding workforce education and human risk mitigation. For a detailed breakdown of local regulatory mandates, review our guide on NIS2 awareness training requirements in Germany.

The German transposition of the NIS2 Directive through the BSIG introduces legally binding cybersecurity obligations for essential and important entities, applying immediately from 6 December 2025 with no transitional period. Unlike voluntary standards, the BSIG imposes direct corporate obligations and personal accountability on executive leadership: under Section 38 (3) BSIG, the management bodies of essential and important entities must regularly attend training so they can recognise and assess IT security risks and risk management practices. Workforce security awareness is therefore a mandated risk management measure, not an optional best practice.

Two provisions in the BSIG carry the statutory weight for training and governance, one aimed at the general workforce and one at executive leadership:

  • BSIG Section 30 (Risk Management Measures): Requires in-scope entities to implement appropriate, effective and proportionate technical and organizational measures protecting the availability, integrity and confidentiality of their IT systems, including workforce security awareness against social engineering and phishing.
  • BSIG Section 38 (Management Responsibility): Requires management bodies to implement the Section 30 risk management measures and supervise their implementation, makes them personally liable for culpably caused damage, and obliges them to attend regular cybersecurity training. The explanatory memorandum recommends training at least every three years, documented with participants, speakers, content and duration for audit purposes.
  • Enforcement and fine caps: Non-compliance can trigger fines of up to EUR 10 million or 2 percent of total worldwide annual turnover for essential entities, and up to EUR 7 million or 1.4 percent for important entities, whichever is higher.

In practice that means demonstrable proof of effective training and risk reduction, plus audit-ready documentation. For management training, the BSI expects participation to be recorded so that participants, speakers, content and duration remain available for potential audits, which means a simple attendance certificate may not be enough.

ISO 27001:2022: Clause 7.3 and Annex A 6.3

While NIS2 provides statutory enforcement, ISO/IEC 27001:2022 establishes the structural management framework for information security. Within an accredited ISMS, employee competence is treated as a vital control layer. The 2022 revision explicitly shifted the focus from annual attendance records toward demonstrable behavioral capabilities.

ISO 27001 addresses workforce security across two core components: Clause 7.3 governs organizational awareness, while Control Annex A 6.3 defines practical education requirements.

  1. Clause 7.3 (Awareness): Personnel performing work under the organization's control must understand the information security policy, their contribution to ISMS effectiveness, and the security implications of non-conformity.
  2. Annex A Control 6.3 (Information Security Awareness, Education and Training): Personnel must receive appropriate awareness training and regular updates in organizational security policies relevant to their job function.
  3. Behavioral Verification: Auditors require objective evidence that personnel possess practical competence to operate securely when exposed to social engineering techniques.

Modern ISMS implementations achieve compliance by integrating interactive security training directly into employee workflows, ensuring continuous verification rather than passive compliance logging.

BSI IT-Grundschutz ORP.3: Role-specific sensitization

BSI IT-Grundschutz serves as the national baseline defense methodology developed by Germany's Federal Office for Information Security. Standardized in the IT-Grundschutz Compendium, module ORP.3 ('Sensibilisierung und Schulung zur Informationssicherheit') provides granular, operational guidelines for building an effective security culture.

IT-Grundschutz ORP.3 sorts its requirements into basic, standard and elevated-protection tiers, and it rules out generic one-size-fits-all presentations. The module puts the weight on role-based instruction and on correct behavior during an actual incident.

  • Role-Specific Targeting: Tailored training modules designed specifically for high-risk cohorts, IT administrators, financial operators, and executive leadership.
  • Scenario-Based Simulation: Exposure to realistic attack vectors including multi-channel phishing, vishing, and voice impersonation.
  • Incident Response Readiness: Clear instruction on correct reporting procedures during active security incidents, turning employees into an active detection layer.

Operationally, that pushes teams toward continuous, practical drills that test human responses against current threat vectors, including OSINT-driven targeting scenarios.

Comparing the frameworks: A unified requirement matrix

To construct a streamlined compliance posture, CISOs must map the overlapping expectations of NIS2, ISO 27001:2022, and BSI IT-Grundschutz ORP.3. Understanding where legal enforcement, structural management, and operational execution align enables security teams to deploy a single awareness engine across the enterprise.

Compliance DimensionNIS2 / BSIGISO 27001:2022BSI IT-Grundschutz ORP.3
Legal Nature & EnforcementMandatory EU regulation transposed into German law (BSIG)Voluntary international management standardNational baseline methodology and certification framework
Executive Management MandateExplicit training obligation & personal liability (§38 BSIG)General leadership commitment (Clause 5)Role-based awareness for management roles
Awareness Scope & DepthRisk management measure (§30 BSIG) across workforceContinuous awareness & competence (7.3, Annex A 6.3)Granular, role-specific operational sensitization
Verification & Audit EvidenceAudit-ready reporting to BSI; fine cap up to €10MThird-party ISMS audit logs & competence recordsFormal Grundschutz audit evidence & protection modeling
Primary Strategic RoleRegulatory obligation & legal complianceStructural management framework & external trustOperational security measures & granular defense execution

As the matrix illustrates, these three frameworks are complementary rather than contradictory. ISO 27001 and BSI IT-Grundschutz supply the methods and proven practices for implementing NIS2 requirements in a structured, auditable way, but they do not replace the directive itself: NIS2 creates the binding legal duties, addresses the management body, and comes with supervision and sanctions. An organization that operationalizes BSI IT-Grundschutz ORP.3 within an ISO 27001 ISMS is therefore well positioned to evidence the statutory risk management requirements of NIS2.

Fulfilling all three with continuous simulations

Unifying NIS2, ISO 27001, and BSI IT-Grundschutz requires moving away from static annual videos toward continuous, automated threat simulations delivered in the flow of work. The revel8 Platform delivers personalized attack simulations across email, SMS, voice vishing, messenger, and deepfake video scenarios enriched with open-source intelligence (OSINT) data. By adapting to each employee's exact role and risk profile, organizations replace passive compliance checkboxes with measurable human resilience.

Continuous multi-channel simulations turn employees into an active detection layer while satisfying strict European data protection standards. Hosted on sovereign cloud infrastructure at STACKIT in Germany, the revel8 Platform ensures complete GDPR compliance and localized data sovereignty. Learn more about our sovereign infrastructure availability on the STACKIT Marketplace.

Crucially, European enterprises must address employee privacy and works council requirements (Betriebsvereinbarung / BetrVG) early in the onboarding process. To protect worker privacy, reporting metrics utilize configurable group-level anonymization with a strict default minimum group size of five employees. Audit-ready logs, real-time SIEM exports, and benchmarks via the Human Firewall Index allow CISOs to prove compliance across NIS2, ISO 27001, and BSI Grundschutz from a single pane of glass.

  • Multi-channel attack coverage across email, SMS, vishing, and deepfake video
  • Sovereign German cloud hosting on STACKIT with zero customer data model training
  • Worker council compliance via automated group-level reporting anonymization (minimum group size of 5)
  • Audit-ready NIS2, DORA, and ISO 27001 compliance logging and SIEM integration

FAQ

What are the employee training requirements under NIS2?

Under the German NIS2 implementation (BSIG Paragraph 30), important and essential entities must conduct regular security awareness training. The goal is to ensure employees can securely handle IT systems and sensitive data, identifying modern threats like multi-channel social engineering.

Does NIS2 require separate training for management?

Yes. Under BSIG Paragraph 38, management boards must undergo specialized cybersecurity training. This is a distinct legal obligation separate from the general employee awareness requirements, ensuring leadership understands cyber risks and their direct accountability.

How does ISO 27001:2022 address security awareness?

ISO 27001 Clause 7.3 and Annex A 6.3 require organizations to implement a formal information security awareness program. Personnel must be educated on organizational policies and equipped with the practical skills needed to operate securely within their specific roles.

What is BSI IT-Grundschutz ORP.3?

ORP.3 is the BSI IT-Grundschutz module dedicated to sensitization and training. It outlines how to build an effective awareness program, emphasizing that employees must understand relevant threats and know exactly how to react in security-critical situations.

Can one training program satisfy NIS2, ISO 27001, and BSI Grundschutz?

Yes. A unified approach that delivers role-specific, continuous threat simulations and provides audit-ready reporting fulfills the compliance mandates of all three frameworks. This eliminates duplicate efforts and provides centralized documentation for auditors.

How do works council rules affect awareness training in Germany?

German works councils (BetrVG) require strict privacy controls for employee monitoring. Training platforms must offer group-level reporting anonymization, ensuring compliance data can be aggregated for audits without tracking individual user failures.

Sources

Related Articles

White abstract curved shape with jagged edges on a black background.

Ready to defend against
AI-powered attacks?