# NIS2 security awareness training: what to arrange in 2026

> NIS2 requires cyber hygiene and cybersecurity training for employees through Article 21(2)(g). Read what that means, how often you train and what evidence to keep.

- Canonical: https://cyberpulse.it/en/nis2-security-awareness-training
- Dutch version: https://cyberpulse.it/nis2-security-awareness-training
- Published: 2026-08-09
- Updated: 2026-08-25
- Publisher: CyberPulse (https://cyberpulse.it)

NIS2 requires organisations to train their employees. Article 21(2)(g) of the Directive names basic cyber hygiene practices and cybersecurity training explicitly as part of the duty of care, and in the Netherlands that requirement becomes enforceable on 15 August 2026 through the Dutch Cybersecurity Act (Cbw). This page sets out what that means in practice: which training, for whom, how often, and what evidence you will be showing the regulator.

## What does NIS2 require of employee training?

The NIS2 Directive (Directive (EU) 2022/2555) imposes a duty of care on organisations: a coherent package of measures to manage cyber risks. Training employees is written into it literally. Article 21(2)(g) requires organisations to have:

> “basic cyber hygiene practices and cybersecurity training”
> – NIS2, Article 21(2)(g); in the Netherlands: Cbw, Article 21(2)(g)

The Netherlands implements NIS2 through the Dutch Cybersecurity Act, which replaces the Wbni (the previous Dutch act on the security of network and information systems). The Act was adopted by the Dutch Senate on 7 July 2026, published in the Dutch Government Gazette (Stb. 2026, 187), and enters into force on 15 August 2026. It applies to some 8,000 organisations in 18 sectors; the threshold is more than 50 employees or more than €10 million in turnover or balance sheet total (Annexes I and II). Every other EU member state has its own implementing law with the same European basis, so a group operating across borders should check the national act per establishment.

The training requirement does not stand alone. Alongside the duty of care, the Cbw has a registration obligation in the entity register of the Dutch National Cyber Security Centre (NCSC), a reporting obligation for significant incidents to the CSIRT, and management responsibility. So if you fall under the Act, employee training is one of the obligations you have to be able to demonstrate: next to your incident process, for example.

Note the distinction with the management body. A separate, stricter regime applies to management: Cbw Article 24 requires members of the management body to demonstrably possess knowledge and skills within two years, with a mandatory certificate from a training course. What that track looks like is covered in [NIS2 management training](/en/nis2-management-training). An overview of every law and standard that touches training can be found at [is security awareness training mandatory](/en/security-awareness-training-mandatory).

## Which topics belong to basic cyber hygiene?

The Act prescribes no list of topics. NIS2 says *what* you must do, train basic cyber hygiene practices and provide cybersecurity training, but not which material belongs to it. In practice, this is the common shape of such a programme:

- **Recognising and reporting phishing.** Employees learn to recognise suspicious emails, messages and phone calls and to report them internally straight away, instead of clicking or hesitating.
- **Passwords and MFA.** Strong, unique passwords and the consistent use of multi-factor authentication on business accounts.
- **Reporting incidents.** Anyone who sees something odd reports it immediately. That is more than good hygiene: the Cbw has a reporting obligation for significant incidents to the CSIRT, and you only meet it if employees raise the alarm internally in time.
- **A secure home workplace.** Handling devices, networks and company data safely outside the office.

Important: this is a common interpretation, not a statutory list. Choose and deepen the topics on the basis of the risks in your own organisation: the duty of care is about managing your risks, not about ticking off a standard package.

### What must an employee actually be able to do per topic?

“Awareness” stays vague as long as you do not translate it into observable behaviour. Formulate per topic what someone must be able to *do* after the training: that makes the training testable and your evidence stronger:

| Topic | Concrete behaviour after the training |
|---|---|
| Phishing | Recognise a suspicious message by sender, tone and link, and report it instead of clicking or deleting it |
| Passwords and MFA | Use a unique, strong password for every business account and switch on MFA wherever possible |
| Reporting incidents | Know what an incident can be, who to report it to internally, and that reporting quickly always beats waiting |
| Working from home | Lock the screen, use only approved devices and connections, and never share company information through private channels |

An SME example makes the difference clear. An administrative employee at a logistics company receives an email that appears to come from a supplier, with a changed bank account number. An employee who has only seen a presentation about “phishing exists” hesitates. An employee trained on concrete behaviour recognises the pattern, does not click, and reports the message immediately: which also proves that the internal reporting route works.

Then test that behaviour as well: quiz questions about recognisable situations and periodic phishing simulations show whether the behaviour is really there, and immediately produce the records your evidence file needs. That way your programme grows with what employees already master: anyone scoring flawlessly on phishing can move on to more depth, anyone who slips gets targeted repetition.

## How often should you train?

Neither NIS2 nor the Cbw names a training frequency. Even so, “we ran a workshop once in 2026” is a weak story. Three reasons to choose a continuous programme, or at the very least a periodic one:

1. **The duty of care is continuous.** The obligation applies without interruption from 15 August 2026, not only on the day of your annual training session. A programme that runs all year fits that far better than a one-off moment.
2. **Your workforce changes.** New employees fall outside last year’s session. Without a fixed rhythm, gaps appear in your coverage that you will have to explain during an inspection.
3. **Demonstrability.** A regulator visiting in 2028 wants to see that training is an ongoing process. A single attendance list from 2026 convinces nobody by then; a continuous programme automatically produces a continuous evidence file with participation, results and repetition per employee.

In short: the Act leaves the frequency to you, but the burden of proof pushes you towards training continuously.

## The burden of proof towards the regulator

Supervision and enforcement of the Cbw sit with, among others, the Dutch Authority for Digital Infrastructure (RDI). During an inspection the question is not whether you once purchased a training course, but whether you can *show* that employees were actually trained: who took part, when, and what came out of it.

Ask yourself the question an inspector would ask: “for these three employees, show me which training they completed this year and what the result was.” If you can do that within a quarter of an hour, you are in good shape. If it means searching mailboxes and calling former colleagues, you effectively have no evidence: however good the training itself was.

The stakes are considerable. NIS2 obliges member states to set substantial maximum fines (Article 34): at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities. The precise Dutch amounts are worked out in the Cyberbeveiligingsbesluit (the Dutch implementing decree). On top of that, the management body can be held liable (NIS2 Article 20(1)) and the Cbw even makes it possible to suspend a member of the management body (Article 78).

You do not have to maintain that evidence file with spreadsheets. CyberPulse records training participation, quiz results, certificates and the outcomes of phishing simulations per employee: precisely the records a regulator asks for. [Start a free trial](/trial) and watch that file build itself.

## NIS2 vs the Cbw: what is the difference?

NIS2 is the European directive; the Dutch Cybersecurity Act is the national law that implements it. For your training approach, the difference lies mainly in the details:

| | NIS2 (EU directive) | Dutch Cybersecurity Act (NL) |
|---|---|---|
| What is it | Directive (EU) 2022/2555; works through national legislation | Dutch implementation of NIS2; replaces the Wbni |
| Status | Adopted in 2022 | Adopted 7 July 2026 (Stb. 2026, 187); in force from 15 August 2026 |
| Employee training | Art. 21(2)(g): cyber hygiene and cybersecurity training | Art. 21(2)(g): the same requirement, directly enforceable |
| Requirements for management | Art. 20(2): the management body is required to follow training | Art. 24: demonstrable knowledge and skills, within 2 years, with a certificate |
| Sanctions | Art. 34: at least €10m/2% (essential), €7m/1.4% (important) | Amounts set out in the Cyberbeveiligingsbesluit; suspension of a member of the management body possible (Art. 78) |
| Supervision | Organised per member state | The RDI, among others |

The full Dutch elaboration (registration obligation, reporting obligation and the rest of the duty of care) is covered in [Dutch Cybersecurity Act: the training requirements](/en/dutch-cybersecurity-act-training-requirements).

## How to comply: checklist

1. **Check whether you fall under the Cbw.** More than 50 employees or more than €10 million in turnover or balance sheet total, in one of the 18 sectors from Annexes I and II.
2. **Register your organisation** in the NCSC entity register.
3. **Set up a continuous training programme** covering at least phishing, passwords and MFA, reporting incidents and secure home working: supplemented with the risks specific to your organisation.
4. **Arrange the management track separately.** Members of the management body must demonstrably have knowledge and skills within two years, with a certificate (Cbw Article 24).
5. **Record everything per employee:** participation, results and certificates.
6. **Measure and adjust.** Use quiz and phishing results to see whether the message lands and where you need to steer.
7. **Keep the evidence centrally,** so that you can deliver immediately when the regulator inspects.

That way you meet the letter of Article 21(2)(g) and build the file that proves your compliance, and that, in the end, is what supervision is about.

## Frequently asked questions

### Is security awareness training mandatory under NIS2?

Yes. Article 21(2)(g) of NIS2 requires organisations to have basic cyber hygiene practices and cybersecurity training as part of the duty of care. In the Netherlands that requirement is implemented in the Dutch Cybersecurity Act (Article 21(2)(g)), which enters into force on 15 August 2026. If you fall under the Act, you must therefore train your employees and be able to demonstrate it.
### Which organisations does the NIS2 training obligation apply to?

The Dutch Cybersecurity Act applies to some 8,000 organisations in 18 sectors (Annexes I and II of the Act). The threshold is more than 50 employees or more than €10 million in turnover or balance sheet total. If you fall under it, then alongside the duty of care, training included, a registration obligation in the NCSC entity register and a reporting obligation for significant incidents apply as well.
### How often do employees have to train under NIS2?

The Act names no frequency. But the duty of care applies continuously, your workforce changes, and a regulator wants to see evidence covering a longer period. A continuous or periodic programme is therefore far easier to defend than a one-off session: it automatically covers new employees and produces a steady stream of records you can show during an inspection.
### Which topics must NIS2 training cover?

NIS2 and the Cbw prescribe no list of topics; the Act speaks only of basic cyber hygiene practices and cybersecurity training. The common interpretation: recognising and reporting phishing, passwords and MFA, reporting incidents and a secure home workplace. Beyond that, choose topics that match the specific risks of your own organisation.
### What fines do I risk if I do not train?

Training is part of the duty of care, and breaching it carries substantial sanctions. NIS2 obliges member states to set maximum fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities (Article 34). The precise Dutch amounts are set out in the Cyberbeveiligingsbesluit. The management body can also be held liable.
### Does the training obligation apply to the management body as well?

Yes, and for them an even stricter regime applies. NIS2 Article 20(2) provides that members of the management body are required to follow training. The Cbw works that out in Article 24: members of the management body must demonstrably possess knowledge and skills within two years, with a mandatory certificate from a training course. In cases of serious failure, suspension of a member of the management body is even possible (Cbw Article 78).

## Sources

- [Dutch government, Dutch Cybersecurity Act in force from 15 August 2026](https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht)
- [EUR-Lex, NIS2 Directive (EU) 2022/2555](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555)
- [NCSC, duty of care under the Dutch Cybersecurity Act](https://www.ncsc.nl/cyberbeveiligingswet-nis2/zorgplicht)
- [RDI, Dutch Cybersecurity Act](https://www.rdi.nl/onderwerpen/digitale-weerbaarheid/cyberbeveiligingswet)
- [NCTV, management responsibility and the training obligation](https://www.nctv.nl/onderwerpen/c/cyberbeveiligingswet/bestuurlijke-verantwoordelijkheid-en-opleidingsplicht-voor-bestuurders)
