What should NIS2 training for the board cover?

Michał Rutkowski • for the board and management • published August 18, 2026 • updated August 18, 2026 • 9 min read

Legal status

August 2026. The Polish Act on the National Cybersecurity System (KSC) as amended by the Act of January 23, 2026 (Journal of Laws 2026, item 252), in force since April 3, 2026. Training obligation of the head of the entity: Article 8e; the catalogue of obligations they are answerable for: Articles 8c and 8d.

Last significant update: August 18, 2026.

Short answer

The scope of this training is not a matter of taste or of what a provider happens to offer — it is set by the Polish Act on the National Cybersecurity System (KSC). Under Article 8e(2), the training covers the performance of the very obligations for which the head of the entity bears responsibility: from entry in the KSC Register, through the information security management system and criminal record checks on staff, to incident handling and reporting, documentation and audit. The Act says nothing, however, about the form, the length or the level of detail — that is for the organization to settle. The practical difference between training that satisfies the obligation and training that changes something is whether the statutory scope has been translated into the decisions this particular board actually takes.

Why this question arises at all

Two different products circulate on the market under the same name. The first is an overview of Directive (EU) 2022/2555: objectives, sectors, the implementation calendar across the EU. The second is training on the obligations that rest on a particular entity under Polish law. Boards usually order the first and are held to account for the second — because the directive binds the Member State, whereas an organization’s obligations and the personal responsibility of the head of the entity follow from the KSC Act as amended by the Act of January 23, 2026, in force since April 3, 2026.

The second source of doubt is the construction of the training obligation itself. The Act states who is to be trained and how often: the head of an essential or important entity, and the person entrusted with the head’s cybersecurity duties, undergoes training once per calendar year (Article 8e(1)), and participation in the training is documented (Article 8e(3)). It describes the scope by reference to article numbers, not by a list of topics. Someone reading that provision knows they have to be trained, but cannot see directly on what.

That cross-reference does, however, reveal something important. The catalogue in Article 8e(2) overlaps with the catalogue of obligations for which the head is responsible under Article 8c(1). The legislator therefore did not design a general development programme — it tied the scope of the training to the scope of responsibility. That is the shortest answer to the question of what this training is for: it is meant to prepare a specific person to be held to account for specific obligations.

What should the board know?

The training obligation is personal and applies to the head of the entity, not to the IT department. Where the function is performed by a collective body and no responsible person has been designated, responsibility is borne by all members of that body (Article 8c(2)) — and that settles who has to be trained. Entrusting the duties to another person with their consent does not remove responsibility from the head (Article 8c(3)); it only means that both sides have to be trained. The cycle is annual and counted in calendar years, and participation has to be documented — the evidence is part of the obligation, not a formality after it.

Failure to perform this obligation is separately sanctioned: Article 73a lists it among the grounds for a financial penalty imposed on the head of the entity. That penalty may be imposed independently of the penalty imposed on the entity itself. The transitional provisions defer its application — penalties from that catalogue may only be imposed after two years from the entry into force of the amendment — but the deferral concerns the sanction, not the obligation.

The scope is set by the Act, so training that only covers the directive and the threat landscape does not cover what the head of the entity is held to account for.

What must be determined before the decision

Who in the organization is covered by the obligation

The question sounds trivial and in practice decides half the cost. The obligation applies to the head of the entity — that is, the body or person managing the entity — and to the person entrusted with the head’s duties in the field of cybersecurity. In a company with a three-member management board where no single responsible member has been designated, the whole board has to be trained. In a capital group, status is established separately for each company, so a single session “for the group” does not close the subject in entities whose heads did not attend.

It is worth deciding separately whether anyone else should take part. The Act does not require it, but the person preparing decision material for the board, and the people designated as contact points for the entities of the national cybersecurity system, usually need the same knowledge — otherwise the board receives, for its meeting, a paper whose author understood the subject differently than it does.

When the obligation starts to bind

The Act regulates the cycle, not the start. Article 8e(1) imposes the obligation to undergo training once per calendar year, and Article 8e(3) requires participation to be documented — and that is where what follows directly from the provision ends. The Act sets no separate deadline for the first training: it indicates neither a cut-off date nor an event from which one would run.

In practical terms this means the organization itself adopts and records an assumption as to the first year of the cycle, and then keeps to it consistently — because every subsequent training date depends on it. The calendar year is a rigid unit here: training held in December satisfies the obligation for the year in which it took place and does not carry it over to the next one.

A practical recommendation, not a statutory obligation: hold the first training as part of implementing the information security management system, before the deadline for performing obligations set out in Article 33(1) of the amending act, and treat the year in which it is held as the first year of the cycle.

What scope the Act sets

Article 8e(2) refers to specific provisions. The table below translates them into the areas the board actually asks about, and into the decisions that sit behind each of them.

Area referred to in Article 8e(2)What it coversThe board decision it serves
Registration obligations (Article 7b(4), Article 7c, Article 7f(3))Application for entry in the KSC Register, notification of changes to the data, removal from the register once the criteria cease to be metWho watches the entity’s status and the deadlines for updating the data
Information security management system (Article 8)A catalogue of measures from risk assessment policies, through human resources security, the ICT supply chain, business continuity, monitoring, cryptography and multi-factor authentication, to asset management and access control; for an important entity that is a public entity — a simplified system under the annex to the ActThe scope of implementation, priorities, budget and the split between in-house work and work entrusted to a supplier
Tasks of the head of the entity (Article 8d)Decisions on the ISMS, planning of financial resources, assignment of tasks and oversight of their performance, staff awareness, compliance with the law and internal rulesHow the board performs these tasks — and what it will document that with
Criminal record checks on staff (Article 8f(1) and (2))Information from the National Criminal Register on the absence of convictions for offences against the protection of information, before a person is allowed to perform tasks under Article 8 or Article 11, and a repeat request for information where there is reasonable suspicion; a valid security clearance to the “confidential” level or higher replaces that requirementThe point at which a person is allowed to perform tasks, and the change in the HR process
Contact and information duties (Article 9)Designation of at least two contact persons for the entities of the national cybersecurity system — one is enough only for micro and small enterprises and for an important entity that is a public entity; a channel for reporting cyber threats, vulnerabilities and incidents; passing on knowledge about threats to usersStaffing, cover arrangements and the real availability of those people
Cybersecurity documentation (Article 10)Preparation and updating of normative and operational documentation, retention for at least 2 yearsWho maintains the documentation and in what mode the board reviews it
Incident handling and reporting, and reporting duties (Articles 11–12b)Incident handling, classification of a significant incident against the thresholds, an early warning within 24 hours and a report within 72 hours — both counted from detection; an interim report at the CSIRT’s request, a final report within one month of the notification, a progress report where handling is not complete; the duty to inform the users of the services; submission through the S46 systemThe escalation path to the head of the entity and the organization’s readiness during the first day
Structures and audit (Articles 14 and 15)Own structures responsible for cybersecurity or a contract with a provider of managed services in the field of cybersecurity, and a security audit of the information system — in an essential entity at least once every three years, counting from the signature of the previous reportThe operating model for the area and the audit schedule

The table shows why training about threats is not enough. Apart from one area — human resources security and cyber hygiene — the whole list is about the organization of work, contracts, documents and deadlines, not about technology.

One element is worth verifying against the procedures during the training, because it is most often written into them incorrectly: the addressee of the report. The Act directs reports to the competent sectoral CSIRT, but the transitional provisions keep CSIRT MON, CSIRT NASK and CSIRT GOV as the addressees until a communication is issued confirming that the sectoral CSIRT has reached operational capability — and the competent authorities have eighteen months to establish them.

What the programme should contain

This is already a practical judgement, not the content of a provision. A programme that uses the time sensibly is built on the material of a specific organization and usually contains seven elements:

  1. A map of the entity’s obligations with roles assigned — who delivers each of the areas from the table above and how the board will know it is being delivered.
  2. An explanation of how responsibility is constructed: what it means that delegating tasks does not transfer responsibility, how the position of a collective body works, and what makes the penalty for the head of the entity separate.
  3. Reading a risk analysis at decision level — what the board approves, what level of risk it accepts and how it records that.
  4. A decision exercise on the first day of an incident: who informs the head of the entity, within what time, who decides on the report and what happens when the decision falls on a Friday evening.
  5. Supplier oversight — which contractual clauses need to change and who in the organization can negotiate them.
  6. A review of the evidence: what the documentation the organization will show an auditor looks like, and what is missing from it today.
  7. A calendar of the organization’s own obligations for the next twelve months, with the deadlines that organization actually faces.

The fourth element is in practice the most instructive. A discussion of the reporting obligation usually ends with the finding that information about an incident reaches the board more slowly than the reporting deadlines require — and that finding changes the procedure, not the state of knowledge.

How to demonstrate that the obligation has been met

Article 8e(3) requires participation in the training to be documented, but does not describe the form of the document. Evidential value attaches to a set that makes it possible to reconstruct what the training was about: a programme whose scope is referenced to the provisions listed in Article 8e(2), the date and format of the session, named confirmation of attendance by the head of the entity and by the person entrusted with the duties, and the materials handed to participants. A certificate that merely says “NIS2 training” shows that somebody was somewhere.

A practical note on the cycle: the provision speaks of a calendar year, not of twelve months from the previous training. Training held in December satisfies the obligation for the year in which it took place — it does not carry over to the following year. Organizations that plan training on an annual cycle counted from the date of the previous one drift out of the calendar year unnoticed after a few years.

How this training differs from staff training

These are two different obligations, and confusing them costs either money or compliance. Training for the head of the entity has its source in Article 8e and applies to named individuals. Staff education in cybersecurity and basic cyber hygiene, by contrast, are elements of the information security management system under Article 8, and the head of the entity is answerable for staff being aware of their obligations and knowing the internal rules (Article 8d). For staff the Act sets no interval — the Ministry of Digitization, in its questions and answers, indicates that education should take place on an ongoing basis and should take into account staff obligations within the ISMS, the applicable procedures and examples of incidents. The exception is important entities that are public entities: for them the annex to the Act names training for people involved in processing information as a specific measure, and requires a review of the whole system at least once a year. Which people beyond the head of the entity that second group covers is settled in a separate article on selecting the groups to train.

A simple organizational conclusion follows: one event will not serve both obligations. The board and the staff need different content, and a joint session usually ends with material that is too technical for the board and too abstract for employees. Where an organization is also subject to the GDPR, it is more practical to build one training plan rather than two: the hard deadline from the KSC Act sets the rhythm for management roles, and the GDPR criteria — the scope for the remaining groups. How to set that second rhythm I have described in How often should employees be trained on personal data protection?.

Most common mistakes

  • Training about the directive instead of about the entity’s obligations. An overview of NIS2 at EU level is useful as an introduction, but it does not cover the scope set out in Article 8e(2), because the obligations follow from national law.
  • A technical programme for a management audience. A survey of attack types does not prepare anyone to approve a risk analysis or to decide on reporting an incident.
  • Leaving out the person entrusted with the head’s duties. The Act names them alongside the head of the entity, and in practice it is they who run the subject day to day.
  • Training one board member where no responsible person has been formally designated. Where there is no designation, responsibility covers all members of the body.
  • Evidence limited to an attendance list. Without the programme and its scope there is no way to show that the training corresponded to the provisions the Act refers to.
  • Postponing training to the end of the adjustment period. What is deferred is the penalties, not the obligations — and training held early shows what is missing in the other areas, for which the deadline is the same.
  • Training instead of a gap analysis. Training organizes the board’s knowledge of the obligations; it does not replace establishing which of them the organization already meets.

Conclusions and next steps

The question of the scope of the training has an unusually concrete answer, because the legislator tied it to the responsibility of the head of the entity. Good training for a board is therefore not a lecture on cybersecurity but a review of the organization’s own obligations, ending with a list of decisions to be taken and a list of evidence to be assembled.

An order that works when commissioning such training:

  1. Establish by name who is covered by the obligation: the head of the entity, the members of a collective body where no responsible person has been designated, and the person entrusted with the cybersecurity duties.
  2. Set the obligations under Article 8e(2) against the facts of the organization — that document is at once training material and the starting point for a gap analysis.
  3. Ask the provider for a programme referenced to the provisions, not to a thematic agenda.
  4. Plan the date within the calendar year, not on a twelve-month cycle, and record the assumption adopted as to the first year of the cycle.
  5. Establish what will remain after the training as evidence and where it will be kept.
  6. Record the decisions taken during the training — it is those, not the certificate, that are its outcome.

If an organization is only now putting the order of work together, training is not the first step. The first is settling who is responsible and what the starting point is, and right after it a gap analysis for NIS2 and KSC readiness — without it, the training discusses obligations in isolation from how many of them the organization already meets.

Related materials

Sources

  • Act of July 5, 2018 on the National Cybersecurity System, Articles 8c–8f, Articles 9–15 and Article 73a, consolidated text — Chancellery of the Sejm, ISAP: isap.sejm.gov.pl (accessed: August 18, 2026) (in Polish)
  • Act of January 23, 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252) — transitional provisions, Journal of Laws: dziennikustaw.gov.pl (accessed: August 18, 2026) (in Polish)
  • Directive (EU) 2022/2555 of the European Parliament and of the Council (NIS2), Article 20 — EUR-Lex: eur-lex.europa.eu (accessed: August 18, 2026)
  • Amendment to the KSC Act — questions and answers — Ministry of Digitization: gov.pl (accessed: August 18, 2026) (in Polish)
  • Amendment to the KSC Act — obligations of essential and important entities — Ministry of Digitization: gov.pl (accessed: August 18, 2026) (in Polish)

Author

Michał Rutkowski — LabLogic. Combines legal, organizational, and technological perspectives in working with boards of medium and large organizations: support and performance of DPO functions, preparation for NIS2 and KSC, incident response, audits, and training. Contact: M.Rutkowski@LabLogic.pl

Let’s set the scope of training for your board

If there is no training for the head of the entity in the calendar yet, it is worth starting by setting the obligations under Article 8e(2) against the facts of the organization — that comparison defines the programme and shows what is really missing. Training and workshops tailored to roles and processes are built on exactly that comparison.

This material is general and educational in nature. It does not constitute individual legal advice or a recommendation for a specific organization. The scope of obligations should be assessed taking into account its situation.

Legal status: August 2026.

Scroll to Top