🚨  NIS2 is now in effect. Security awareness is now legally required in the EU.

Check compliance
Log in
NIS2 IS NOW IN EFFECT

New obligations. One place to meet them.

NIS2 introduces new requirements for security awareness, executive accountability, and incident reporting. Guardey helps your organization prepare for Articles 20 and 21 with continuous training for employees and leadership.

Fines up to €10 million or 2% of annual turnover
Guardey helps you close awareness gaps before an audit does.
Leadership is accountable
Executive training helps leadership understand and meet Article 20 responsibilities.
Security awareness training is mandatory
Continuous awareness training helps meet the employee requirements of Article 21.
Reporting is on a 24-hour clock
Train employees to recognize and report incidents before the clock starts.
TWO LAYERS OF TRAINING

Everyone has a role to play.

For your organisation

Security awareness training

Continuous security awareness training with three-minute challenges, phishing simulations, and audit-ready reporting. Helps meet the employee awareness requirements of Article 21.

FOR EXECUTIVE LEADERSHIP

NIS2 executive training

Short modules on what Article 20 requires of the management body, with a certificate you can use as evidence of director training.

MADE IN THE EU

Guardey is built and hosted entirely within the EU, so your training data stays under European jurisdiction. No transfers outside the EU, giving you clarity around data residency and GDPR.

Completing a 4-week streak in Guardey.
BUILT FOR ENGAGEMENT

Three-minute challenges keep employees coming back instead of dreading another mandatory course. Streaks, levels, and rewards turn security awareness into a lasting habit.

Example of the reporting dashboard in Guardey
AUDIT-READY REPORTING

Track completion, scores, and progress across your organization with audit-ready reporting that helps demonstrate your NIS2 awareness efforts.

FREE NIS2 COMPLIANCE CHECK

Do you need to comply with NIS2?

Answer 4 quick questions and find out in just 2 minutes.

Whitepaper

Download the NIS2 Compliance Guide 2026

Get your free 15-page guide covering everything you need to know about NIS2. Learn who needs to comply, understand the key requirements, follow a practical compliance checklist, and discover how to prepare your organization for NIS2.

Common NIS2 questions.

Does NIS2 apply to my organisation?

NIS2 covers essential and important entities across 18 sectors, including energy, transport, healthcare, banking, digital infrastructure and manufacturing. Size thresholds apply: generally 50+ staff or €10 million or more in turnover, though some sectors are covered regardless of size. The test tells you which category you fall into.

What is the difference between essential and important entities?

Both must meet the same security obligations. The difference is supervision: essential entities face proactive supervision and audits, important entities are supervised reactively after an incident. Fines differ too, up to €10 million or 2% of turnover for essential, up to €7 million or 1.4% for important.

Is security awareness training actually required?

Yes. Article 21 lists basic cyber hygiene practices and cybersecurity training among the minimum measures organisations must take. You need to be able to evidence it, which is where reporting matters.

What does NIS2 require of directors specifically?

Article 20 requires management bodies to approve the cybersecurity risk-management measures, oversee their implementation, and follow training themselves. Member states can hold leadership personally accountable for failures.

What are the reporting deadlines?

An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month.