# Is security awareness training mandatory? The laws and standards in 2026

> From 15 August 2026 the Dutch Cybersecurity Act makes training mandatory for around 8,000 organisations. This overview sets out every law, standard and certification that requires security awareness training, and what you have to be able to prove.

- Canonical: https://cyberpulse.it/en/security-awareness-training-mandatory
- Dutch version: https://cyberpulse.it/security-awareness-training-verplicht
- Published: 2026-08-09
- Updated: 2026-08-25
- Publisher: CyberPulse (https://cyberpulse.it)

Yes: for a fast-growing group of Dutch organisations, security awareness training is mandatory. From 15 August 2026 the Dutch Cybersecurity Act (Cbw) requires cybersecurity training from around 8,000 organisations, and DORA and BIO2 impose hard training requirements of their own. On top of that, regulators expect training under the GDPR and NEN 7510, and certifications such as ISO 27001 and PCI DSS demand a demonstrable awareness programme. What applies to your organisation depends on sector, size and contracts: this page sets out every framework.

## Is security awareness training mandatory?

The short answer: yes, more and more often, but the legal basis differs. There is no law saying that every Dutch company must train its staff. There are, however, three routes along which the obligation can reach you, and in 2026 the odds that at least one of them applies to your organisation have grown considerably.

**1. Required by law.** The Dutch Cybersecurity Act (the Dutch implementation of NIS2), the European DORA regulation for the financial sector and BIO2 for the public sector all contain explicit training requirements. If you fall under one of these frameworks, training is not advice but an obligation, with supervision and sanctions behind it.

**2. Expected by the regulator.** The GDPR nowhere names a mandatory course, but assessment turns on whether you have taken "appropriate organisational measures", and staff awareness is part of that. The same applies to the Dutch Health and Youth Care Inspectorate (IGJ), which expects demonstrable compliance with NEN 7510 in healthcare.

**3. Certification and contract.** ISO 27001, SOC 2, PCI DSS and TISAX are formally voluntary, but in practice often rock-solid: your customer or client demands the certificate, and the certificate demands auditable awareness training.

The distinction between those three routes is more than legal precision. It determines what you have to prove, to whom, and what happens if you do not. Confusing "certification requirement" with "legal obligation" makes your business case to the board weaker than it needs to be, or promises a certainty that is not there.

2026 is also the year in which this tips over. Where training was for years mainly a concern for banks and ISO-certified companies, the Cbw widens the obligation in one move: some 8,000 organisations across 18 sectors. Below you will find every framework in turn: starting with the laws, because that is where the urgency is greatest: the Cbw takes effect on 15 August 2026.

## Required by law: Cbw/NIS2, DORA and BIO2

### The Dutch Cybersecurity Act (Cbw): a training obligation from 15 August 2026

The Dutch Cybersecurity Act implements the European NIS2 Directive (Directive (EU) 2022/2555) and replaces the Wbni, the earlier Dutch act on the security of network and information systems. The Dutch Senate passed the act on 7 July 2026, it was published in the Dutch Government Gazette (Stb. 2026, 187), and it enters into force on 15 August 2026. It affects some 8,000 organisations across 18 sectors; the threshold sits roughly at more than 50 employees or more than €10 million in turnover or balance sheet total, for organisations in the sectors listed in Annexes I and II of the directive.

The Cbw carries four main obligations: a registration obligation (signing up in the entity register of the Dutch National Cyber Security Centre, the NCSC), a duty of care, a reporting obligation for significant incidents to the CSIRT, and management accountability. Supervision and enforcement sit with the Dutch Authority for Digital Infrastructure (RDI), among others.

For training, the duty of care is the core. It prescribes a series of measures, including this one word for word:

> "basic cyber hygiene practices and cybersecurity training"
> – NIS2 art. 21(2)(g), transposed into Cbw art. 21(2)(g)

Under the Cbw, training your staff is therefore not a best practice but a legally prescribed part of your security measures. What that means in concrete terms for your programme is set out in [the training requirements of the Dutch Cybersecurity Act](/en/dutch-cybersecurity-act-training-requirements); how to build an awareness programme that satisfies the directive is covered in [NIS2 security awareness training](/en/nis2-security-awareness-training).

The sanctions are not to be shrugged off. NIS2 (art. 34) requires that fines for essential entities can run to at least €10 million or 2% of worldwide annual turnover, and for important entities to €7 million or 1.4%. The exact Dutch amounts are set out in the Cybersecurity Decree (Cyberbeveiligingsbesluit, Stb. 2026, 189).

### Management body members: demonstrable knowledge, with a certificate

The Cbw places responsibility squarely with the management body, and not only on paper. NIS2 art. 20(2) obliges Member States to ensure that members of the management body are themselves "required to follow training". The Netherlands has worked that out in Cbw art. 24: members of the management body must have demonstrable knowledge and skills within two years, evidenced by a mandatory certificate from a completed training course.

That certificate is no formality. The management body can be held liable for non-compliance (NIS2 art. 20(1)), and the Cbw even makes it possible to suspend a member of the management body (art. 78). The training obligation has become personal: a director who "delegates" awareness training to the IT department is taking a risk personally. Everything about this obligation (who, what, when and how to arrange the certificate) is in [NIS2 management training](/en/nis2-management-training).

### DORA: compulsory modules for the financial sector

For the financial sector, DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025: the detail is in [DORA security awareness training](/en/dora-security-awareness-training). Unlike the Cbw, DORA has no headcount threshold: banks, insurers, pension funds, payment institutions, investment firms and ICT service providers all fall under it, whatever their size.

DORA is the most explicit of all the frameworks on training. Art. 13(6) prescribes word for word:

> "Financial entities shall develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes … applicable to all employees and to senior management staff … complexity commensurate to the remit of their functions."
> – DORA art. 13(6)

Three things stand out. The training is a compulsory module in the staff training scheme, it covers all employees as well as senior management, and its complexity has to match the role. The management body must also set budget aside for it (art. 5(2)(e)). One generic annual e-learning for everybody, from service desk to risk officer, does not automatically meet that standard: the regulation explicitly asks for differentiation by role.

### BIO2: government and its suppliers

Public sector bodies work to BIO2, the Dutch government's baseline information security standard (Baseline Informatiebeveiliging Overheid 2). Version 1.3 has applied since 2 March 2026 (circular BWBR0052376) and replaces BIO 1.04. From 15 August 2026 BIO2 is also anchored in law: the Dutch cybersecurity regulation for government bodies points to BIO2 as the way to give substance to the Cbw duty of care. The baseline applies to central government, municipalities, provinces and water authorities, and works through to their suppliers via contracts.

The training requirement is concrete and measurable:

> "All employees and contractors … have demonstrably and successfully completed information security awareness training within three months of joining."
> – BIO2, measure 6.03.02 (translated from Dutch)

Measure 5.04.01 additionally requires the management body and employees to undergo regular training. Note the two sharp edges in 6.03.02: the deadline of three months after joining, and the word "demonstrably". If your company supplies the Dutch government, this requirement can reach your own people through your contract: contractual pass-through is very much the intention with BIO2. More on this in [BIO2 awareness training](/en/bio2-awareness-training).

### The legal frameworks at a glance

| Framework | Who it applies to | Requirement | Article |
|---|---|---|---|
| Cbw (NIS2) | ±8,000 organisations across 18 sectors (>50 employees or >€10 million turnover/balance sheet total) | Cybersecurity training and cyber hygiene as part of the duty of care | Cbw art. 21(2)(g) |
| Cbw: management body | Management body members of organisations covered by the Cbw | Demonstrable knowledge and skills; training with a certificate, within 2 years | Cbw art. 24 (NIS2 art. 20(2)) |
| DORA | Financial entities, no headcount threshold | Compulsory awareness and resilience modules for all employees and senior management | DORA art. 13(6) |
| BIO2 | Central government, municipalities, provinces, water authorities and their suppliers | Demonstrable information security awareness training within 3 months of joining; regular training | BIO2 6.03.02 and 5.04.01 |

## Expected by the regulator: GDPR and NEN 7510

### GDPR: no mandatory course, but demonstrable awareness

The GDPR nowhere names a mandatory security training course, and anyone claiming otherwise wants to sell you something. There are, however, three hooks that together come down to the same thing. Art. 32(4) provides that staff process personal data only on instructions from the controller; that presupposes people who know those instructions. Art. 39(1)(a) explicitly gives the data protection officer the task of monitoring, among other things, "awareness-raising and training of staff". And training counts as an expected "appropriate organisational measure" under art. 32.

The honest summary: the GDPR does not name a mandatory course, but without demonstrable awareness you do not meet art. 32. When a data breach starts with human error (a misaddressed email, an opened phishing attachment) the first question is what you as an organisation did to prevent that error. "Nothing" is not a defensible answer, certainly not with a maximum fine of €10 million or 2% of worldwide turnover for this category of failing (art. 83(4)). How to put GDPR awareness into practice is covered in [GDPR security awareness training](/en/gdpr-security-awareness-training).

### NEN 7510: the standard for healthcare

Healthcare providers have a framework of their own in NEN 7510, the Dutch healthcare information security standard. Since 1 December 2024, NEN 7510-1:2024 plus 7510-2:2024 apply, following the structure of ISO 27002:2022: awareness sits in control 6.3. Formally NEN 7510 is a standard, but it is anchored in Dutch legislation including the Wabvpz and the decree on electronic data processing by healthcare providers (Besluit elektronische gegevensverwerking door zorgaanbieders), and the Dutch Health and Youth Care Inspectorate (IGJ) expects demonstrable compliance. That includes an independent assessment at least once every three years.

In practice this means a healthcare organisation cannot skip awareness training by arguing that "it is only a standard". The detail (which version applies, what the IGJ asks for and how to go about it) is in [NEN 7510 awareness training](/en/nen-7510-awareness-training).

## Certifications and contracts: ISO 27001, SOC 2, PCI DSS and TISAX

Certifications are formally voluntary, but in practice often as compelling as a law. More and more purchasing conditions and public tenders require a certificate simply to be allowed to bid, and that certificate in turn requires auditable training. The obligation then comes not from The Hague or Brussels, but from your own order book.

### ISO/IEC 27001:2022

Annex A control 6.3 ("Information security awareness, education and training") requires personnel and relevant interested parties to receive appropriate awareness, education and training, with regular updates, relevant to their role. Clause 7.2(d) obliges you to retain "documented information as evidence of competence", and clause 7.3 requires employees to know the policy, understand their own contribution and know the consequences of non-conformity. ISO 27002 adds at 6.3 that understanding must be tested: a test, then, not just an attendance list.

Auditors translate that into four pieces of evidence: a training plan, participation records, proof of competence per role, and a measurement of effectiveness. What that means for the design of your programme is covered in [ISO 27001 awareness training](/en/iso-27001-awareness-training).

### SOC 2

SOC 2 touches training through CC1.4 ("commitment to competence"). Auditors like to see a completion register covering the whole audit period: a training session you organise two weeks before the audit does not cover a report spanning twelve months.

### PCI DSS v4.0

If you process card payments, PCI DSS applies: see also the full guide [PCI DSS security awareness training](/en/pci-dss-security-awareness-training). Requirement 12.6.1 demands a formal security awareness programme for all personnel, 12.6.3 requires training on joining and at least annually thereafter, and 12.6.3.1, mandatory since 31 March 2025, prescribes that the training covers phishing and social engineering. Enforcement runs through the card brands and acquirers.

### TISAX

In the automotive supply chain, TISAX applies. VDA ISA question 2.1.3 requires awareness training with mandatory periodic repetition. Without a TISAX label you simply do not get a look-in with many manufacturers and suppliers.

### And Cyber Essentials? The honest answer: no training requirement

For completeness: the UK's Cyber Essentials does not require security awareness training. Anyone telling you that you "have to train for Cyber Essentials" has it wrong. That does not mean training outside the frameworks above is pointless: frameworks such as CIS Controls v8 (Control 14: training on joining and at least annually thereafter, safeguard 14.1) and NIST CSF 2.0 (category PR.AT) do include it as a core measure, but it pays to know exactly which framework requires what, and which one requires nothing.

## What does 'demonstrable' mean for the audit?

One word comes back in almost every framework: demonstrable. BIO2 requires "demonstrably" completed information security awareness training, ISO 27001 asks for "evidence of competence", the Cbw requires a certificate from management body members, and SOC 2 auditors want a register covering the whole audit period. A well-meant lunch session without registration counts for no framework at all, not because the session was worthless, but because you cannot prove it happened.

In practice, auditors and regulators ask for four kinds of evidence:

1. **Training records.** Who was invited to which training and when, and who took part? Per employee, with a date, so you can also show that new colleagues started on time.
2. **Completion evidence and certificates.** Not just "invited" but successfully completed, with test results where the standard requires testing (ISO 27002 at 6.3) and with a certificate where that is mandatory (Cbw art. 24 for management body members).
3. **Phishing results.** Since PCI DSS 12.6.3.1 explicitly requires phishing and social engineering as part of training, simulation results are a logical piece of evidence: they show that you transfer knowledge and measure behaviour.
4. **Coverage over time.** New employees within the deadline (three months under BIO2), repetition at least annually where that is required, and no gaps in the audit period.

Keep this in spreadsheets and every audit costs you days, and one missed record is a finding. This is exactly what CyberPulse was built for: the platform records training participation, quiz results, certificates and phishing results per employee, so you can hand over the evidence auditors and regulators ask for in a single report. [Try it free](/trial) and see what that record looks like for your organisation.

## Which training qualifies? The checklist

The frameworks differ in scope, but their requirements for the training itself point in strikingly similar directions. Work through this checklist:

- **Everyone in scope.** All employees and senior management (DORA art. 13(6)), including contractors where BIO2 applies (6.03.02). Exceptions for "the board" or "the production floor" stand out immediately in an audit.
- **Management body arranged separately.** Under the Cbw, members of the management body need demonstrable knowledge and skills within two years, with a certificate from a training course (art. 24).
- **Start on joining.** BIO2 allows three months; PCI DSS (12.6.3) and CIS Controls (14.1) tie training to onboarding. Do not wait for the next annual round.
- **Continuous, not one-off.** ISO 27001 asks for regular updates (A 6.3), BIO2 for regular training (5.04.01), TISAX for periodic repetition and PCI DSS for at least annually. One session a year is minimum thinking; continuous micro-learning keeps knowledge fresh and fills your records all year round.
- **Matched to the role.** DORA requires complexity "commensurate to the remit of their functions"; ISO 6.3 asks for relevance to the role. A system administrator needs different training from a receptionist.
- **Phishing and social engineering included.** A mandatory component under PCI DSS 12.6.3.1, and everywhere the most practical part of the programme. Combine explanation with simulations, so you measure behaviour as well.
- **Test understanding.** ISO 27002 expects understanding to be tested at 6.3. Quizzes deliver the proof of competence that clause 7.2(d) asks for at the same time.
- **Automatic record-keeping.** Every completion, test and simulation captured per employee as it happens: otherwise you prove nothing at the audit.

If your current approach ticks all of these boxes, you are in good shape for every framework named above. If not: start with the framework that applies to you. The [knowledge base](/en/knowledge-base) has a dedicated page for each law and standard, from [the training requirements of the Dutch Cybersecurity Act](/en/dutch-cybersecurity-act-training-requirements) to [ISO 27001](/en/iso-27001-awareness-training). If you are an IT partner or MSP and want to arrange this for your customers, take a look at [/partner](/partner). And keep an eye on the calendar: with the Cbw entering into force on 15 August 2026, "later this year" is no longer a plan but a delay.

## Frequently asked questions

### Is security awareness training required by law?

For a growing group of organisations: yes. The Dutch Cybersecurity Act (from 15 August 2026) requires cybersecurity training as part of the duty of care (art. 21(2)(g)), DORA has required awareness modules across the financial sector since 17 January 2025 (art. 13(6)), and BIO2 requires demonstrable training for government bodies and their suppliers (measure 6.03.02). If none of these applies to you, training may still be expected (GDPR, NEN 7510) or required by contract (ISO 27001, PCI DSS, TISAX).
### Who does the Dutch Cybersecurity Act apply to?

The Cbw applies to around 8,000 organisations across the 18 sectors listed in Annexes I and II of the NIS2 Directive. The threshold sits roughly at more than 50 employees or more than €10 million in turnover or balance sheet total. Organisations in scope face a registration obligation (the entity register of the Dutch National Cyber Security Centre), a duty of care, a reporting obligation for significant incidents and management accountability. Supervision sits with the Dutch Authority for Digital Infrastructure (RDI), among others.
### What is the difference between NIS2 and the Cbw?

NIS2 is the European directive (Directive (EU) 2022/2555); the Dutch Cybersecurity Act is the Dutch law implementing that directive and replacing the Wbni. A directive does not apply directly: only the Cbw makes the obligations, including the training requirement in the duty of care and the training obligation with a certificate for management body members (art. 24): enforceable in the Netherlands. The Cbw was passed on 7 July 2026 and takes effect on 15 August 2026. Other EU member states have their own implementing law.
### Is an annual e-learning enough for ISO 27001?

Not by itself. Annex A 6.3 asks for training that is relevant to the role, with regular updates: one generic module a year covers that thinly. Clause 7.2(d) also requires retained evidence of competence, and ISO 27002 expects understanding to be tested. Auditors look for a training plan, participation records, proof of competence per role and a measurement of effectiveness. An annual e-learning can be part of the programme, but without testing, differentiation and record-keeping you will fall short at the audit.
### Do I have to be able to prove training took place?

Yes: in virtually every framework, evidence is the core. BIO2 literally requires employees to have "demonstrably" completed information security awareness training within three months, ISO 27001 requires you to retain "evidence of competence" (clause 7.2(d)), the Cbw requires a certificate from management body members (art. 24) and SOC 2 auditors want a completion register covering the whole audit period. So make sure you record per employee: participation, completion, test results and, where relevant, phishing simulation results.
### What does non-compliance cost?

That depends on the framework. NIS2 requires that fines can run to at least €10 million or 2% of worldwide annual turnover for essential entities, and €7 million or 1.4% for important entities; the exact Dutch amounts are set out in the Cybersecurity Decree. Management body members can be held liable and, under the Cbw, even suspended (art. 78). For failing measures, the GDPR sets a maximum of €10 million or 2% (art. 83(4)). Under PCI DSS, enforcement runs through the card brands and acquirers, and with certifications you lose contracts.

## Sources

- [Dutch government, Cybersecurity Act in force from 15 August 2026](https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht)
- [EUR-Lex, NIS2 Directive (EU) 2022/2555](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555)
- [EUR-Lex, DORA Regulation (EU) 2022/2554](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554)
- [Wetten.overheid.nl, BIO2 circular (BWBR0052376)](https://wetten.overheid.nl/BWBR0052376/)
- [NCTV, management accountability and the training obligation for management body members](https://www.nctv.nl/onderwerpen/c/cyberbeveiligingswet/bestuurlijke-verantwoordelijkheid-en-opleidingsplicht-voor-bestuurders)
- [EUR-Lex, GDPR, Regulation (EU) 2016/679](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679)
- [IGJ, questions about NEN 7510](https://www.igj.nl/vraag-en-antwoord/vragen-over-nen-7510)
