The NIS2 training obligation is a concrete legal requirement for executive directors of organisations that are included as an essential or important entity under the Dutch Cybersecurity Act. This FAQ helps directors, board secretaries, CISOS and compliance board members who seek NIS2 training or Cbw training to determine who should follow the training, what the content should include and how the organisation can demonstrably record compliance.
Who should be in NIS2 training?
1. Should our board be required to take NIS2 training?
Yes, when your organisation as an essential or important entity is covered by the Dutch Cybersecurity Act. The specific training obligation shall apply to the executive directors of that entity. They should have sufficient knowledge and skills to assess cyber risks and risk management measures and understand their impact on the organisation.
Therefore, first determine the applicability and entity status of the organisation. Without a reliable scope assessment, it is not appropriate to determine what legal obligations apply.
2. Which board members should follow the NIS2 training?
The obligation applies to natural persons who perform an executive board-level function in an essential or important entity. If a legal person is a director, the obligation shall apply to natural persons who are on the Board's behalf.
The legal role is decisive, not just the function title. Therefore, check the statutes, registration and actual division of tasks when it is unclear who is the executive director.
3. Does the training obligation apply to the Supervisory Board or Supervisory Board?
No. Supervisory directors, supervisory directors and non-executive directors are excluded from this specific training and certificate obligation. However, digital risks, board-level responsibility and oversight of the duty of care remain relevant to them.
A joint boardroom session can therefore be useful, but it must be clearly distinguished from the formal training that executive directors must be able to demonstrate.
4. When should the training have been followed?
The Dutch Cybersecurity Act entered into force on 15 August 2026. Board members who were in office at that time must therefore have the necessary knowledge and skills by 15 August 2028 at the latest. New board members must meet the requirements within two years of their appointment.
Don't wait until the end of the term. The organisation needs the knowledge to properly organise the duty of care, measures, incident reporting and board-level reporting.
The core is simple: determine which executive directors are under the obligation, choose a training that covers all the legally mentioned topics, keep a complete certificate per board member and then organise demonstrable updating of knowledge.
What does the Dutch Cybersecurity Act require from the training?
5. What exactly does a Cbw training for board members entail?
A Cbw board member training provides knowledge and skills to assess cyber risks, risk management measures and the impact on the organisation. The board member does not need to become a technical specialist. The law requires knowledge at strategic level, so that the board can ask the right questions, adopt measures and take informed decisions.
6. What requirements should the training meet?
The training must cover the legally designated subjects and be in line with the purpose of the training obligation. The law does not prescribe fixed duration, type of honking or teaching method. The chosen design should be sufficient to effectively build up the necessary board-level knowledge and skills.
Pre-determine the topics and save programme, participant information and certificate. This allows the organisation to back up the reasons for the training that was followed.
7. What subjects should be covered in the training?
The Cybersecurity Decision links training to cyber risks, the risk management process, the risk analysis methodology used and the measures of the statutory duty of care. The board member must understand in general how these issues relate to continuity, security and board-level decision-making.
- policy for risk analysis and security of network and information systems
- incident handling and reporting processes
- business continuity, back-ups, crisis management and recovery
- supply chain security and suppliers
- safe acquisition, development and maintenance of systems, including vulnerabilities
- assessment of the effectiveness of risk management measures
- cyber-hygiene and cyber-security training
- Cryptography and Encryption
- personnel security, access policy and asset management
- multifactor authentication, secure communication and other appropriate access measures
8. Which NIS2 training or Cbw training is required?
The government does not designate a specific course, trainer or training form. An external training, customised programme or internal training may be appropriate as long as the content covers the legal subjects and each mandatory board member receives a useful certificate.
Therefore, do not choose only by name or price. Review the programme, the board-level level, the connection to the organisation and the quality of the evidence.
9. Should the trainer be officially recognised or certified?
No. The Dutch Cybersecurity Act does not require recognition or certification of the trainer. However, the certificate must state who took care of the training. The organisation remains responsible for a defensible choice of content, level and provider.
Certificate and demonstration of the training obligation
10. What evidence should the board member be able to show?
Every board member subject to the training obligation shall be able to show a certificate showing that the training has been followed. A joint attendance list without an individual certificate is not sufficiently careful.
11. What should the certificate say?
The certificate shall indicate at least the board member's name, the date or dates of the training, the subjects covered and the name of the provider. The certificate may be drawn up in Dutch or English; training itself may also be given in another language.
- board member's name
- date or dates of the training
- 3-1994, point 1.2.101
- name of the supplier
12. How does the organisation make compliance demonstrably?
Keep the certificate by board member together with the programme, the content learning objectives and the date on which participation is administratively or administratively established. In the governance calendar, also include how knowledge is kept up-to-date and how the governance is informed about cyber risks.
A compact evidence file prevents the need to retrieve information from mailboxes and calendar service providers in case of a staff change or oversight request.
13. Should the training be repeated periodically?
The regulations do not prescribe a fixed deadline. Board members must keep their knowledge and skills up to date after the first training. This can be done with targeted training, periodic updates, exercises or other demonstrable activities that fit in with changes in threats, legislation and organisation.
Therefore, record a maintenance cycle instead of waiting for an explicit expiry date of the certificate.
What do the board and the secretary of the board do now?
14. What practical checklist can the secretary of the board use?
Use the legal deadline as the end point, but organise the execution as a board-level file with clear owners. The following steps make the training obligation practically manageable.
- confirm whether the organisation is an essential or important entity
- determine which natural persons are executive directors
- select a training that will be able to demonstrate all official topics
- plan participation well ahead of the applicable deadline
- check by board member that the certificate contains all mandatory information
- keep program, certificates and decision making centrally
- plan how knowledge and skills are demonstrable to be up-to-date
15. Is board member training sufficient to comply with NIS2?
The training is the knowledge base within the broader implementation obligation. Depending on the entity's status, the organisation also organises registration, risk analysis, mandatory care measures, supplier control, incident reporting, governance and demonstrable follow-up.
Kynexis Information Security supports the implementation side with a quick scan, GAP analysis, audit, implementation and assurance. Training and execution are complementary, but each has its own purpose and evidence.
Sources and deepening
Based on official frameworks and practical implementation
The source pages provide the formal background. Kynexis Information Security translates this information into an executable approach for your organisation, sector and risk profile.


