# White label security awareness training for MSPs and IT partners (2026)

> Offer security awareness training and phishing simulations to your clients under your own brand. Without building a platform, and with the audit evidence the Dutch Cybersecurity Act asks of your clients from 15 August 2026.

- Canonical: https://cyberpulse.it/en/white-label-security-awareness-training
- Dutch version: https://cyberpulse.it/white-label-security-awareness-training
- Published: 2026-08-09
- Updated: 2026-08-25
- Publisher: CyberPulse (https://cyberpulse.it)

With white label security awareness training you deliver security awareness training to your clients under your own brand name: complete with phishing simulations, weekly micro-learning and per-employee audit evidence, without building a platform or writing content yourself. CyberPulse supplies the technology and the content; you supply the service under your logo, your colours and your own subdomain. And the timing could hardly be better: from 15 August 2026, thousands of Dutch organisations have to have their training demonstrably in order.

## Why now? From 15 August 2026 your Dutch clients have to evidence this

The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw) is the Netherlands' implementation of NIS2. It was passed by the Dutch Senate on 7 July 2026 and takes effect on 15 August 2026. The act reaches around 8,000 organisations across 18 sectors. The threshold: more than 50 employees or more than €10 million in turnover or balance sheet total. That is precisely the SME segment an MSP serves day in, day out.

Be clear about one thing: this deadline is Dutch. NIS2 is an EU directive and every member state transposes it in its own law, on its own timetable: the 15 August 2026 date, the 18 sectors and the roughly 8,000 organisations are specific to the Netherlands. If your clients are Dutch, or you serve the Dutch entities of an international group, that is the date your phone will ring about.

The duty of care in the act names training in so many words:

> "basic cyber hygiene practices and cybersecurity training". NIS2 art. 21(2)(g), transposed into Dutch law as Cbw art. 21 paragraph 2 under g

And it does not stop at the shop floor. Members of the management body at your clients must demonstrably possess the relevant knowledge and skills within two years, with a mandatory certificate from a training course (Cbw art. 24), and they can be held personally liable. NIS2 also sets maximum fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities.

Your clients will call about this, and they will call you, because you are their IT partner. The only question is whether you then have a service of your own to offer, or have to refer them elsewhere. With a [white-label partnership](/partner) you have the answer ready under your own brand, and you build a recurring service with a margin on it at the same time.

## What is white-label security awareness training?

White-label means you offer a ready-made training platform as if it were your own product. CyberPulse is a Dutch security awareness and phishing simulation platform that runs entirely under your own flag for MSPs and IT partners: your brand name, your logo and colours, and your own subdomain where your clients log in.

To your clients it feels like your service. For you it means you do not have to build a platform, do not have to write weekly content and do not have to run phishing infrastructure. You focus on what you already do well: the client relationship, the advice and the services around it.

The difference with reselling somebody else's product is in the brand experience. With white-label, every weekly lesson reinforces your positioning as the security partner, not that of a vendor your client could just as easily approach directly tomorrow.

## What do you get as a partner?

Three things make the partner model work in practice:

**Your brand, everywhere.** The platform runs under your brand name, with your logo and colours, on your own subdomain. Invitations, lessons, quizzes and certificates: your clients see your service, from the first login to the last certificate.

**Central reporting per client organisation.** You manage all your clients from one place and see per organisation how participation, quiz results and phishing results are developing. That means you walk into every quarterly review with a concrete story instead of a gut feeling.

**No implementation burden.** The content is ready: a continuous weekly programme of Dutch-language micro-learning (the platform interface is also available in English), phishing simulations and quizzes. Add a client, invite the employees, done. No content team or e-learning project is needed on your side.

And perhaps the most important part for the compliance conversation: the platform records training participation, quiz results, certificates and phishing results per employee. That is precisely the evidence auditors and supervisory authorities request from your clients, and that you, as their partner, can supply from a single report.

## What do your clients experience?

For your clients' employees it is not a two-hour mandatory e-learning once a year, but a weekly rhythm. Every week a short micro-learning is waiting: a few minutes of learning, a quiz, done. Short enough to keep up, frequent enough to stick.

What holds attention is the story. Together the lessons form a continuous espionage narrative around the character Cipher, which brings employees back for the next instalment, not only because they have to. Security awareness becomes something people talk about over coffee rather than something they click away.

In between, phishing simulations test whether the theory lands in practice: simulated phishing emails that measure who clicks and who reports. The results land per employee in the reporting, so you and your client can see where things are going well and where extra attention is needed.

And all of it happens under your brand. Your client's employee experiences a well-made training service from their trusted IT partner: which is you.

## Compliance as a sales conversation

In 2026 you no longer have to open the sales conversation with worst-case scenarios: the standards do the work. Beyond the Cbw there is broader pressure. ISO 27001 asks in Annex A control 6.3 for appropriate awareness training, and in clause 7.2 for documented evidence of competence. NEN 7510 (the Dutch healthcare information security standard) sets comparable expectations for care organisations. BIO2 (the Dutch government's baseline information security standard) obliges public sector organisations, and works through to their suppliers via contracts, to deliver a demonstrable information security awareness training within three months of joining. And the GDPR prescribes no specific course, but without demonstrable awareness you do not meet the appropriate organisational measures of article 32.

For you as a partner that means: almost every client has a standard, a law or a certification that asks for demonstrable training. You do not have to sell them something they do not need: you only have to show them what is already being asked of them.

So pass these knowledge base guides on to your clients: [is security awareness training mandatory?](/en/security-awareness-training-mandatory) for the complete overview per law and standard, and [the training requirements of the Dutch Cybersecurity Act](/en/dutch-cybersecurity-act-training-requirements) for the Cbw detail. Two readable articles that open the conversation for you, so all you have to do is finish it.

## How to get started

From interest to first client in five steps:

1. **Try it yourself first.** Start a [free trial](/trial) and go through a few weeks as a participant, so you know what your clients will experience.
2. **Apply as a partner.** Request the partnership via [/partner](/partner); we set up your environment together.
3. **Set up your brand.** Brand name, logo, colours and your own subdomain: after that everything runs under your flag.
4. **Onboard your first client.** Add the organisation and invite the employees; the weekly programme starts by itself.
5. **Report and deepen.** Use the central per-client reporting as a fixed part of your quarterly reviews, and as audit evidence when the accountant, auditor or supervisory authority asks for it.

The Cbw takes effect on 15 August 2026 and your clients are looking right now for someone to arrange this for them. Make sure that someone is you: under your own brand.

## Frequently asked questions

### Will my clients see that it is CyberPulse?

No. With white-label the platform runs entirely under your brand: your brand name, your logo and colours, and your own subdomain where your clients log in. From the invitation email to the weekly lessons and the certificates, your client's employees experience a service from their own IT partner. CyberPulse supplies the technology and the content in the background; the brand experience and the client relationship stay yours.
### Who handles the administration?

You manage your clients centrally from one place: adding organisations, inviting employees and following the reporting per client organisation. The content burden does not sit with you: the weekly programme of Dutch-language micro-learning, quizzes and phishing simulations is ready and keeps running without you having to produce anything for it. Day-to-day work per client is therefore limited to onboarding, monitoring and discussing the results.
### Which clients is this interesting for?

Certainly for clients in scope of the Dutch Cybersecurity Act: organisations in the 18 designated sectors with more than 50 employees or more than €10 million in turnover or balance sheet total: around 8,000 organisations in the Netherlands. On top of that there is broader standards pressure: clients with an ISO 27001 certification, care organisations under NEN 7510, government suppliers that inherit BIO2 through contracts, and really any organisation that has to demonstrate appropriate organisational measures under the GDPR.
### Can I test it myself first?

Yes. Start a free trial and go through the programme yourself: the weekly micro-learning, the continuous espionage story, the quizzes and the reporting. That way you know exactly what your clients will experience before you offer it under your own brand, and you can talk about how it works first-hand in sales conversations.
### Is the content in Dutch?

Yes, the training content is Dutch-language: weekly micro-learning with a continuous espionage story, written for Dutch working practice. For international teams the platform interface is also available in English. For SME clients in the Netherlands that is a real difference compared with translated foreign programmes: employees drop out less quickly when the training is in their own language and context.
### How do I help my clients demonstrate compliance?

The platform records training participation, quiz results, certificates and phishing results per employee. That is exactly the kind of evidence auditors and supervisory authorities request for the duty of care under the Dutch Cybersecurity Act, for ISO 27001 (evidence of competence, clause 7.2) and for comparable standards. As the partner you supply it per client organisation from the central reporting, so your client does not have to hunt for evidence when an audit or inspection comes.

## Sources

- [Dutch government, Cybersecurity Act in force from 15 August 2026](https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht)
- [Dutch National Cyber Security Centre (NCSC), duty of care under the Cbw](https://www.ncsc.nl/cyberbeveiligingswet-nis2/zorgplicht)
- [EUR-Lex, NIS2 Directive (EU) 2022/2555](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555)
- [NCTV, management responsibility and the training obligation for members of the management body](https://www.nctv.nl/onderwerpen/c/cyberbeveiligingswet/bestuurlijke-verantwoordelijkheid-en-opleidingsplicht-voor-bestuurders)
