# NIS2 management training: mandatory certificate in 2026

> Members of the management body of organisations under the Dutch Cybersecurity Act must complete demonstrable training, with a certificate, within two years. Who must train, what evidence counts and how to arrange it.

- Canonical: https://cyberpulse.it/en/nis2-management-training
- Dutch version: https://cyberpulse.it/nis2-bestuurderstraining
- Published: 2026-08-09
- Updated: 2026-08-25
- Publisher: CyberPulse (https://cyberpulse.it)

Yes, NIS2 management training is mandatory: if your organisation falls under the Dutch Cybersecurity Act (Cbw), members of the management body must demonstrably possess knowledge and skills in the field of cybersecurity within two years: completed with a mandatory certificate. The Act takes effect on 15 August 2026, and the management body can be held personally liable if it falls short. This page sets out exactly who has to train, what the training must deliver, what evidence counts and how to arrange it in practice.

One point of context for readers outside the Netherlands: the Cbw is the Dutch implementation of the NIS2 Directive. Every EU member state has its own implementing law, so if you operate in more than one country, check the national act for each establishment as well.

## Are members of the management body required to follow training?

Yes. The obligation comes in two layers. The European NIS2 Directive instructs member states in Article 20(2) to ensure that members of the management body follow training:

> members of the management body are “required to follow training”
> – NIS2, Article 20(2)

The Netherlands has given that shape in the Dutch Cybersecurity Act. Cbw Article 24 requires members of the management body to **demonstrably** possess knowledge and skills, **within two years**, with a mandatory **certificate** from a completed training course. That certificate makes this obligation different from most compliance requirements: it is not enough to have “been in the room”: there has to be a document to show for it.

The obligation applies to organisations that fall under the Cbw: 18 sectors, with a threshold of more than 50 employees or more than €10 million in turnover or balance sheet total. If you are unsure whether your organisation is in scope, start with [the training requirements of the Dutch Cybersecurity Act](/en/dutch-cybersecurity-act-training-requirements). And for the wider picture of every law and standard that touches awareness training, there is the guide [is security awareness training mandatory?](/en/security-awareness-training-mandatory).

## Who counts as a member of the management body?

The Act attaches the duty to the **management body** of the organisation. In a classic Dutch corporate structure that is the statutory board: the executive management or the management board.

A common follow-up question concerns one-tier boards. There, executive and non-executive members sit together in a single body, and that body *is* the management body. Assume, therefore, that in a one-tier board the training obligation reaches both groups; there is no indication that non-executive members fall outside it. For edge cases: think of managers with a director title but no statutory appointment, or a separate supervisory board in a two-tier structure: the statutory text discussed here gives no definitive answer. In that case, consult [the explanation from the Dutch National Coordinator for Counterterrorism and Security (NCTV) on management responsibility and the training obligation](https://www.nctv.nl/onderwerpen/c/cyberbeveiligingswet/bestuurlijke-verantwoordelijkheid-en-opleidingsplicht-voor-bestuurders) or put the question to your legal counsel.

Practical advice: do not draw the circle too tightly. One certificate too many costs half a day; one member of the management body without a certificate is an open flank when the regulator calls or after an incident.

An example from SME practice: a family business with two statutory board members and an operational management team of five. The hard obligation touches the two statutory board members: they are the ones who need the certificate. But in practice the management team makes daily decisions with a security impact; letting them join the session costs little and strengthens both internal buy-in and the account you give to the regulator.

## What must management training cover?

The Act does not prescribe a fixed table of contents. What is fixed is the goal: members of the management body must demonstrably possess knowledge and skills that match their responsibility under the Act. The management body carries ultimate responsibility for compliance, after all, including the duty of care.

That responsibility points logically to what good management training should teach you:

- **Identifying risks**: which cyber risks affect your organisation, and how do you recognise them at management level?
- **Assessing measures**: the duty of care demands appropriate measures; as a member of the management body you have to be able to judge whether what the organisation does really is appropriate.
- **Estimating the consequences for the organisation**: what do an incident, the reporting obligation and the requirements of the Act mean for continuity, customers and liability?

Note that this is a practical reading based on management responsibility, not a legally prescribed curriculum. Management training is therefore fundamentally different from awareness training for employees: the latter is about safe day-to-day behaviour (recognising phishing, cyber hygiene), the former about steering and accounting for it. You need both: the organisation-wide side is covered in [NIS2 security awareness training](/en/nis2-security-awareness-training).

### Sample agenda: what a good management session looks like

The Act prescribes no programme, but in practice a compact half-day session works well for an SME management team. A proven structure:

1. **Threat landscape and your own organisation (45 min).** Which cyber risks affect your sector and business model? Concrete, with recognisable scenarios instead of abstract statistics.
2. **The Act and your role (45 min).** The obligations under the Cbw (duty of care, reporting obligation, registration obligation) and what management responsibility and liability mean within them.
3. **Case study: an incident at the board table (60 min).** An exercise in which the management body makes the choices itself: report or not, who communicates, what do you ask your IT lead? This is where real understanding takes hold.
4. **Assessing your own measures (30 min).** What does the organisation do today, and can you argue as a management body that it is appropriate?
5. **Test and certificate (30 min).** Close with a test, so that the certificate rests on something.

Keep the group small and the examples your own: a member of the management body remembers the case about their own company, not the standard slide about someone else’s.

## What evidence counts?

The core evidence is the **certificate**: Cbw Article 24 requires a certificate from a completed training course. So make sure the training you choose really does produce a certificate per person, and keep those certificates centrally and retrievable, not in the mailbox of one board member.

Beyond that, the requirement is broader than a single document: members of the management body must *demonstrably possess knowledge and skills*. A certificate from years ago convinces a regulator less than current evidence, especially because the threat landscape keeps shifting. So plan repetition or deeper training, and record that participation too. That keeps your evidence present and credible.

### Arranging the certificate in practice

Arranging the certificate is mainly a matter of organisation, not of study:

- **One owner for the file.** Appoint someone (company secretary, office manager, information security officer) to collect and monitor the certificates: rather than every board member their own mailbox.
- **A certificate in a person’s name.** There is no such thing as one certificate “for the board”; the obligation rests on the individual member, so the evidence does too.
- **Record date and content.** Note when the training was completed and what it covered, so that you can show later that the content matched the management responsibility.
- **Schedule repetition.** Put a recurring moment on the board agenda (linked to the annual risk discussion, for instance) so that keeping it current does not depend on anyone’s memory.
- **Onboard new members straight away.** When someone joins, the clock starts for that person; make the training part of the induction programme for every new member of the management body.

CyberPulse has a dedicated management module with a certificate for exactly this. Members of the management body work through the training online at their own pace, the platform records participation and results per person and generates the certificate you can hand over when the regulator asks: alongside the ongoing awareness reporting for the rest of the organisation. [Start a free trial](/trial) and set the management module up today.

## Liability for non-compliance

The training obligation for management does not stand alone; it belongs to a broader package of management responsibility with teeth:

- **Personal liability**: under NIS2 Article 20(1) the management body can be held liable for non-compliance.
- **Suspension**. Cbw Article 78 makes it possible to suspend a member of the management body.
- **Fines for the organisation**: the NIS2 Directive (Article 34) requires maximum fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and €7 million or 1.4% for important entities. The exact Dutch amounts are set out in the Cyberbeveiligingsbesluit (the Dutch implementing decree, Stb. 2026, 189), so base your risk assessment on at least that European floor.

The legislator’s message is clear: cybersecurity is not an IT file you can delegate and forget. The management body has to understand for itself what it is signing off on, and be able to demonstrate that understanding with a certificate.

## How to approach it

Arranging management training is not a large project. Six steps:

1. **Check your scope.** Does your organisation fall under the Cbw? Work through the sectors and thresholds via [the training requirements of the Dutch Cybersecurity Act](/en/dutch-cybersecurity-act-training-requirements).
2. **Define the circle.** Map who belongs to the management body, and when in doubt, go broad rather than narrow.
3. **Plan the training now.** The deadline is two years, but the Act takes effect on 15 August 2026 and management liability does not wait for your diary.
4. **Choose on certificate and on content.** The training has to produce a certificate and match management responsibility: risks, assessing measures, consequences for the organisation.
5. **Record the evidence centrally.** Certificates, participation and results in one place, immediately retrievable when the regulator asks.
6. **Extend it across the organisation.** The duty of care (Article 21(2)(g)) also requires training for your employees: see [NIS2 security awareness training](/en/nis2-security-awareness-training). One platform for both tracks saves administration and completes your evidence file.

## Frequently asked questions

### By when do I need a certificate as a member of the management body?

The Dutch Cybersecurity Act (Article 24) gives members of the management body two years to demonstrably possess knowledge and skills, completed with a mandatory certificate. The Act takes effect on 15 August 2026. Waiting until the end of that period is unwise: management responsibility and potential liability (NIS2 Article 20(1)) apply from the moment the Act enters into force, and after an incident a missing certificate is a painful thing to establish.
### Does the training obligation also apply to non-executive members?

In a one-tier board it does, and that is the safe assumption: there, executive and non-executive members together form the management body, and the Act attaches the duty to that body. For a separate supervisory board in a two-tier structure, the statutory text discussed here gives no definitive answer; consult the NCTV explanation of management responsibility or your legal counsel for that. In practice: draw the circle too widely rather than too narrowly.
### Is ordinary security awareness training enough for the management body?

No. Employee training falls under the duty of care (Cbw Article 21(2)(g)) and is about safe day-to-day behaviour. For members of the management body, Article 24 sets a separate requirement: demonstrable knowledge and skills at management level, completed with a mandatory certificate. Training without a certificate, or training that does not address assessing risks and management responsibility, does not cover that requirement. So choose a specific management training course alongside the organisation-wide programme.
### What do I risk personally if I do not follow the training?

The training obligation belongs to management responsibility, and that has personal consequences. The management body can be held liable for non-compliance (NIS2 Article 20(1)) and Cbw Article 78 makes it possible to suspend a member of the management body. The organisation also risks fines; the NIS2 Directive requires maximums of at least €10 million or 2% of worldwide annual turnover for essential entities (€7 million or 1.4% for important ones). A missing certificate is a failing that is immediately visible to a regulator.
### Does the rest of the organisation need training as well?

Yes. Alongside management training, the duty of care in the Dutch Cybersecurity Act (Article 21(2)(g)) requires basic cyber hygiene practices and cybersecurity training for the organisation. These are two tracks you have to arrange and be able to demonstrate: an organisation-wide awareness programme with recorded participation and results, plus a certified training course for the management body.
### How often does management training have to be repeated?

The provisions discussed here name no fixed repetition frequency; Article 24 requires a certificate within two years and that members of the management body demonstrably possess knowledge and skills. Because the threat landscape shifts, that evidence ages: a certificate from years ago convinces a regulator less than current evidence. So schedule periodic repetition or deeper training and record that participation, so that your knowledge was not merely demonstrated once, but stays demonstrable.

## Sources

- [NCTV, Management responsibility and the training obligation for members of the management body](https://www.nctv.nl/onderwerpen/c/cyberbeveiligingswet/bestuurlijke-verantwoordelijkheid-en-opleidingsplicht-voor-bestuurders)
- [EUR-Lex, NIS2 Directive (Directive (EU) 2022/2555)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555)
- [Dutch government, Dutch Cybersecurity Act in force from 15 August 2026](https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht)
- [RDI, Dutch Cybersecurity Act](https://www.rdi.nl/onderwerpen/digitale-weerbaarheid/cyberbeveiligingswet)
