# DORA security awareness training: what article 13(6) requires in 2026

> DORA puts security awareness training in black and white: compulsory modules for all employees and for senior management, with no headcount threshold. This is what article 13(6) demands, and how to make it demonstrable.

- Canonical: https://cyberpulse.it/en/dora-security-awareness-training
- Dutch version: https://cyberpulse.it/dora-security-awareness-training
- Published: 2026-08-09
- Updated: 2026-08-25
- Publisher: CyberPulse (https://cyberpulse.it)

DORA puts security awareness training in black and white. Article 13(6) of Regulation (EU) 2022/2554 requires every financial entity to include ICT security awareness and digital operational resilience training as compulsory modules in its staff training scheme: for all employees and for senior management. The Regulation has applied since 17 January 2025 and sets no headcount threshold: the smallest office is in scope too. This article sets out exactly what it says, who has to take part and how to make it demonstrable.

## What is DORA and who does it apply to?

DORA stands for Digital Operational Resilience Act, formally Regulation (EU) 2022/2554. The fact that it is a regulation and not a directive is an important detail: a regulation applies directly. No national implementing law is needed anywhere in the EU: the text applies one to one to your organisation, whether you sit in Dublin, Frankfurt or Amsterdam. And DORA has applied since 17 January 2025, so the requirements are live now, not at some point in the future.

The Regulation targets the digital operational resilience of the financial sector and reaches a broad group of organisations:

- banks;
- insurers;
- pension funds;
- payment institutions;
- investment firms;
- ICT service providers working for the financial sector.

Note that last category. Even if you are not a financial institution yourself but supply services to the sector as an ICT provider, DORA applies to you. Compliance does not stop at the door of the bank or the insurer: it runs down the supply chain.

Just as important is what the Regulation does not contain: a headcount threshold. Where NIS2 and the national laws implementing it generally only bite above 50 employees or €10 million in turnover or balance sheet total, DORA has no such floor. An asset manager with five people is covered exactly as a major bank is. In the wider overview of [when security awareness training is mandatory](/en/security-awareness-training-mandatory), DORA is therefore the most explicit example: the training obligation is written into the text, with no exemption for small organisations.

## What exactly does article 13(6) require?

The heart of the training obligation sits in article 13, paragraph 6. This is the passage it all turns on:

> "Financial entities shall develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes … applicable to all employees and to senior management staff … complexity commensurate to the remit of their functions."
> – Regulation (EU) 2022/2554, article 13(6)

That single sentence carries three hard requirements.

**1. Compulsory modules.** Under DORA, awareness is not an optional extra or a one-off campaign. The Regulation requires security awareness programmes and resilience training to be "compulsory modules" in your staff training scheme. That means: written into your training policy or plan, with a mandatory character, and therefore also an answer to the question of what happens when someone does not complete the training.

**2. Everyone takes part, including the top.** The requirement applies to "all employees and to senior management staff". You cannot limit the training to the IT department or to staff with customer contact. And senior management is named explicitly, so that no debate can arise about it: if you lead, you train.

**3. Depth matched to the role.** The complexity of the training has to match "the remit of their functions": the scope of the job. More on that below, because this is the requirement most programmes currently fail.

It is also worth noticing that DORA names two things side by side: ICT security awareness and digital operational resilience training. So it is not only about learning to recognise threats, but about resilience: knowing what your role is when something goes wrong and how the organisation stays on its feet operationally.

## The management body takes part too

DORA places responsibility firmly at the top. Article 5(2)(e) requires the management body to set aside budget for digital operational resilience, and therefore also for the awareness programmes and training that article 13(6) makes compulsory. Training must not be the line item that disappears the moment the year turns difficult: the budget for it is a board decision.

Combine that with article 13(6), which puts senior management explicitly in the training audience, and the picture is complete. Under DORA, awareness is a board matter, not an IT topic. In practice that means two things: record the budget allocation (in the budget itself, in the minutes), and make sure senior management demonstrably takes part in the programme. A management body that joins in also sends the signal the rest of the organisation needs in order to take the training seriously.

## How demanding does the training have to be?

The phrase "complexity commensurate to the remit of their functions" is the most underestimated requirement in article 13(6). It means that the weight and depth of the training must match what someone actually does in their role. That is risk-based differentiation, and it calls for a deliberate segmentation instead of one generic module for everybody.

Think of it in layers:

- **A base layer for everyone**: the threats and behavioural rules that are relevant to every employee, from reception to the boardroom.
- **Depth by risk profile**: staff working in payments, with access to client data or with administrative rights on systems get heavier, role-specific modules.
- **A separate track for senior management**: focused on decision-making, accountability and the operational resilience of the organisation as a whole.

A single annual generic e-learning for the whole organisation is hard to defend against this requirement: if everyone gets exactly the same thing, the depth is by definition not matched to the role. So document which role groups you distinguish, which programme belongs to which group and why. That reasoning is precisely what you need when a supervisory authority asks.

## DORA alongside NIS2 and the national implementing laws

DORA is not the only framework that touches training. How does it relate to NIS2 and the national laws that implement it?

| | DORA | NIS2 / national implementing laws |
|---|---|---|
| Type | Regulation, applies directly | Directive, transposed per member state; in the Netherlands via the Dutch Cybersecurity Act (Cbw) |
| In force | Since 17 January 2025 | Per member state; the Dutch Cbw takes effect on 15 August 2026 |
| Scope | Sector-specific: the financial sector and its ICT service providers | Broad: 18 sectors |
| Threshold | None | Usually more than 50 employees or more than €10 million turnover/balance sheet total |
| Training | Art. 13(6): compulsory modules, all employees plus senior management | Art. 21(2)(g): cyber hygiene and training as part of the duty of care |

Some organisations end up under both frameworks: an ICT service provider that serves the financial sector and is itself in scope of a national NIS2 law, for instance. Exactly how those frameworks run together in a concrete case is a legal question that has to be answered situation by situation. The practical advice is simpler: build your programme around the most explicit requirement, and for training that is almost always DORA's article 13(6). Meet that, and you also have a solid foundation under the broader training expectation behind [NIS2 security awareness training](/en/nis2-security-awareness-training).

## How to make it demonstrable

A supervisory authority will not ask whether you train, but for evidence that you train, and that the programme meets the requirements. Work through this checklist:

- [ ] Awareness and resilience training appear as **compulsory modules** in the staff training scheme, recorded in policy or in a training plan.
- [ ] The audience covers **all employees and senior management**, including new joiners.
- [ ] The **differentiation by role** is documented: which groups, which programme, which rationale.
- [ ] **Participation and results** are recorded per employee, so you can show at any moment who completed what.
- [ ] The **budget** for the programme has been allocated by the management body (art. 5(2)(e)) and is traceable in the budget or the minutes.
- [ ] The programme is **reviewed and adjusted periodically**.

Many financial institutions combine this with ISO 27001 certification; the evidence overlaps heavily with what auditors expect for [ISO 27001 awareness training](/en/iso-27001-awareness-training), such as attendance records and proof of competence per role.

The centre of gravity is that per-employee record, and that is exactly where a platform like CyberPulse makes the difference. It records training participation, quiz results, certificates and phishing results for every employee, and the weekly micro-learning turns the "compulsory module" into a continuous programme instead of an annual tick-box moment. [Start a free trial](/trial) and see what that reporting looks like.

## Frequently asked questions

### Does DORA also apply to small firms?

Yes. DORA has no headcount threshold and no turnover floor. The Regulation applies to banks, insurers, pension funds, payment institutions, investment firms and ICT service providers: regardless of their size. An investment firm or asset manager with a handful of employees is covered just as a major bank is, including the training obligation in article 13(6).
### Since when has DORA applied?

DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025. Because it is a European regulation it applies directly: no national implementing law was needed in any member state. The requirements, including the compulsory security awareness training in article 13(6), are therefore already in force, not pending some future date.
### Is one annual e-learning enough for DORA?

That is hard to defend. Article 13(6) requires compulsory modules for all employees and for senior management, with a complexity that matches the remit of the role. One generic e-learning for everybody cannot, by definition, deliver that differentiation. A continuous programme with a base layer for everyone and added depth for high-risk roles fits the text of the Regulation far better, and is easier to evidence as well.
### Does senior management have to train too?

Yes, explicitly. Article 13(6) names "all employees and senior management staff" as the audience for the compulsory awareness and resilience training. In addition, article 5(2)(e) requires the management body to allocate budget for digital operational resilience, including this training programme. So the top both takes part and demonstrably pays the bill.
### Does DORA apply to ICT service providers?

Yes. DORA applies not only to financial institutions themselves, but also to ICT service providers that work for the financial sector. If you supply services as an ICT company to banks, insurers, pension funds or other financial entities, the Regulation reaches you: which makes a demonstrable awareness programme relevant for your own organisation as well.
### What is the difference between DORA and NIS2?

DORA is a regulation and therefore applies directly, since 17 January 2025, and is sector-specific to the financial sector, with no headcount threshold. NIS2 is a directive that each member state transposes into national law; in the Netherlands that is the Dutch Cybersecurity Act (Cbw), which takes effect on 15 August 2026, applies broadly to 18 sectors and usually works with a threshold of more than 50 employees or €10 million in turnover. For training, DORA is the most explicit: article 13(6) prescribes compulsory modules in so many words.

## Sources

- [EUR-Lex, Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554)
- [EUR-Lex, Directive (EU) 2022/2555 (NIS2)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555)
- [Dutch government, Cybersecurity Act in force from 15 August 2026](https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht)
