Phishing Simulation for Germany: GDPR, NIS2, and Employee Testing

In this blog

phishing simulation Germany

In Short

Germany’s implementation of the EU’s NIS2 Directive — enacted through the updated BSI Act (BSIG) — introduces a provision most companies have not fully absorbed yet: under Section 38(3), management at affected organizations is personally required to complete cybersecurity risk-management training, and this obligation cannot be delegated to someone else in the company. Combined with GDPR enforcement that runs through 16 separate state-level data protection authorities, Germany presents a more fragmented and more personally consequential compliance picture than most other EU markets. Phishing simulation and awareness training give organizations a practical, documentable way to build the human-layer defenses that both frameworks expect — for the wider workforce and, specifically, for leadership.

Why Germany Is a Distinct Compliance Environment

Most guidance on European phishing simulation and awareness programs treats the EU as a single regulatory zone. Germany does not fit that treatment well. Its implementation of NIS2 introduces a personal training obligation for directors that goes further than the directive’s baseline text, and its GDPR enforcement structure is genuinely decentralized in a way that changes how organizations should think about documentation and audit readiness. A German-specific approach to phishing simulation and awareness training needs to account for both.

What NIS2 Requires in Germany

The EU’s NIS2 Directive expanded the scope of critical infrastructure and “important entity” cybersecurity obligations across member states, including mandatory risk-management measures, incident reporting timelines, and governance accountability. Germany’s transposition of NIS2 has moved through its legislative process as the NIS2UmsuCG (the NIS2 Implementation and Cybersecurity Strengthening Act), which amends the existing BSI Act (Gesetz über das Bundesamt für Sicherheit in der Informationstechnik, or BSIG). Phishing and social engineering remain the most common entry point cited in the risk-management measures the directive expects organizations to address, which is why awareness and simulation testing sit squarely inside NIS2 scope rather than at its edges.

As of this writing, the exact final legislative text and enforcement timeline for Germany’s NIS2 transposition has continued to move through the Bundestag, and organizations operating in Germany should confirm the current status directly with legal counsel or the BSI (Bundesamt für Sicherheit in der Informationstechnik) rather than relying on any single article for the up-to-the-day legislative position. What has been consistently reported across legal analyses of the draft and enacted provisions is the structure of the obligations, including the training requirement described below.

The Personal Liability Rule Most Companies Have Missed

The detail that distinguishes Germany’s approach from many other member states is Section 38(3) of the amended BSI Act. This provision requires the management bodies of affected entities — not a delegated compliance officer, not the IT department — to personally complete training in cybersecurity risk management. Legal commentary on this provision has been explicit that the obligation is non-delegable: management cannot satisfy it by ensuring someone else in the organization is trained.

This is a meaningfully different compliance posture than the general expectation, found in most awareness frameworks, that training should reach “all employees” or “all relevant staff.” Section 38(3) puts a specific, personal, and auditable expectation on the individuals who sit on management boards or hold equivalent leadership roles at entities in scope. For organizations building or refreshing a training program in Germany, this means leadership-level phishing awareness and simulation exposure is not optional or symbolic — it is one of the more concretely defined line items in the country’s NIS2 transposition.

Why Germany Faces a Distinctly Structured Threat Landscape

The BSI’s own threat assessments have repeatedly characterized Germany’s cyber threat situation as “tense,” citing sustained targeting of both public institutions and private industry. State-linked actors, including groups publicly associated with Russian military intelligence such as APT28 (Fancy Bear), have been named in BSI and allied-government reporting as active threats against German political, governmental, and industrial targets, frequently using phishing and credential-harvesting techniques as an initial access method.

Separately, Germany’s Mittelstand — the dense network of small and mid-sized industrial and manufacturing firms that make up a large share of the country’s economy — has been repeatedly flagged in German cybersecurity industry reporting as disproportionately exposed. Multiple industry surveys conducted by German business associations and insurers have reported that a large majority of Mittelstand firms — commonly cited around 80% in recent survey years — have experienced some form of cyberattack, while these same firms often carry smaller dedicated security teams than larger enterprises. This combination — high-value intellectual property, a large attack surface, and comparatively lean security resourcing — makes phishing simulation and awareness training a proportionally higher-leverage investment for German SMEs than for organizations of similar size in markets with less pronounced targeting.

phishing simulation Germany

GDPR’s Distinctly Fragmented Enforcement in Germany

Unlike many EU member states that designate a single national data protection authority, Germany enforces GDPR through 16 separate state-level authorities (Landesdatenschutzbehörden), one per federal state, alongside a federal authority (the BfDI) responsible for federal bodies and specific sectors such as telecommunications. This means a company operating across multiple German states may, in principle, be answerable to more than one state authority depending on where processing activity occurs and where complaints are filed.

Phishing simulation and awareness training do not remove GDPR obligations, but they support the “appropriate technical and organisational measures” standard that GDPR Article 32 requires organizations to demonstrate, particularly around protecting personal data from unauthorized access following a credential-theft or business email compromise incident. In a fragmented enforcement environment where the exact authority reviewing an incident may vary by state, having consistent, well-documented training records across the organization is a more defensible position than relying on informal or one-off awareness efforts.

What This Means for Testing Your Team

Given both the NIS2 personal-training obligation and GDPR’s emphasis on organizational measures, a German phishing simulation program should typically account for two distinct audiences:

Management and leadership, where Section 38(3) creates a specific, personal, non-delegable training expectation tied to cybersecurity risk management.

The broader workforce, where general phishing and social engineering resilience supports both NIS2’s risk-management measures and GDPR’s Article 32 “appropriate measures” standard.

PhishCare’s phishing simulation platform lets organizations run realistic, controlled phishing campaigns against employee groups, track click-through and reporting behavior, and generate reporting that can support documentation of ongoing security awareness efforts. This kind of testing and reporting can help German organizations build the kind of ongoing, auditable training record that both NIS2 and GDPR reward, even though — as with any vendor — no simulation platform on its own constitutes full legal compliance with either framework; that determination sits with the organization’s legal and compliance advisors.

A Note on Language and Templates

PhishCare does not currently offer German-language phishing simulation templates. Campaigns and awareness content are run in the languages PhishCare currently supports, which does not include German-language templates at this time. Organizations running phishing simulations for a primarily German-speaking workforce should factor this into their evaluation and testing plan, since realistic phishing simulations are generally most effective when template language matches what employees would actually encounter in a real attack. We want to be upfront about this rather than let it come as a surprise after signup.

Building a Testing Program

A practical starting point for a German phishing simulation program typically includes:

  1. Confirming which entities and roles at your organization fall inside NIS2 scope, and identifying which individuals hold “management body” status under Section 38(3).

  2. Running an initial baseline phishing simulation to understand current click-through and reporting rates across departments.

  3. Delivering targeted awareness content and retesting on a regular cadence, with documentation retained for compliance review.

  4. Extending simulation and awareness coverage specifically to leadership, given the personal nature of the Section 38(3) obligation.

  5. Coordinating with legal or compliance counsel on how simulation records fit into your organization’s broader NIS2 and GDPR documentation.

Final Thoughts

Germany’s regulatory environment does not simply mirror the rest of the EU. The personal, non-delegable training obligation on management under Section 38(3) of the amended BSI Act, combined with GDPR enforcement spread across 16 state authorities, means German organizations have specific, well-defined reasons to build a documented, ongoing phishing simulation and awareness program — one that reaches leadership as deliberately as it reaches the rest of the workforce.

FAQ

Does NIS2 apply to every company in Germany?
NIS2 scope depends on sector and organization size, generally applying to medium and large entities in sectors the directive designates as essential or important. Organizations should confirm their specific scope status with legal counsel, as thresholds and sector lists are defined in the legislation itself.
What is Section 38(3) of the BSI Act?
It is a provision in Germany’s amended BSI Act requiring management bodies at NIS2-affected entities to personally complete training in cybersecurity risk management. Legal commentary on the provision has described this obligation as non-delegable, meaning it applies specifically to those in management roles rather than being satisfiable by training other staff.
Does phishing simulation satisfy GDPR requirements on its own?
No. Phishing simulation and awareness training can support the “appropriate technical and organisational measures” standard under GDPR Article 32, but GDPR compliance involves many additional requirements beyond training. Organizations should work with legal counsel to assess their full compliance position.
Does PhishCare offer phishing simulation templates in German?
Not currently. PhishCare does not offer German-language templates at this time. This is worth factoring into your evaluation if your workforce is primarily German-speaking.
Who enforces GDPR in Germany?
Enforcement is handled by 16 separate state-level data protection authorities (Landesdatenschutzbehörden), plus a federal authority (the BfDI) for federal bodies and certain sectors. Which authority applies can depend on where your organization processes data and where a complaint originates.
How often should German organizations run phishing simulations?
There is no single legally mandated frequency under NIS2 or GDPR. Many organizations run baseline testing followed by regular ongoing campaigns (commonly quarterly or more frequently) to build a consistent, documentable training record, particularly useful given NIS2’s risk-management documentation expectations.
Content Reviewed By
Mohammed Nawaz Sajjad, Sr. Security Analyst at PhishCare
Mohammed Nawaz Sajjad
Sr. Security Analyst at CyberSapiens | Phishing Simulation | Ethical Hacker | Bug Hunter | Red Team

Nawaz is a practising security analyst specializing in phishing simulation campaigns, employee awareness assessments, red team exercises, and ethical hacking. He leads phishing simulation deployments at PhishCare, a product developed by CyberSapiens, with hands-on experience evaluating and deploying phishing simulation tools across organizations in multiple industries and regions globally.

View LinkedIn Profile

See How PhishCare Can Help

See how PhishCare’s phishing simulation platform can help you build a documented, ongoing awareness program for your team, including leadership.

and run your first test campaign.