Back to blogNIS2

The Dutch Cyber Security Act for boards: training obligation and personal liability

uComply

Team uComply

Author

September 29, 2026

Published

On 15 August 2026 the Dutch Cyber Security Act (Cyberbeveiligingswet, Cbw) entered into force, after the Senate (Eerste Kamer) approved it on 7 July 2026. With that, the European NIS2 Directive has become law in the Netherlands for an estimated 8,000 organisations. So far, most of the attention has gone to the technical and organisational measures. But the Act places responsibility firmly in one place: with the board. And that board has a deadline. By 15 August 2028 at the latest, board members must demonstrably have the knowledge and skills to assess and manage cyber risks.

This article looks at what that board-level responsibility actually means, what the training obligation asks of you, and how to organise it so that you can prove it later.

The board is responsible, not the IT department

The Cbw makes cyber security a board matter. The management board of an essential or important entity must approve the measures the organisation takes to meet its duty of care and must oversee their implementation. The board is therefore responsible for compliance with the Act.

That changes the dynamic. A CISO or security officer can organise the execution, but ultimate responsibility does not move with it. The NCTV (the Dutch National Coordinator for Counterterrorism and Security) puts it clearly: the board must actively keep itself informed about cyber risks and discuss the subject regularly at board level. An annual presentation from IT is therefore not enough. The Act expects you, as a board member, to understand where the risks are, which measures address them and whether those measures actually work.

Three core obligations you sign off on

The Cbw contains three core obligations for which the board is ultimately responsible:

  • Registration obligation. Organisations covered by the Act register via Mijn.NCSC.nl, the portal of the Dutch National Cyber Security Centre.
  • Duty of care. Appropriate and proportionate measures to manage risks to network and information systems, from risk policy and access management to business continuity and the supply chain.
  • Reporting obligation. Significant incidents must be reported within 24 hours by means of an early warning, followed by a more detailed notification and a final report.
  • For each of these obligations the same applies: the board must know whether they have been fulfilled, and must be able to substantiate that.

    The training obligation: what exactly is expected of you

    The training obligation is the most personal part of the Act. Board members must have sufficient knowledge and skills to recognise and assess cyber risks and to steer how they are managed. Three rules apply:

    1.By 15 August 2028 at the latest (two years after entry into force), board members must have acquired that knowledge and those skills.
    2.After that, they must demonstrably keep that knowledge up to date. One training course in 2027 will therefore not be sufficient for the years that follow.
    3.Organisations are also encouraged to train employees regularly, so that awareness does not remain confined to the top.

    The word "demonstrably" is the crux here. According to the NCTV, board members receive a certificate after training, listing the topics covered. That certificate is the evidence, but only if you keep it, link it to the right person and monitor its expiry date. And when a board member is replaced, the clock starts again for the new member.

    Personal liability and sanctions

    Supervisory authorities, including the RDI (the Dutch Authority for Digital Infrastructure) and other sector-specific regulators, can impose administrative sanctions. These include an order subject to a periodic penalty payment or an administrative fine. What is new is that these sanctions can also be imposed on individual board members, for example where the training obligation is not met. For essential entities, the ultimate measure can even be a temporary ban on holding management positions.

    For the organisation itself, fines can reach 10 million euros or 2% of worldwide annual turnover for essential entities, and 7 million euros or 1.4% for important entities.

    This is not about scaremongering. It is about the legislator having deliberately chosen to stop treating cyber security as a departmental problem and to treat it instead as a board responsibility with personal consequences.

    How to organise it demonstrably

    What can you, as a board, do right now? A practical checklist:

  • Record the approval. Adopt the policy and the measures for the duty of care as a formal board decision, with date and version.
  • Put cyber risks on the agenda structurally. For example as a fixed item in the management review, with decisions and actions recorded.
  • Plan the training of every board member. Record who has attended which training, when, and when a refresher is due.
  • Keep the evidence centrally. Certificates, attendance lists and programmes belong in the management system, not in a personal mailbox.
  • Ensure current insight. A board that must be "actively informed" needs an overview that is correct every day, not a report from three months ago.
  • How uComply helps

    uComply makes the role of the board visible in the compliance loop. The CBW/NIS2 control framework developed by the NCSC, including the underlying Cyber Security Decree, is built into the platform as a working set of standards. You record policy and measures with an owner and evidence, and you attach the board's approval decision directly to them, so that the approval is traceable. You document the management review in uComply, including findings, decisions and assigned actions, with follow-up that does not slip out of sight.

    Training and refresher training for board members are recorded as tasks with an owner and a deadline; the certificate is attached as evidence. With Reminders and scheduled tasks you plan the periodic refresher as a series in one go, and uComply taps the board member on the shoulder in time. And with the Flightdeck dashboard the board sees at a glance the compliance score, open risks, findings, progress per standard and the status of legal obligations. Exactly the up-to-date insight the Act requires of board members.

    Summary

    The Dutch Cyber Security Act has been in force since 15 August 2026 and places responsibility for cyber security with the board. By 15 August 2028 at the latest, board members must demonstrably have the required knowledge and keep it up to date thereafter. Sanctions can also be imposed personally. Those who set up approval, the management review and training records properly now will not have to hunt for evidence later.

    Would you like to see how your board can demonstrably take control? Book a no-obligation demo or view our pricing.

    Sources

  • NCTV: Board responsibility and training obligation for board members (Dutch)
  • RDI: Cyber Security Act (Dutch)
  • NCSC: Cyber Security Act (NIS2) (Dutch)