These are the 8 key points this article covers on how to create a corporate training plan for ISO 27001, NIS2 and GDPR:
- Why training is not “extra”, but a compliance requirement
- What ISO 27001 requires for competence and awareness
- What NIS2 requires from management bodies and reinforces for employees
- What GDPR turns into training for teams that handle data
- How to design the plan by roles: scope, content, and cadence
- What evidence auditors will ask for: records, materials, and evaluation
- How to keep the plan alive: onboarding and post-incident learning
- Common mistakes that can slow you down and how to fix them
When an organisation grows, the risk does not grow only in technology.
It also grows in people: what they know, what they repeat without thinking, and what they cannot do when an incident happens.
A well-designed corporate training plan turns that risk into an advantage: it helps you demonstrate control and operate consistently.
What ISO 27001, NIS2 and GDPR require on training
The shared idea is simple.
Regulations do not expect you to “give a talk”.
They expect you to prove that people are competent, aware, and that you know how to maintain training over time.
ISO 27001: competence and awareness, with evidence
ISO/IEC 27001 expects organisations to determine the competence people need for their roles, take action where needed, and ensure that people are aware of the security policy, their contribution, and the consequences of not following procedures.
It also follows a continuous-improvement approach.
The standard does not prescribe one universal course or training timetable. The right approach depends on the role, the ISMS scope, and the risks the person can influence.
To go deeper into the standard, review ISO/IEC 27001:2022 – Information security management systems.
NIS2: training as part of organisational resilience
With NIS2, training stops being only a “cybersecurity topic” and becomes an element of governance.
Article 20 requires Member States to ensure that management bodies of essential and important entities approve and oversee cybersecurity risk-management measures, and that their members follow training. It also encourages entities to offer similar training to employees on a regular basis.
This does not create one universal employee syllabus or fixed calendar for every organisation. Training should be proportionate to the organisation’s risks, roles, sector, and applicable national transposition rules.
Directive (EU) 2022/2555 strengthens training and oversight so the organisation manages cybersecurity risk in an operational way.
You can consult the text in Directive (EU) 2022/2555 on NIS2.
To understand the core NIS2 expectations and whether your organisation is in scope, see what is NIS2 and who needs to comply.
For a more practical breakdown of NIS2 training and awareness by audience, see what training employees need to comply with NIS2.
GDPR: practical training for teams that handle personal data
GDPR does not prescribe a single syllabus.
But it does require proactive accountability and that people who process personal data do so with knowledge of their obligations.
Where a Data Protection Officer is required, Article 39 specifically includes awareness-raising and training of staff involved in processing activities among the DPO’s monitoring tasks. In practice, the training should reflect the organisation’s processing activities and risks.
In practice, that translates into training that reaches day-to-day work:
- what “personal information” is;
- how to act in incidents; and
- how to execute data subject rights with internal traceability.
To align privacy training with audit expectations, use what should a GDPR audit include.
How the three frameworks fit into one plan, without mixing concepts
You do not need three separate plans if you define the map of requirements well.
ISO 27001 asks for competence and awareness regarding information security and the consequences of non-compliance.
NIS2 reinforces that cybersecurity is an organisational responsibility and that training forms part of resilience.
GDPR requires that anyone processing personal data does so with judgement and knowledge of basic obligations.
In practice, a solid corporate plan answers three questions in parallel:
Does the person know what to protect? Does the person know how to act when an incident happens? And can you demonstrate it with consistent records?
Design the plan by roles: scope, content, and audit-ready cadence
The first mistake is “a course for everyone”. Role-based training is the most direct way to make it relevant. And relevance is what an auditor recognises as a control.
1) Define the scope: who is included
It is not only internal template work.
It includes people under your control: employees, collaborators, contractors, temporary staff, and profiles that handle data or critical systems.
Here, it is key to document which teams are included—and why.
2) Map content by role type
A practical way to structure training is with three layers:
- Corporate layer: minimums for everyone, including security hygiene, phishing and reporting, basic information handling, and the use of approved tools.
- Role layer: what each team truly does, such as HR, Sales, Support, Operations, IT, or SecOps.
- Risk layer: short reinforcements when new vectors appear, such as changes in tools, providers, incidents, or near-misses.
3) Set a cadence you can actually maintain
A credible plan has frequency.
For it to be auditable, a common reference is:
- Onboarding in the first weeks;
- Annual refreshers as a baseline;
- Quarterly micro-sessions focused on current risks; and
- Updates after incidents when there is demonstrable learning.
These are practical examples, not universal legal minimums. Your cadence should be risk-based, feasible for the organisation, and documented consistently.
You do not need to turn this into an infinite project.
You need it to be repeatable, and the calendar must have an owner.
Example of a minimal matrix per area
The matrix does not have to be perfect on day one.
It must be honest and auditable.
A simple version can look like this:
| Area or audience | Main training focus | Evidence to retain | Practical refresh model |
|---|---|---|---|
| Leadership / governance body | Cybersecurity risks, oversight, incident decisions, supplier risk, and communications | Attendance, agenda, materials, decisions or actions | Onboarding into the role, then risk-based refreshers |
| HR | Employee data, onboarding and offboarding, secure channels, and privacy responsibilities | Completion record, materials, assessment | Onboarding plus annual review |
| Sales and marketing | Customer and lead data, external sharing, urgent requests, and approved tools | Completion record, scenario exercise | Annual refresher and campaign-specific updates |
| Customer support | Identity verification, access requests, resets, escalation, and data-leak prevention | Completion record, assessment, quality checks | Onboarding plus periodic scenarios |
| Operations and administration | Shared files, providers, billing, and sensitive documentation | Attendance, materials, policy acknowledgement | Annual refresher and process-change updates |
| IT / SecOps | Operational controls, privileges, incident records, backups, and continuity | Role-based records, technical exercise, review results | Role- and risk-based refreshers |
If you document which module each area receives, how often, and what evidence it generates, you will have an artefact that holds up when audit questions come.
Evidence an auditor will ask for, and how to prepare it
Technology can fail. People can fail too.
What ISO, NIS2, and GDPR look for is that you have evidence that you train and that training is maintained and improved.
In an audit-ready approach, prepare at minimum:
- Plan: scope, audiences, objectives per role, periodicity, and responsible owners;
- Delivery records: dates, attendees, onboarding or offboarding events, materials used, and format;
- Evidence of understanding: a short quiz, simulation, or scenario response;
- Evidence of updates: content versioning, changes triggered by incidents, or contextual changes.
Completion proves that training was delivered. Assessments, simulations, interviews, and recurring error patterns help demonstrate whether it was understood and effective.
If your roadmap is aligned with ISO 27001 certification, you may find it useful to review how to obtain ISO 27001 certification as a startup in the EU.
In audits, value is about coherence.
If your plan says you train every quarter but records show otherwise, the problem is not “the year, “ it is traceability.
What they typically ask in a document review
It is not an exhaustive legal list, but it is often the minimum credible set:
- Current version of the plan and its approval date;
- Executed calendar with real dates;
- Attendance lists or equivalent LMS records;
- The materials used;
- Evaluation results or simulations;
- Onboarding evidence for recent hires; and
- A record of content changes and why they were made.
If you can reconstruct the history with records or tickets without relying on one person’s memory, you are on the right track.
For a more detailed audit-evidence model, see how to prove in an audit that your staff is properly trained.
Sampling in interviews: what an auditor evaluates
Many audits do not stay in the file.
They ask people in different departments if they know who to notify, where the procedure is, and what they should not do.
If the plan exists but reality does not match it, a gap appears.
A useful internal check is to select a few people across roles, compare their required modules with the training register, trace their completion to the relevant material, and document any missing evidence or remediation.
Onboarding and continuous learning: how to keep training alive
Training that “happened once” is not training.
It is an event.
To make it work as a control, you need a continuous chain: input, reinforcement, learning, and improvement.
Onboarding: minimum from day one
Every new hire should receive a basic package.
The key is not to overwhelm people, but to make sure they understand which behaviours are expected and how to report risk signals without waiting to “learn more”.
Quarterly micro-sessions, without bureaucracy
A short micro-session can be enough if it is connected to what happens in the quarter.
Typical examples:
- A phishing campaign observed;
- An improvement in procedures; or
- A change in tools used to share information.
Post-incident learning: training as remediation
When an incident or near-miss happens, the plan should reflect it.
This is not only about repeating the course.
It is about demonstrating:
- What failed;
- What was corrected; and
- What people learned so it does not happen again.
Providers, subcontractors, and temporary access
If a provider accesses relevant systems or data, the human risk also exists outside the employee population.
You may not be able to train them in the same way as employees, but you can still define minimum requirements: limited access, policy acceptance, mandatory short training where applicable, and compliance evidence when relevant.
This reduces the typical gap: “we train internally”, but the provider enters without briefing.
How to integrate the training plan without duplicating work
A corporate training plan does not live in isolation.
It integrates into your management system and how you manage risk.
The goal is that the same artifact provides both internal coherence and audit readiness.
Integrate with your security and risk management
If you already have an ISMS or risk-management system, look for responsibilities and roles already defined, review calendars, internal audit mechanisms, non-conformity management, and corrective actions.
Training fits there as living evidence of competence and awareness.
Unify what overlaps across the three frameworks
Although ISO 27001, NIS2, and GDPR are not the same, they share logic:
Train, document, and maintain.
A single role matrix can cover corporate minimums, team modules, and updates when risk changes.
That prevents each framework from asking you for another different plan.
Annual plan review: what must change
Once a year, or when the context changes, review:
- Whether roles are still the same;
- Whether tools changed;
- Whether there were incidents or near-misses requiring a new module; and
- Whether responsible owners are still correct.
Document the review as a decision: date, participants, and applied changes.
That is exactly the kind of continuous-improvement signal that fits ISO 27001 and mature risk management.
Roles and responsibilities: who owns the plan
A plan fails when no one owns the calendar.
Define at least:
- An owner for the programme;
- Module owners by area or topic; and
- An escalation mechanism when someone detects a gap.
This is not bureaucracy for the sake of bureaucracy.
It is the simplest way to ensure training does not depend on one person—and does not pause during holidays.
Spain: FUNDAE as an execution lever, when it fits
In Spain, many organisations can leverage subsidised training schemes for programmes aligned with cybersecurity and privacy.
Eligibility, available credit, delivery conditions, and documentary requirements depend on the applicable rules and the organisation’s circumstances. FUNDAE explains that companies may organise training directly or appoint an external organising entity.
It does not replace plan design or regulatory evidence, but it can help you maintain cadence across large teams.
If you use funding, keep documentary discipline: what was delivered, to whom, when, and with what outcome. Review the current conditions directly through FUNDAE’s guidance for companies.
How PrivaLex can help with a corporate training plan
At PrivaLex, we design and structure training plans so you can address ISO 27001, NIS2, and GDPR in an integrated way.
We focus on ensuring the plan is:
- Relevant by role, not a generic course;
- Auditable, with coherent records and evidence;
- Operational, including onboarding and post-incident learning; and
- Sustainable, with a cadence you can truly maintain.
We also help review existing training materials and evidence so they reflect your actual tools, procedures, reporting routes, and risk profile. Where needed, we can structure registers for attendance, completion, assessments, content versions, and corrective actions, so the programme is not dependent on one person’s memory or scattered files.
If you operate in Spain, PrivaLex can also support the FUNDAE process where it is applicable and eligible. The result is a training plan that is relevant by role, sustainable in day-to-day operations, and ready to support audit or certification preparation.
Schedule a strategic session with PrivaLex and review your starting point.
4 common mistakes that can slow you down
1) Limiting training to IT or leadership
If you only have IT records or you only train leadership, the plan leaves a visible gap.
Incidents often start in everyday processes and non-technical teams.
2) Not defining scope and audiences by role
A plan without a role mapping does not allow you to prove proportionality.
The auditor must see why each team receives the content they receive.
3) Not documenting evidence
When there are no traceable records, the plan becomes declarative.
ISO, NIS2, and GDPR rely on your ability to show that training happened and was effective.
4) Not updating the plan after changes or incidents
If tools, providers, or new vectors appear, training must evolve.
A static plan contradicts the continuous-improvement logic.
Next step
A corporate training plan is not simply a calendar of courses.
It is evidence that your people understand their responsibilities, know how to act, and receive updates when risk changes.
If you want to assess whether your current programme is audit-ready, schedule a strategic session with PrivaLex.
Frequently Asked Questions
Yes, provided that you map each framework’s requirements separately and keep the role-based evidence clear. One shared plan can reduce duplication, but it should not blur the different objectives of information security, cybersecurity governance, and data protection.
There is no universal schedule for every organisation. Onboarding, annual refreshers, and short quarterly sessions are practical examples. The right cadence depends on roles, risks, incidents, regulatory context, and changes to systems or processes.
Auditors commonly ask for the current plan, role matrix, attendance or LMS records, training materials, assessments, onboarding evidence, and records showing how the plan was updated after relevant changes or incidents.
They should be included where their access, role, or processing activities create relevant risk. The appropriate measure may be a short briefing, policy acknowledgement, limited access, or role-specific training rather than the full employee programme.
Assign the core module during the first weeks, record completion, and make sure the new joiner knows the relevant policies, reporting route, approved tools, and expected behaviours before accessing sensitive systems or data.
Not automatically in every case. Review what failed, which roles were affected, and whether a focused update, simulation, procedure change, or wider refresher is appropriate. Keep evidence of the decision and resulting action.
