# Dutch Cybersecurity Act: the training requirements that apply in 2026

> The Dutch Cybersecurity Act takes effect on 15 August 2026 and requires training for your organisation as well as a certified course for your management body. Here is what you need to arrange.

- Canonical: https://cyberpulse.it/en/dutch-cybersecurity-act-training-requirements
- Dutch version: https://cyberpulse.it/cyberbeveiligingswet-training-eisen
- Published: 2026-08-09
- Updated: 2026-08-25
- Publisher: CyberPulse (https://cyberpulse.it)

The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) enters into force on 15 August 2026 and requires some 8,000 Dutch organisations to get their cybersecurity demonstrably in order. The Cbw is the Netherlands' national implementation of the European NIS2 Directive, so if you operate elsewhere in the EU the same directive will reach you through your own country's implementing law rather than through the Cbw. Two training requirements stand out: the duty of care covers cybersecurity training for your organisation (art. 21(2)(g)), and members of the management body must be demonstrably trained within two years, with a certificate (art. 24). Below you will find who the act applies to, what those training requirements actually mean, and how to give practical substance to "demonstrable".

## What is the Dutch Cybersecurity Act?

The Dutch Cybersecurity Act is the Dutch implementation of the European NIS2 Directive (Directive (EU) 2022/2555) and replaces the Wbni, the earlier Dutch act on the security of network and information systems. The Dutch Senate passed the act on 7 July 2026, publication followed in the Dutch Government Gazette (Stb. 2026, 187), and on 15 August 2026 the act takes effect.

The act rests on five pillars:

- **Registration obligation**: your organisation registers in the entity register of the Dutch National Cyber Security Centre (NCSC).
- **Duty of care**: you take appropriate security measures, including basic cyber hygiene practices and training.
- **Reporting obligation**: you report significant incidents to the CSIRT.
- **Management accountability**: the management body carries ultimate responsibility and must be trained itself.
- **Supervision and enforcement**: the Dutch Authority for Digital Infrastructure (RDI), among others, supervises compliance.

The Cbw is not the only framework that sets training requirements either: DORA, BIO2, ISO 27001 and the GDPR also impose requirements or expectations around security awareness. The complete overview is in the guide [is security awareness training mandatory?](/en/security-awareness-training-mandatory).

## Who does the Cbw apply to?

The act applies to organisations in 18 sectors, listed in Annexes I and II of the NIS2 Directive. Within those sectors, a size threshold applies. If you are above it, you are one of the roughly 8,000 Dutch organisations covered by the act from 15 August 2026.

| Criterion | Threshold |
|---|---|
| Sector | One of the 18 sectors in Annex I or II |
| Employees | More than 50 |
| Turnover or balance sheet total | More than €10 million |

Note the word "or": the threshold is more than 50 employees **or** more than €10 million in turnover or balance sheet total. A company with 40 employees and €12 million in turnover therefore does fall under the act: provided it is active in one of the 18 sectors.

The act also distinguishes between **essential** and **important** entities. That distinction mainly works through in supervision and in the maximum fines (more on that below). The training requirements in this article apply to any organisation covered by the act, whichever category it is in.

## Which training requirements apply?

The Cbw runs along two tracks: training for the organisation as part of the duty of care, and a personal training obligation for members of the management body.

### Track 1: training for the organisation (art. 21(2)(g))

The duty of care lists measures you must take in any event. One of them is explicitly about training:

> "basic cyber hygiene practices and cybersecurity training"
> – NIS2 art. 21(2)(g), transposed into Cbw art. 21(2)(g)

Training is therefore not non-binding advice but part of the statutory duty of care. The NCSC [explains the duty of care on its website](https://www.ncsc.nl/cyberbeveiligingswet-nis2/zorgplicht) (in Dutch). How to set up such a training programme in concrete terms, and how to keep it alive rather than turning it into an annual box-ticking e-learning, is covered in [NIS2 security awareness training](/en/nis2-security-awareness-training).

Here is what that looks like in practice for an SME with, say, 80 employees:

1. **Appoint an owner.** Often the office manager, the person responsible for IT or the information security officer: someone who guards the programme and manages the records.
2. **Choose a format you can sustain.** Short, recurring learning moments are easier to keep up and easier to defend than one annual afternoon that keeps getting pushed back.
3. **Cover cyber hygiene as a minimum.** The text of the act names basic practices explicitly; think phishing, passwords and reporting incidents.
4. **Bring new employees in straight away.** Someone who starts in October should not stay out of view until the next annual round.
5. **Record who completed what from day one.** Reconstructing it afterwards rarely works.

### Track 2: training members of the management body, with a certificate (art. 24)

For the management body, the act goes a step further than for employees. Cbw art. 24 requires members of the management body to have **demonstrable** knowledge and skills, **within two years**, evidenced by a mandatory **certificate** from a completed training course. This is the Dutch working-out of NIS2 art. 20(2), which instructs Member States to ensure that members of the management body are required to follow training.

A general e-learning for staff therefore does not cover this requirement: there has to be a certificate against it. What that means for your board or management team, including exactly who counts as a member of the management body, is set out in [NIS2 management training](/en/nis2-management-training).

## What does 'demonstrable' mean?

The act asks that you train and that you can prove it. Management accountability and supervision mean, in practice, that during an inspection or after an incident you want to be able to show in black and white who followed which training, when, and with what result.

Think of this evidence file:

- **Participation records per employee**: who completed which module, and when?
- **Results**: whether the material landed (quiz and test results), not just who attended.
- **Certificates**: legally required for members of the management body (art. 24), and strong evidence for the rest of the organisation.
- **A continuous programme**: a one-off session in the distant past convinces a regulator less than a current, repeated programme.

This is exactly where many organisations come unstuck: the training was delivered, but nobody can prove it. CyberPulse records this automatically: training participation, quiz results, certificates and phishing results are captured per employee; precisely the evidence auditors and regulators ask for. [Start a free trial](/trial) to see what those reports look like.

## Fines and supervision

Supervision of the Cbw sits with the RDI, among others. Some caution is in order about the fine amounts: the exact Dutch figures are set out in the Cybersecurity Decree (Cyberbeveiligingsbesluit, Stb. 2026, 189). The NIS2 Directive itself (art. 34) does give a clear floor for what Member States must at least make possible:

- **Essential entities**: at least €10 million or 2% of worldwide annual turnover.
- **Important entities**: at least €7 million or 1.4% of worldwide annual turnover.

So do not count on the Netherlands turning out milder than that European floor. And the consequences are not limited to the organisation: under NIS2 art. 20(1) the management body can be held liable, and Cbw art. 78 even makes it possible to suspend a member of the management body. More on that in [NIS2 management training](/en/nis2-management-training).

### What the regulator will come and ask

Exactly how an inspection runs is for the regulator to decide. But the obligations in the act make clear which evidence has to be available. Count on having to answer these questions at the very least:

| Obligation | The question you have to be able to answer |
|---|---|
| Registration obligation | Is your organisation listed in the NCSC entity register? |
| Duty of care: training | Who was trained and when, and what were the results? |
| Management body training (art. 24) | Can you produce a certificate for each member of the management body? |
| Reporting obligation | Do employees know how to report an incident internally, so it reaches the CSIRT in time? |

The common denominator: paperwork. Not because paperwork produces security, but because supervision without evidence has nothing to test against. Organisations that keep their records up to date continuously answer such questions in minutes; anyone who has to go hunting through mailboxes and stray spreadsheets turns every inspection into a project.

A practical stress test: could your organisation deliver the complete file (registration, training evidence, management body certificates and reporting process) within one working day, without anyone working late? If not, the file probably does not really exist, and now is the moment to fix that, not the week the regulator gets in touch.

## Checklist: how to comply before and after 15 August 2026

**Before (or as soon as possible after) 15 August 2026:**

1. **Determine your scope.** Is your organisation in one of the 18 sectors from Annex I/II, and are you above the threshold (>50 employees **or** >€10 million turnover/balance sheet total)?
2. **Register your organisation** in the NCSC entity register.
3. **Start a security awareness programme** for all employees: the duty of care (art. 21(2)(g)) names cyber hygiene and training explicitly.
4. **Plan the management body training** with a certificate. The deadline is two years, but the management body's liability applies from the moment the act takes effect: putting it off is unwise.
5. **Set up your reporting process**, so significant incidents reach the CSIRT in time.

**After 15 August 2026: keep it demonstrable:**

6. **Record everything**: participation, results and certificates per employee, centrally and available on request.
7. **Repeat and refresh** the programme; a one-off effort dates quickly.
8. **Prepare for supervision** (by the RDI, among others): make sure your evidence file can be on the table within a day.

If you want to look wider than the Cbw, because customers are asking for ISO 27001, for example, or because you are in the financial sector and fall under DORA: start with the overview [is security awareness training mandatory?](/en/security-awareness-training-mandatory).

## Frequently asked questions

### My company has 40 employees: does the Dutch Cybersecurity Act affect me?

Possibly. The threshold is more than 50 employees or more than €10 million in turnover or balance sheet total. With 40 employees but, say, €12 million in turnover you are still covered by the act, provided you operate in one of the 18 sectors from Annex I/II. If nothing applies to you, training is often still sensible: the GDPR expects demonstrable awareness as an appropriate organisational measure, and customers may ask for it by contract.
### When does my organisation have to be registered?

The Dutch Cybersecurity Act takes effect on 15 August 2026 and carries a registration obligation: organisations covered by the act register in the entity register of the Dutch National Cyber Security Centre (NCSC). Do not wait until a regulator asks: check the current registration procedure and deadline with the NCSC and put registration at the top of your compliance list.
### What is the difference between NIS2 and the Dutch Cybersecurity Act?

NIS2 is a European directive (Directive (EU) 2022/2555). A directive does not apply directly; each EU country has to transpose it into national law. The Dutch Cybersecurity Act is the Dutch transposition, and it replaces the earlier Wbni. In practice that means the obligations you have to comply with in the Netherlands are set out in the Cbw, based on the requirements of NIS2, such as the duty of care including training (art. 21(2)(g)) and the management body training (art. 24). Other EU member states transpose the same directive through their own national law.
### Does the Dutch Cybersecurity Act also apply to suppliers?

Not automatically. The act applies to organisations that are themselves in one of the 18 sectors and above the threshold, so check your own scope first. Requirements can, however, work through by contract via your customers. The clearest example is the public sector: BIO2 applies to central government, municipalities, provinces and water authorities as well as their suppliers, through contractual pass-through. Outside government too, customers who fall under the Cbw themselves may ask for evidence of your security measures.
### What has to be in the training?

The act does not prescribe a detailed curriculum. The duty of care (art. 21(2)(g)) names basic cyber hygiene practices and cybersecurity training; for members of the management body, art. 24 requires demonstrable knowledge and skills, completed with a certificate. The common thread is demonstrability: choose a programme whose participation, results and certificates you can show per person, and keep it current through repetition.
### What happens if I do not meet the training requirements?

The training requirements are part of the statutory duty of care and management accountability, supervised by the RDI among others. The NIS2 Directive requires maximum fines of at least €10 million or 2% of worldwide annual turnover for essential entities (€7 million or 1.4% for important entities); the exact Dutch amounts are set out in the Cybersecurity Decree. On top of that, the management body can be held liable (NIS2 art. 20(1)) and Cbw art. 78 makes it possible to suspend a member of the management body.

## Sources

- [Dutch government, Cybersecurity Act in force from 15 August 2026](https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht)
- [NCSC, the duty of care under the Dutch Cybersecurity Act](https://www.ncsc.nl/cyberbeveiligingswet-nis2/zorgplicht)
- [NCTV, management accountability and the training obligation for management body members](https://www.nctv.nl/onderwerpen/c/cyberbeveiligingswet/bestuurlijke-verantwoordelijkheid-en-opleidingsplicht-voor-bestuurders)
- [RDI, Dutch Cybersecurity Act](https://www.rdi.nl/onderwerpen/digitale-weerbaarheid/cyberbeveiligingswet)
- [EUR-Lex, NIS2 Directive (Directive (EU) 2022/2555)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555)
