---
title: "Compliance vs. Behavior Change: What Security Awareness Training Actually Satisfies Under NIS2, DORA, and ISO 27001"
description: "What NIS2, DORA, and ISO 27001 require from security awareness training, what auditors accept as evidence, and where compliance and behavior split."
category: "Deep dives"
date: 2026-08-20
canonical: https://www.brside.com/blog/security-awareness-training-compliance-nis2-dora-iso27001
source: "Brightside AI"
image: https://www.brside.com/assets/security-awareness-training-compliance-nis2-dora-iso27001.CEbb_MoT.jpg
---

# Compliance vs. Behavior Change: What Security Awareness Training Actually Satisfies Under NIS2, DORA, and ISO 27001

Your last audit passed with completion at 98%. The click rate on your phishing simulations hasn't moved in three cycles.

Both can be true at once. A security awareness program in a regulated organization is asked to produce two separate things: proof that the training happened, and proof that people behave differently when a real attack arrives. The first is what gets audited. The second decides whether the program was worth running.

NIS2, DORA, and ISO 27001:2022 all address employee training, and most coverage treats them as though they say the same thing. They don't. NIS2 mandates training for your board while treating staff training as a proportionate risk measure. DORA calls it compulsory in the text. ISO splits the obligation across two mandatory clauses and a control you choose to apply.

What follows is the actual text of each, what an auditor accepts as evidence, what the research says about changing behavior, and which clauses already let behavioral data do compliance work.

## Key Takeaways

- NIS2 directly requires training for management bodies. Staff training is obligatory through Article 21(2)(g), with its intensity set by the proportionality test in Article 21(1).
- DORA is the only one of the three whose text calls training compulsory, and the only one that pushes it beyond your headcount to ICT third-party providers.
- ISO 27001:2022 splits the obligation: clauses 7.2 and 7.3 say "shall," while Annex A 6.3 says "should" and binds through your Statement of Applicability.
- The evidence auditors are guided to look for is programme documentation and per-employee completion records. Nothing in it measures whether the training worked.
- Effectiveness assessment is already required for role-specific training under Implementing Regulation 2024/2690, and available under NIS2 Article 21(2)(f) and ISO clause 9.1, which makes behavioral measurement an auditable deliverable.

## The Two Files Every Training Program Produces

Think of your awareness program as generating two files.

The **audit file** holds the programme outline, syllabus, delivery schedule, per-employee completion records, quiz scores, and policy acknowledgements. It answers one question: did the required people receive the required training on the required cadence? It's exportable and largely binary.

The **risk file** holds click rate, credential submission rate, report rate, time to report, [role-weighted failure rate](/blog/human-risk-scoring-best-practices), and repeat-clicker behavior. It answers a different question: when someone tried to manipulate your staff, what did they do? It's noisy and it resists a simple pass or fail.

Both files are legitimate, and mature programs produce both. Most produce only the first, which isn't laziness. It's a rational response to how the frameworks and their evidence expectations are written.

## NIS2 Mandates Board Training and Leaves Staff Training to Proportionality

One sentence in the directive gets paraphrased incorrectly more often than any other.

[Article 20(2) of the NIS 2 Directive](https://www.nis-2-directive.com/NIS_2_Directive_Article_20.html) says Member States "shall ensure that the members of the management bodies of essential and important entities are required to follow training, and shall **encourage** essential and important entities to offer similar training to their employees on a regular basis."

Training for your management body is required. Training for your employees is encouraged. If Article 20(2) were the whole story, your all-staff module would be optional and your board's training would be the compliance gap.

It isn't the whole story. The staff obligation lives one article later. [Article 21(2)(g)](https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html) lists "basic cyber hygiene practices and cybersecurity training" among the ten minimum measures every essential and important entity must take. Employee training is obligatory, but it arrives as a risk-management measure rather than as a standalone training rule.

Article 21(1) then subjects those measures to a proportionality test covering "the state-of-the-art," cost of implementation, "the degree of the entity's exposure to risks, the entity's size and the likelihood of occurrence of incidents and their severity." How much training you owe is a function of your risk profile, and the directive prescribes no curriculum and no frequency.

### Where the specifics live, and who they bind

The concrete requirements sit in [Commission Implementing Regulation (EU) 2024/2690](https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj/eng), adopted 17 October 2024. Before using it, check whether it binds you. It applies to DNS providers, TLD registries, cloud computing, data centre and content delivery network providers, managed service and managed security service providers, online marketplaces, search engines, social networking platforms, and trust service providers. If you're a hospital or a water utility under NIS2, this regulation doesn't set your requirements; your national transposition does. It remains the clearest available benchmark and auditors reference it, but it isn't automatically your rulebook.

Annex section 8 splits training in two, and the split is worth reading closely.

**Section 8.1** covers awareness raising and basic cyber hygiene for everyone. The programme must reach all employees including management body members, and direct suppliers where appropriate. It must be "scheduled over time, so that the activities are repeated and cover new employees," aligned to your security policies, and cover the measures in place, contact points, and cyber hygiene practices. One annual session doesn't satisfy "repeated."

**Section 8.2** covers role-specific security training: identify which roles require security-relevant skill sets, [build a programme defining needs per role](/blog/enterprise-security-awareness-training-for-large-teams), apply it when staff transfer into those roles, and run it periodically.

Now compare the two effectiveness clauses. Section 8.1.3: the awareness programme "shall, **where appropriate**, be tested in terms of effectiveness." Section 8.2.3: role-specific training "shall be relevant to the job function of the employee and its effectiveness **shall be assessed**."

Conditional for the all-staff programme. Unconditional for role-specific training. Most organizations build their measurement the other way round, running detailed phishing simulation analytics across the whole workforce while their privileged-access and finance-role training gets a completion checkbox.

## DORA Is the Only Framework That Calls Training Compulsory

If you're a financial entity, you have the most explicit training mandate of the three, and it's the one that gets written about least.

[Article 13(6) of DORA](https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng) states that financial entities "shall develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes." Those programmes apply "to all employees and to senior management staff," and must have "a level of complexity commensurate to the remit of their functions." Where appropriate, financial entities must also include ICT third-party service providers in their training schemes.

Three things separate this from NIS2. The word *compulsory* appears in the text. There's no proportionality carve-out on whether to train, only on how deep the training goes. And the scope reaches past your own payroll into your supply chain, which is rarely reflected in seat-based platform procurement.

"Commensurate to the remit of their functions" deserves more attention than it gets. It's a direct textual instruction to differentiate by role. A payments operations analyst and a marketing coordinator sit under the same obligation at different depths, and one universal module leaves the first under-trained and the second over-trained.

Article 13 sits within DORA's chapter on learning and evolving, alongside post-incident review and threat intelligence. The placement frames training as part of how a financial entity improves rather than as an annual administrative event.

DORA adds a separate personal duty for leadership. Article 5(4) requires management body members to "actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk and its impact on the operations of the financial entity, including by following specific training on a regular basis, commensurate to the ICT risk being managed."

One more thing distinguishes DORA in practice: it's a regulation, not a directive, and it has applied since 17 January 2025. There's no transposition gap and no national variation to track. NIS2 obligations arrive on each Member State's own timetable. The transposition deadline was 17 October 2024, and on 8 July 2026 the European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice for failing to notify full transposition, asking the Court to impose a lump sum and daily penalty payments.

## ISO 27001:2022 Splits the Obligation Across Three Places

ISO is where precision matters most, because the standard uses two different verbs and a lot of published guidance blurs them.

**Clause 7.2, Competence**, is a mandatory ISMS requirement: the organization shall determine the necessary competence for people whose work affects information security performance, ensure they are competent, and retain documented information as evidence. It's role-specific and evidence-bearing.

**Clause 7.3, Awareness**, is also mandatory, and universal. Everyone under the organization's control must be aware of the information security policy, their contribution to the ISMS, and the implications of not conforming.

**Annex A 6.3** is the named awareness control: "Personnel of the organisation and relevant interested parties should receive appropriate information security awareness, education and training and regular updates of the organisation's information security policy, topic-specific policies and procedures, as relevant for their job function." (The standard is paywalled, so that control sentence is quoted here and nothing more.)

Annex A controls say *should*, and they become binding for your organization through your Statement of Applicability, where you declare which controls you've applied and justify any exclusions. Saying "ISO 27001 requires A.6.3" without that step is the kind of imprecision an experienced auditor will pick up on.

The practical failure mode is treating 7.2 and 7.3 as one requirement. A finance team that has acknowledged the security policy satisfies 7.3 and tells you nothing about 7.2. Competence for a role handling payment authorization is a separate determination requiring separate evidence, and it's a well-known source of nonconformity findings.

**Clause 9.1** is the fourth piece, and the one that reopens this whole question further down: it requires the organization to evaluate its information security performance and the effectiveness of the ISMS.

## What an Auditor Asks to See

The two files come apart here, and the clearest statement of it comes from the EU's own cybersecurity agency rather than from any critic of the training industry.

ENISA's [Technical Implementation Guidance on Cybersecurity Risk Management Measures](https://www.enisa.europa.eu/sites/default/files/2025-06/ENISA_Technical_implementation_guidance_on_cybersecurity_risk_management_measures_version_1.0.pdf) (June 2025) accompanies Implementing Regulation 2024/2690 and lists, requirement by requirement, the evidence that a measure is in place. For the awareness programme under 8.1, its examples of evidence are a programme outline "detailing its objectives, content, frequency, syllabus and schedule," and "logs, sign-in sheet, certificates of completion or acknowledgements given to employees upon completing the programme, showing which employees have taken part." For staff transferring into security-relevant roles, the same pattern applies plus evidence that certifications have been maintained.

The sharpest detail sits elsewhere in the same document. Among ENISA's indicative example KPIs for assessing the effectiveness of cybersecurity risk-management measures is "the number of employees who have attended cybersecurity trainings." Attendance is offered there as a measure of effectiveness.

The frameworks themselves are more demanding than that suggests, and DORA's "compulsory" and the Implementing Regulation's "shall be assessed" carry real teeth. But the evidence conventions that grew up around these requirements are overwhelmingly completion-based. Produce a defensible audit file and you've satisfied the people reviewing you. Nothing in that evidence list asks whether anyone's behavior changed.

One caveat on using this guidance: ENISA states its document is "not legally binding and is only of an advisory character," so cite it for evidence expectations rather than as law.

## What the Research Says Changes Behavior

The other file has a literature behind it, and it's more equivocal than either the vendors or the skeptics tend to admit.

The most useful single source is a peer-reviewed scoping review in *Computers & Security* ([doi 10.1016/j.cose.2023.103695](https://doi.org/10.1016/j.cose.2023.103695), open access) synthesizing the evidence for email phishing training. Two findings matter here. First, current methods leave roughly 23% of users susceptible, a figure drawn across heterogeneous studies rather than measured in one population. Second, and more relevant to program design: "annualised programs are unlikely to provide sustained protection." Most studies, the review notes, don't measure retention beyond the immediate term at all.

The same review is specific about what improves outcomes: active engagement, repeated practice, and process-based feedback, with attentional awareness reducing susceptibility further. That's a design specification, and it maps poorly onto a once-yearly video module. It also explains a good deal about [why phishing simulations fail](/blog/why-phishing-simulations-fail-realistic-simulation-2026) to move numbers that matter.

A meta-analysis of training effects on end users adds nuance in the other direction. Training does produce a positive effect overall. But behavioral effects are consistently smaller than effects on knowledge and intention, and they shrink further under stronger study designs. People learn; whether they act differently under pressure is a separate and harder question.

Academic work has named the mechanism directly. In a 2025 paper based on interviews with 20 CISOs and awareness professionals, Nurse, Milward and Alashe (the first author holds a joint University of Kent and CybSafe appointment, with the co-authors at CybSafe, which sells human risk management software) observe that awareness training has suffered from "a focus on compliance over behavior change, and a lack of proven long-term effectiveness." Their conclusion reads as a diagnosis of regulatory design: requirements embedded in regulations and standards "have tended to emphasize structured training programs and periodic awareness activities rather than measurable improvements in human behavior."

Both overreaches are worth resisting. Training isn't useless, and it works considerably better when built around practice and feedback. Completion still isn't evidence, because the same body of work is unambiguous that finishing a module predicts very little about conduct.

## Where the Frameworks Already Let Behavior Count as Evidence

Every one of these frameworks contains a clause that makes behavioral measurement an auditable deliverable. They just aren't the training clauses, which is why they get missed.

| What you want to measure | Clause | What it says |
|---|---|---|
| Effectiveness of your risk-management measures, training included | NIS2 Article 21(2)(f) | Requires "policies and procedures to assess the effectiveness of cybersecurity risk-management measures" |
| Effectiveness of role-specific security training | CIR 2024/2690 Annex 8.2.3 | Training effectiveness "shall be assessed." No conditional |
| Effectiveness of the all-staff awareness programme | CIR 2024/2690 Annex 8.1.3 | Tested for effectiveness "where appropriate" |
| Training depth differentiated by role | DORA Article 13(6) | Complexity "commensurate to the remit of their functions" |
| Current competence for a specific role | ISO 27001:2022 clause 7.2 | Determine required competence, ensure it, retain documented evidence |
| Overall programme and ISMS performance | ISO 27001:2022 clause 9.1 | Evaluate information security performance and ISMS effectiveness |

The table is a budget argument. Behavioral measurement isn't something you fund once compliance is handled. Under Article 21(2)(f) and Annex 8.2.3 it's part of what compliance means, and ISO clause 7.2 asks whether competence is current for the role, which a completion timestamp doesn't establish. Reported certification-body practice already accepts phishing simulation results showing improvement over time as competence evidence.

Most organizations running simulations already generate everything they'd need, then file it as an internal security metric and hand the auditor a completion export, because that's what the evidence list asked for. Presenting the same data against clause 7.2, Article 21(2)(f), and Annex 8.2.3 costs nothing and produces a materially stronger audit position. What it requires is [measuring more than click rate](/blog/how-to-measure-security-awareness-training-effectiveness), since reporting rate and time-to-report carry most of the signal about whether behavior has actually shifted.

## Security Awareness Platforms Judged on Evidence Quality

If you're buying for a regulated environment, the useful evaluation questions aren't about library size. They're narrower: what can this platform hand an auditor without manual reconstruction, can it differentiate by role, and will its behavioral data survive scrutiny? Five platforms below, alphabetically; for a wider field, see this [breakdown of security awareness training platforms](/blog/best-security-awareness-training-platforms-for-2026).

### Brightside AI

Brightside builds each course around one primary goal: topic awareness, behavior change, or compliance knowledge, with a distinct methodology for each. That separation lets you plan which part of your program produces which file.

Both evidence sets come out of one platform: completion, pass, and coverage rates on the compliance side; click rate, credential submission rate, report rate, NIST-weighted failure rate, and month-over-month trend on the behavioral side, per employee, group, and company. Simulations align to NIST Phish Scale difficulty bands, so failure rates carry difficulty context instead of drifting with lure quality.

Two details matter for audit defensibility. Hidden honeypot links separate security-scanner clicks from human clicks, so mail gateways can't inflate your numbers or falsely fail someone who never saw the message. Historical metrics are point-in-time, so last quarter's figures reflect who was actually employed then.

**Pros**

- Compliance and behavioral evidence from one system, exportable per employee, group, or company
- Evidence-integrity mechanisms that hold up under questioning: honeypot filtering, point-in-time history, admin audit logging
- Role differentiation through dynamic groups, supporting DORA's "commensurate to the remit" language
- PDF dashboard exports suited to board reporting under NIS2 Article 20(1) and DORA Article 5(4)
- Follow-up training triggers automatically on simulation failure, matching the process-based feedback the research points to

**Cons**

- Curricula and simulations run one-time, quarterly, or yearly. There's no continuous-delivery mode, so cadence depends on quarterly scheduling plus failure-triggered follow-ups
- Smaller content library than the large incumbents
- AI OSINT spear-phishing and AI vishing sit in the Pro tier, with vishing also available as an add-on
- Video deepfake simulations are a managed service scoped per engagement rather than self-serve

### Hoxhunt

Hoxhunt sells behavior change more explicitly than anyone else in the category: adaptive phishing that adjusts difficulty per person, gamified learning, and remediation workflows connected to the SOC. If your stated goal is moving the risk file, it's the most philosophically aligned option here.

**Pros**

- Adaptive per-user difficulty rather than uniform campaigns
- Strong engagement model and behavioral reporting
- Reporting workflows that feed real incident response

**Cons**

- Enterprise-oriented, which shows in cost and implementation effort
- Compliance-specific content is less of a focus than at the incumbents

### KnowBe4

KnowBe4 is the default in compliance-driven procurement, and its strengths are real for this audience: the largest content library in the category, extensive compliance-specific modules, and reporting built for handing evidence to auditors. If your binding constraint is a well-documented audit file across a large, varied workforce, this is the mature answer.

**Pros**

- Largest content library, with broad compliance-specific coverage
- Reporting designed around audit evidence and completion tracking
- Deep localization and a mature enterprise feature set

**Cons**

- Volume-oriented content that some teams find generic
- Behavioral realism in simulations lags the newer AI-era specialists

### Proofpoint

Proofpoint fits organizations already running its email security stack. Training connects to threat intelligence from the wider platform, so simulation can target the people actually being attacked rather than everyone equally.

**Pros**

- Training driven by real threat telemetry from the surrounding stack
- Strong fit where Proofpoint email security is already deployed
- Enterprise reporting and established compliance workflows

**Cons**

- Value depends heavily on adopting the broader Proofpoint stack
- Less differentiated as a standalone awareness purchase

### SoSafe

SoSafe is the European comparison most buyers here will expect: behavior-science-led program design, strong EU market presence, and localization depth that matters for multinational workforces under NIS2.

**Pros**

- Behavior-science-driven program design
- Strong European market presence and language coverage
- Well-developed reporting and human risk metrics

**Cons**

- Less depth on voice and synthetic-media simulation than the specialists
- Enterprise-weighted pricing and onboarding

Capability details change quickly here. Verify current feature sets and packaging directly with any vendor, particularly where a control maps to an obligation you're relying on.

## Frequently Asked Questions

**Can one security awareness training programme satisfy NIS2, DORA, and ISO 27001 at the same time?**

Largely yes on content, with two conditions. The frameworks differ on who is mandated, at what depth, and with what effectiveness assessment, so a single programme needs real role differentiation. And it needs an evidence layer answering three different audits: ISO asks about competence per role, DORA about compulsory modules scaled to function, NIS2 about proportionality to your risk profile.

**Does NIS2 require annual security awareness training for all employees?**

Not in those terms. NIS2 sets no frequency for staff training. Article 20(2) requires training for management body members and encourages employee training; Article 21(2)(g) makes staff training obligatory as a minimum risk-management measure, with the appropriate level set by the proportionality test in Article 21(1). Where Implementing Regulation 2024/2690 applies, the awareness programme must be scheduled so activities repeat and cover new employees, which rules out a one-off.

**What evidence does an auditor actually ask for to prove awareness training took place?**

Per ENISA's guidance: a programme outline covering objectives, content, frequency, syllabus, and schedule, plus logs, sign-in sheets, certificates of completion, or acknowledgements showing which employees took part. For staff moving into security-relevant roles, records of role-appropriate training and maintained certifications.

**Do phishing simulation results count as compliance evidence?**

Yes, and they're underused. Reported certification-body practice accepts simulation results showing improvement over time as ISO 27001 clause 7.2 competence evidence. They also support NIS2 Article 21(2)(f) and, where Implementing Regulation 2024/2690 applies, Annex 8.2.3's requirement that role-specific training effectiveness be assessed. The data is most defensible when it separates scanner activity from human clicks and preserves point-in-time population figures.

**Does DORA training apply to contractors and ICT third-party providers?**

Article 13(6) requires financial entities to include ICT third-party service providers in their relevant training schemes where appropriate. Training scope under DORA can therefore exceed your own headcount, which is worth checking against seat-based licensing before you buy.

This article summarizes framework requirements for planning purposes and is not legal advice. NIS2 is implemented through national law and the details differ by Member State, so confirm your specific obligations against your national transposition and with your own counsel.
