Connect each record to a purpose
Start with the requirement or internal policy the activity is intended to support. Record the audience, learning objective, owner and review date. Different roles may need different training.
For organisations in scope, NIS2 addresses management-body training in Article 20 and includes cybersecurity training among the measures in Article 21. Applicability and detailed obligations depend on national implementation and your organisation’s circumstances.
Record the activity and its scope
Keep the training title, version, learning objective, assignment date and intended audience. Record what was delivered and when, including the language or accessible alternative used.
- Link the approved policy or programme objective.
- Record participation and completion separately.
- Document justified exceptions, such as leave or reassignment.
- Keep the owner and date of any content review.
Record the review and follow-up
Explain how you evaluated the activity and what you decided to change. A completion export alone does not demonstrate that the training was effective.
Keep a record of gaps, actions, owners and review dates. Use proportionate access controls and a retention policy for employee-level records. Do not publish identifiable employee results as marketing evidence.
Check the evidence before sharing it
Make sure dates, versions and audiences match across documents. Provide a short explanation of what each file establishes and what it does not.
This is an organisational checklist, not a prescribed legal evidence package or proof of NIS2 compliance. Have the responsible compliance adviser check the requirements that apply to you.
Your review checklist
Use this checklist during your review. Selections are not saved when you leave the page.