Is security awareness training mandatory in the installation sector?
If your installation company falls under the NIS2 Directive, employee awareness is part of the measures that the duty of care expects from you. The Directive explicitly names education and awareness as part of the cybersecurity measures that an essential or important entity must take. In addition, there is a separate obligation specifically targeted at managers, and these two are often confused in practice.
The difference lies in who is obligated and how strict that obligation is. For employees in general, the Directive speaks of appropriate and proportionate measures, with training being one of the named elements within the broader duty of care under Article 21. For managers and other members of the governing body, there is a separate, personal obligation to undergo training themselves in order to recognise and assess cyber risks. This is not optional advice, but a requirement for the persons responsible for approving the policy.
Why this distinction is relevant for an installation company
In an installation company, there are mechanics on site, a scheduling department, administrative staff, and usually one or a few directors who run day-to-day operations. For the group of employees, awareness is mainly about recognisable risks: phishing emails posing as a supplier or client, suspicious requests for login credentials, and careful handling of access to customer and project data on mobile devices in company vans. The duty of care requires that this type of training happens periodically and that you can demonstrate that it does happen, not that there is a fixed minimum number of hours per year.
For the management or owner of the company, the bar is set somewhat differently. That person must be able to recognise risks themselves and properly approve the policy that follows from them. This does not mean the manager must become a technical expert, but they must understand what the main risks for the business are and why certain measures are necessary. This obligation is separate from what is organised for employees and therefore cannot be replaced by, for example, only a general phishing test for the entire team.
What this means in practice for your file
Because training is part of the duty of care, every training activity must be documented: who attended the training, when, and what was the content. This applies both to general employee awareness and to the training that managers undergo. A casual email with tips does not count as evidence; a record with participants, date and subject does. the ten measures of the duty of care outlined provides an overview of where training fits exactly and how it relates to other obligations such as access control and incident reporting.
For companies that are affected through the supply chain, without being obligated themselves, this topic also plays a role. A client who themselves falls under NIS2 can ask in a security questionnaire whether employees are regularly made aware of cyber risks and whether this has been documented. An installation company working as a subcontractor for an energy company or a hospital often receives this question back, even without being obligated itself.
Whether your company is itself subject to the duty of care, subject to the management obligation, or only has to deal with training through a client depends on the sector, the size and the role in the supply chain. in a few questions see where your company stands provides an initial indication, with explanation as to why. Frequently asked questions about what precisely falls under training and whether a certificate is required are compiled in one place in the frequently asked questions.
No training without documentation, no documentation without dossier
The core for an installation company is therefore simple to remember: employee awareness is part of the broader duty of care, training of senior management is a separate, personal obligation. Both call for documentation that you can present to a competent authority or to a client who requests it. For the exact wording and the location in the official text, we refer you to the directive itself and to the national transposition that applies in your country.
Would you like a clear picture for your own installation company of what has already been arranged and what is still missing? Start with the free NIS2 check or create a business account to build up the dossier as soon as you know which measures apply to your situation.