NIS2 · ISO 27001 · awareness evidence

Document NIS2 awareness pragmatically.

Short cyber missions for employees: identify risks, use reporting paths, complete the knowledge check and document participation internally. No learning platform rollout.

StartMission code

Redeem in the browser without classic participant accounts.

TrainingDecisions

Phishing, MFA, AI use, data and reporting paths in daily work situations.

EvidenceKnowledge check

Check completion and document participation internally or for audit requests.

TemplatePolicy included

Ready-to-use template for internal documentation.

What this page is for.

NIS2 awareness does not replace legal advice, a scope assessment or an ISMS. This page explains which awareness topics employees should understand and which Paragamix.Cyber missions fit that need.

NIS2 and BSIG

NIS2 sets the European framework. In Germany, obligations become practical through national implementation and the BSIG context.

ISO 27001

ISO/IEC 27001 provides the structure for information security management, training, competence and documented evidence.

Awareness in daily work

Employees need to classify common situations correctly: email, MFA, AI tools, customer data, suppliers and incident reporting.

Suitable missions for NIS2 awareness.

The basic training is the leanest entry point. AI Awareness and Blackout add concrete NIS2-related risk areas.

Basic training

The New Customer: passwords, MFA, email, customer data, remote work, AI use, visitors and security incidents.

View product page

AI Awareness

The Quick Prompt: use approved tools, minimise data, review prompts, recognise deepfake calls and assess AI results.

View product page

Blackout

Everything Stops: identify outages, initiate emergency operation, secure communication and coordinate recovery.

View product page

Important content for NIS2.

Employees do not need directive language in daily work. They need safe behaviour in recurring situations.

  • Recognise phishing, social engineering, suspicious attachments, QR codes and lookalike websites
  • Handle MFA, authenticator prompts, passwords and access securely
  • Protect customer, contract, personal and access data
  • Use AI tools only with an approved purpose and minimised data
  • Report security incidents through internal channels and document observations traceably

Evidence and boundaries.

Participation evidence can be used internally and for customer or audit requests. It documents completion and the knowledge check, but does not replace certification, audit confirmation or legal advice.

  • useful as a component for training documentation, ISMS and management reporting
  • policy template per mission as a working aid for internal documentation
  • code-based start without a classic learning platform or personal learning profiles

Professionally framed.

Professionally responsible: Alexander Graf Schulenburg, Certified ISO/IEC 27001 Lead Auditor. The missions are aligned with information security, cyber hygiene, NIS2/German BSIG context, ISO/IEC 27001, ENISA/BSI orientation and practical ISMS experience.

Sources and status.

Status: 28 June 2026. Organizations should check sector, size, role and scope against national implementation and BSI information.

Frequently asked questions about NIS2 awareness.

Short answers on obligation, target groups and evidence.

Is NIS2 training mandatory for employees?

Whether and to what extent training is required depends on scope, national implementation and the organization's risk management. Awareness is an important component, but it does not replace legal assessment.

Which employees should be trained?

Awareness is useful for all employees who work with email, access rights, information, customers, suppliers, AI tools or reporting paths.

Is employee training sufficient for NIS2?

No. Employee training is only one component. Risk management, technical and organizational measures, reporting processes, responsibilities and documentation are also required.

Does the evidence help with ISO 27001?

Yes, as training and awareness evidence within an ISMS. It does not replace formal certification or an audit.

Start lean.

For a first NIS2 awareness step, the Basic Training The New Customer is the most direct starting point.