The training duty under Sec. 38 BSIG: what management has to prove

Since 6 December 2025, the German BSI Act contains a sentence that puts responsibility for cybersecurity where it belongs anyway: with executive management. Sec. 38 (3) BSIG requires management to attend training regularly. That means management itself, not IT and not the information security officer.

Most companies in scope read that, ticked it off and moved on. Then a customer request, an audit or the regulator turns up and somebody asks for the evidence. And the evidence is the actual work.

What Sec. 38 BSIG asks of management

The provision sets out three duties, none of which can be delegated. Management has to implement the risk management measures, it has to oversee that implementation, and it has to be trained. The liability for this is personal.

Behind it sits a simple assumption: whoever decides on budgets and risks has to understand what they are deciding on. A board member who signs off on accepting a residual risk without knowing the terms in it is not deciding, they are signing.

The duty applies to the management of important and essential entities. Which one you are depends on sector, headcount and turnover. If you are unsure, that is the first question, not the training.

What "regularly" means

The law sets no interval. It says regularly and leaves the interpretation to you. That sounds relaxed, but it is not: you have to be able to justify your interval later.

The BSI has published guidance on this that serves as orientation. The core idea: a thorough initial session, then regular refreshers. We treat an annual rhythm as the one you can defend without much thought, because it attaches to cycles that already exist, the management review or the budget round.

A three-year interval is hard to defend when the law, the threat landscape and your own IT have all changed in the meantime. And they have.

The part almost everyone underestimates: the evidence

A training session that happened but was not documented does not exist for the regulator. The BSI recommends recording at least participants, time, duration and content. The documentation stays in house and is handed over on request.

In practice that means a file with:

  • Who delivered the training, internal or external
  • Who took part, with name and role
  • Date, time, duration
  • Which content was covered, referenced to the legal requirements
  • In which format, on site, online, as e-learning

That is a small effort when you do it on the day. It is a very large effort when you have to reconstruct it two years later because a customer asks as part of their supply chain review.

Why the e-learning certificate often falls short

A video with multiple choice at the end produces a certificate of attendance. That is convenient and formally satisfies something. Nobody checks, though, whether your leadership can assess its own risks afterwards.

The difference shows up in an incident. Knowing the definition of a significant security incident is one thing. Deciding under time pressure that this incident gets reported although not all the facts are on the table is another. The 24-hour deadline for the early warning to the BSI runs from the moment you become aware, not from the moment you are certain.

Whoever has rehearsed that decision once makes it faster for real. Whoever has only read about it spends the first two hours debating.

What the sanctions actually mean

Sec. 65 BSIG provides for fines of up to EUR 10 million or 2 percent of worldwide annual turnover for essential entities, and up to EUR 7 million or 1.4 percent for important ones. These numbers appear in every talk on the subject, and they are honestly the least interesting part.

The personal level is more interesting. When an incident is investigated and the question comes up whether management met its duties, the training documentation is one of the few pieces of paper you either have or you do not. It is documented diligence. And it costs half a day a year.

A practical start

If this is open in your company, you do not need a roadmap, you need four answers:

  • Are we an important or an essential entity, and is that documented?
  • Who counts as executive management under the law, and which of them has been trained?
  • Do we have documentation we could put in front of the BSI on request?
  • When is the next session, and is it in the calendar?

The fourth question decides. Everything else is preparation.

How we set up a session like that is on the page for NIS2 training for executive management. If there is no management system underneath yet, the work starts one level down anyway, with an ISMS to ISO 27001.

Frequently asked questions

How often does management have to be trained under Sec. 38 BSIG?

The law only says regularly. The BSI recommends a thorough initial session followed by regular refreshers. As anchors it names a change in management and significant changes in business processes, risk exposure or measures.

Can the training duty be delegated?

No. Sec. 38 BSIG addresses management itself, and liability for culpably caused damage is personal. The information security officer supplies the input, decisions about risks stay with management.

What has to be documented as evidence?

The BSI names at minimum the training provider or internal unit, participants with name and role, date, time and duration, and the content and formats covered with a reference to Sec. 38 (3) BSIG. The documentation is kept internally and handed over on request.