For teams
Which EU laws require staff training: NIS2, DORA, the GDPR or the AI Act?

Four EU laws that reach many organizations put training into the text: NIS2 for the management bodies of essential and important entities, DORA for every employee of a financial entity, the GDPR through the data protection officer's tasks, and the AI Act for anyone using AI systems at work. They differ in who must be trained, how strictly, and since when. This page quotes each from the Official Journal and gives you a register to record what your organization does about them.
Every quotation was read on 2 October 2026 from the Official Journal texts of Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2016/679 (the GDPR) and Regulation (EU) 2024/1689 (the AI Act), as amended. This is not legal advice.
How do the four training duties compare?
| Law | Who must be trained | Since |
|---|---|---|
| NIS2, Article 20(2) | Members of the management bodies of essential and important entities; employees are to be encouraged | National law; Member States were to apply it from 18 October 2024 |
| DORA, Article 13(6) | All employees and senior management staff of financial entities | 17 January 2025 |
| GDPR, Article 39(1)(b) | Staff involved in processing operations, through the DPO's monitoring task | 25 May 2018 |
| AI Act, Article 4 | Staff and others dealing with AI systems on the organization's behalf | 2 February 2025, wording amended from 27 July 2026 |
What does NIS2 require of management bodies?
Article 20 of NIS2 is headed "Governance". Paragraph 1 requires Member States to ensure that management bodies approve their entity's cybersecurity risk-management measures, oversee their implementation, and "can be held liable for infringements". Paragraph 2 adds the training duty:
Member States shall ensure that the members of the management bodies of essential and important entities are required to follow training, and shall encourage essential and important entities to offer similar training to their employees on a regular basis, in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity.
Two points matter for a training plan. The duty on the board is firm, while training for employees is something Member States must encourage. And NIS2 is a directive: Article 41 required Member States to adopt their measures by 17 October 2024 and apply them from 18 October 2024, so the duty that binds you is in your country's transposing law, which may go further. Our guide to NIS2 duties for management bodies covers Articles 20, 21 and 23 in full.
What does DORA require of financial entities?
DORA is a regulation and has applied directly since 17 January 2025. It covers the financial entities listed in Article 2, from credit institutions, payment institutions and investment firms to insurers, fund managers and crypto-asset service providers. Article 13(6) reads:
Financial entities shall develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes. Those programmes and training shall be applicable to all employees and to senior management staff, and shall have a level of complexity commensurate to the remit of their functions.
It goes on to say that, where appropriate, financial entities shall also include ICT third-party service providers in their training schemes. DORA also puts the budget on the board: under Article 5(2)(g), the management body must "allocate and periodically review the appropriate budget" for digital operational resilience, including this training and "ICT skills for all staff". Article 5(4) adds a duty on each board member to keep up to date "including by following specific training on a regular basis". Of the four laws, DORA is the most specific: compulsory, for everyone, and scaled to the role. Our DORA guide for management bodies has the detail.
Does the GDPR require staff training?
Only indirectly, and it is easy to overstate. Article 39(1)(b) lists among the tasks of the data protection officer:
to monitor compliance with this Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;
So the DPO monitors whether staff involved in processing are made aware and trained. The Article does not on its own oblige the organization to train every employee. Our guide to the CIPP/E exam covers the DPO's role as the IAPP tests it.
Training obligation register
Law,Article,Does it apply to us? (yes or no and why),Who must be trained,What the text requires (summary),Applies since,Our measure,Owner,Evidence kept (where),Review date,Notes EU AI Act (Regulation (EU) 2024/1689),Article 4 as amended by Regulation (EU) 2026/1744,,Staff and other persons dealing with AI systems on our behalf,Take measures to support the development of AI literacy; no specific level required,2 February 2025,,,,,The Commission's Q&A says no certificate is needed; keep an internal record. EU AI Act (Regulation (EU) 2024/1689),Article 26(2),,People assigned to human oversight of high-risk AI systems,"Necessary competence, training and authority, and support",2 December 2027 (Annex III) or 2 August 2028 (Annex I),,,,,Only for deployers of high-risk AI systems. NIS2 (Directive (EU) 2022/2555),Article 20(2),,Members of the management body; employees (encouraged),Management body members required to follow training; entities encouraged to offer similar training to employees regularly,National transposing law (Member States to apply measures from 18 October 2024),,,,,A directive: check your national law for the exact duty. DORA (Regulation (EU) 2022/2554),Article 13(6),,All employees and senior management staff; ICT third-party service providers where appropriate,ICT security awareness programs and digital operational resilience training as compulsory modules,17 January 2025,,,,,Article 5(2)(g): the management body allocates and reviews the budget for this training. GDPR (Regulation (EU) 2016/679),Article 39(1)(b),,Staff involved in processing operations,The DPO monitors compliance including awareness-raising and training of staff,25 May 2018,,,,,A task of the DPO; not a free-standing duty to train all staff. ,,,,,,,,,, "Read from the Official Journal texts on 2 October 2026. Template from credentialpress.com/guides/eu-laws-that-require-staff-training. Not legal advice.",,,,,,,,,,
What does the AI Act add?
Article 4 requires providers and deployers of AI systems to "take measures to support the development of AI literacy" of their staff and others dealing with AI systems on their behalf. Since the July 2026 amendment, it says this "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". A separate duty in Article 26(2) requires deployers of high-risk AI systems to give the people who oversee them "the necessary competence, training and authority", from 2 December 2027 for Annex III systems. Our guide to Article 4 AI literacy covers both.
Do any of these laws require a certification?
No. All four require training, awareness programs or measures, and none names a certificate. For the AI Act, the Commission's Q&A says outright that "There is no need for a certificate." Certifications still have a place: they are one way to show that the people who design and run a training program, such as the security lead, the DPO or the AI governance lead, know the subject. Our role-by-role certification guide matches those people to credentials, and the certification cost guide prices them.
Are any of these duties about to change?
On 2 October 2026, the EU Publications Office recorded no adopted act amending NIS2, DORA or the GDPR. Two proposals were pending: the Commission's Digital Omnibus, COM(2025) 837, which proposes amending the GDPR and NIS2 among other acts, and COM(2026) 13, which proposes amending NIS2 and contains no change to Article 20. The AI Act has already been amended, by Regulation (EU) 2026/1744. Recheck before relying on this page in later months.
What should you do this week?
Open the register, mark which of the four laws apply to your organization, and record what training each group already receives. Where a law applies and the evidence column is empty, that is your first gap. For security and privacy leads who will run the program, the CISM book for security managers and the CIPP/E practice questions are on the teams page with the rest of the list.
Frequently asked questions
Does NIS2 require cybersecurity training for the board?
Yes. Article 20(2) of Directive (EU) 2022/2555 requires Member States to ensure that the members of the management bodies of essential and important entities are required to follow training. It also requires Member States to encourage those entities to offer similar training to employees on a regular basis. Because NIS2 is a directive, the exact duty is in each country's transposing law.
What training does DORA require?
Article 13(6) of Regulation (EU) 2022/2554 requires financial entities to make ICT security awareness programs and digital operational resilience training compulsory modules in staff training, for all employees and senior management, at a complexity matched to each person's role. DORA has applied since 17 January 2025.
Does the GDPR require staff training?
Article 39(1)(b) makes monitoring compliance, including awareness-raising and training of staff involved in processing operations, one of the data protection officer's tasks. It is a task of the DPO, not a free-standing duty to train every employee.
Does the EU AI Act require AI training?
Article 4, as amended in July 2026, requires providers and deployers of AI systems to take measures to support the development of AI literacy of their staff. It does not require any specific level of AI literacy, and the Commission says no certificate is needed.
Do these laws require a certification?
None of the four texts requires staff to hold a certification. They require training, awareness programs or measures. A certification can be one way to evidence competence for the people who run the program.
Have NIS2, DORA or the GDPR been amended?
Not on these points as of 2 October 2026. The EU Publications Office recorded no adopted amending act for any of the three. Proposals to amend NIS2 and the GDPR were pending, and should be checked before you rely on this page in later months.
Which books help the people who run these programs?

Certified Information Security Manager. 12 chapters, 342 pages.

Certified Information Privacy Professional, Europe. 18 chapters, 441 pages.
Sources
Every quotation above was read from the Official Journal text on 2 October 2026, through the EU Publications Office.
- Directive (EU) 2022/2555 (NIS2), OJ L 333, 27 December 2022, Articles 20 and 41
- Regulation (EU) 2022/2554 (DORA), OJ L 333, 27 December 2022, Articles 2, 5, 13 and 64
- Regulation (EU) 2016/679 (GDPR), OJ L 119, 4 May 2016, Articles 39 and 99
- Regulation (EU) 2024/1689 (AI Act), Articles 4 and 26, as amended by Regulation (EU) 2026/1744
- European Commission, AI Literacy: Questions and Answers
Credential Press is independent of the EU institutions and of every exam board named here. This is not legal advice.