The Training Obligations Compass 2026.
The obligations matrix for mid-sized companies under German law: what applies, to whom, how often — on two pages.

The problem this is about
NIS2, the EU AI Act, whistleblower protection, supply chain due diligence, accessibility: in quick succession, lawmakers have created training and instruction obligations that long stopped being a corporate-only issue. Whether an obligation applies to your company is decided by headcount, revenue and sector — not by gut feeling.
At the same time, most companies below 500 employees have nobody whose job description says “track training obligations”. The result: every obligation is discovered one by one, usually through an occasion — a customer requirement, an audit, an incident.

What is inside
- The obligations that apply to practically every company — with legal basis, target group and cadence
- The threshold obligations: NIS2, AML, supply chain act, CSRD, DORA, TISAX and the sector packages — who they hit and what to train
- Three questions for a first triage: headcount? sector? customer contracts?
- Why evidence without a system starts from zero again next year
For everyone who wants to know which of the new obligations really apply — before an audit or an incident answers the question.
Your download is ready.
Thank you! Here is the paper — the link keeps working later, feel free to save it.
Download PDF (7 pages)All papers provide general information and are not legal advice.