role-based · verifiable · compliance-oriented
NIS2 Training for Regulated Organizations
role-based · verifiable · compliance-oriented
We provide role-based training for executive management, departments, and employees – ensuring that regulatory requirements are reliably implemented and that competencies are sustainably embedded within the company.
The ML Gruppe offers you
NIS-2: Who Is Affected? It’s More Than Just Your IT!
The requirements range from executive management to incident management and extend all the way to the supply chain. Those affected must take a holistic view of responsibilities, processes, and competencies.
Five Steps to NIS 2 Implementation
We’ll support you with a learning solution tailored to your company’s needs.

We follow a five-step process:
1 | Identify NIS-2 Training Needs
Together, we’ll analyze which regulatory requirements apply to your company and which target groups need to be certified.
5 | Generate insights
Structured feedback from students and academic departments—the foundation for continuous improvement.

2 | Developing a Learning Architecture
What content do management, business units, IT, and employees need? Subject matter experts from the respective areas will be consulted.
4 | Provide supporting documentation
Document participation, learning progress, and training activities in a transparent manner.
3 | Implement Formats
E-learning, live training ( , both online and in-person), live hacking, or blended learning.
4 | Provide supporting documentation
Document participation, learning progress, and training activities in a transparent manner.
5 | Generate insights
Structured feedback from students and academic departments—the foundation for continuous improvement.
Our NIS 2 training solution: modular, role-based, and verifiable
No one-size-fits-all approach – every role in the company receives exactly the training it needs.
Our modules are designed to meet the requirements of the NIS2UmsuCG and BSIG and help companies establish responsibilities, security competencies, and organizational measures in a sustainable manner.
ML Gruppe: Experience in safety-critical industries
For over 35 years, we have been supporting organizations through challenging change processes. Our experience in KRITIS sectors, the defense industry, and other regulated industries is incorporated into every learning solution.
Questions & Answers: What You Need to Know About NIS-2
NIS-2 (Network and Information Security Directive 2) is the revised EU directive on cybersecurity for critical infrastructure.
It replaces the original NIS Directive from 2016 and sets out binding minimum requirements for cyber resilience, risk management, reporting obligations, supply chain security, and, quite explicitly, employee training.
The directive took effect throughout the EU on January 16, 2023, and member states were required to transpose it into national law by October 17, 2024.
The NIS 2 Implementation Act (NIS2UmsuCG) took effect on December 6, 2025—without a transition period. Affected companies have been required to comply with the obligations immediately since then. The competent authority is the BSI, with which registration is required.
For affected companies, this means they can no longer view cybersecurity as merely an IT issue, but rather as an ongoing organizational responsibility, and they must implement it in a verifiable manner rather than simply documenting it from a technical standpoint.
The classification follows three steps: sector → size → category. Eighteen sectors are regulated, divided into two groups in accordance with two annexes to the BSIG:
Appendix 1 — Sectors of critical and important infrastructure (high criticality): Energy, transportation and traffic, banking, financial market infrastructures, healthcare, drinking water and wastewater, digital infrastructure, ICT service management, public administration, and space.
Appendix 2 – Sectors of Critical Infrastructure: Postal and courier services, waste management, chemicals, food production, manufacturing (including mechanical engineering, medical devices, electronics, and automotive manufacturing), digital service providers, and research.
Within these sectors, the company’s size (“size-cap rule”) determines the category:
- Major organization with 50 or more employees OR €10 million in revenue or total assets, as well as
- An organization of particular importance with 250 or more employees OR €50 million in revenue or €43 million in total assets.
KRITIS operators, trust service providers, and TLD/DNS providers are also affected, regardless of their size. Suppliers are also often indirectly subject to these requirements through supply chain mandates.
The BSI offers a service for conducting an impact analysis. The impact analysis is based on the BSI’s decision tree.
NIS-2 requires organizational and technical cybersecurity measures. These explicitly include training, awareness initiatives, and cyber hygiene for employees.
Defense companies are often part of critical supply chains or operate security-critical infrastructure. As a result, regulatory requirements and threat levels increase significantly.
This applies to electricity, gas, district heating, and oil suppliers, as well as all grid operators (transmission and distribution system operators) and operators of critical generation facilities—in effect, the entire relevant energy sector. Municipal utilities and local providers also fall under NIS-2, provided they meet the thresholds, which is the case for most companies with their own grid. Particular attention must be paid here to supply chain security: Many municipal utilities share service providers, IT systems, and remote maintenance infrastructures, which must also be secured under NIS-2.
For significant entities, fines of up to 10 million euros or 2% of global annual revenue may be imposed—whichever amount is higher. For important entities, the upper limit is 7 million euros or 1.4% of annual revenue. In addition, regulatory authorities may order temporary operational restrictions.
Of particular note: Managing directors and governing bodies are personally liable for ensuring compliance with safety obligations.
Yes—and that is one of the most important changes compared to the old NIS 1 Directive. Article 20 of NIS 2 explicitly requires the management bodies of essential and important facilities to participate in cybersecurity training and to demonstrate the knowledge they have acquired. Training must therefore not be limited to the IT department.
NIS-2 and the German KRITIS regulation (Section 8a BSIG) overlap in some areas but have different focuses. NIS-2 has a broader scope—both in terms of sector coverage and organizational requirements. The KRITIS umbrella law, which is currently being drafted in Germany, is intended to regulate the physical resilience of critical infrastructure and adds another dimension of compliance to NIS-2. Energy providers must keep both sets of regulations in mind.
That depends on the starting point and the size of the organization. Based on practical experience: A full rollout—from needs analysis through design to the first documented training session—typically takes three to six months for medium-sized energy utilities (200–1,000 employees). Ongoing updates and refresher training should then be viewed as a continuous process, not as a one-time project.
Effective NIS-2 training programs for KRITIS companies must:
- Take into account OT/IT convergence and specific KRITIS scenarios
- be structured according to specific roles (control center, field staff, management, IT)
- Ensure traceability for regulatory authorities (documentation, certification)
- Include regular review cycles and status updates
- Explicitly involve executives and governing bodies (NIS 2 requirement)
The legal obligations can be grouped into five categories:
1. Comprehensive Risk Management (Section 30 BSIG)
Affected companies must implement technical and organizational measures—ranging from risk analysis, incident response, business continuity, and supply chain security to access control and multi-factor authentication. The scope is determined by the principle of proportionality, not by a rigid, standardized list.
2. Reporting of Security Incidents Within Specified Time Frames (Section 32 BSIG)
In the event of a significant security incident, a three-step reporting procedure applies: an early warning within 24 hours of becoming aware of the incident, a follow-up report with an initial assessment within 72 hours, and a final report no later than one month after the incident.
3. Registration Requirement (Section 33 of the BSIG)
Affected companies must register with the BSI—regardless of their other obligations.
4. Management’s Obligation to Implement, Monitor, and Receive Training (§38 BSIG)
Management must personally approve the risk management measures, monitor their implementation, and undergo regular training. This obligation cannot be delegated to the IT department.
5. Obligation to Provide Evidence (Section 39 BSIG)
Particularly important organizations must demonstrate the effectiveness of their measures to the BSI at regular intervals, for example through audits or certifications.



















