On 15 August 2026 the Dutch Cyber Security Act (Cyberbeveiligingswet, Cbw) entered into force, after the Senate (Eerste Kamer) approved it on 7 July 2026. With that, the European NIS2 Directive has become law in the Netherlands for an estimated 8,000 organisations. So far, most of the attention has gone to the technical and organisational measures. But the Act places responsibility firmly in one place: with the board. And that board has a deadline. By 15 August 2028 at the latest, board members must demonstrably have the knowledge and skills to assess and manage cyber risks.
This article looks at what that board-level responsibility actually means, what the training obligation asks of you, and how to organise it so that you can prove it later.
The board is responsible, not the IT department
The Cbw makes cyber security a board matter. The management board of an essential or important entity must approve the measures the organisation takes to meet its duty of care and must oversee their implementation. The board is therefore responsible for compliance with the Act.
That changes the dynamic. A CISO or security officer can organise the execution, but ultimate responsibility does not move with it. The NCTV (the Dutch National Coordinator for Counterterrorism and Security) puts it clearly: the board must actively keep itself informed about cyber risks and discuss the subject regularly at board level. An annual presentation from IT is therefore not enough. The Act expects you, as a board member, to understand where the risks are, which measures address them and whether those measures actually work.
Three core obligations you sign off on
The Cbw contains three core obligations for which the board is ultimately responsible:
For each of these obligations the same applies: the board must know whether they have been fulfilled, and must be able to substantiate that.
The training obligation: what exactly is expected of you
The training obligation is the most personal part of the Act. Board members must have sufficient knowledge and skills to recognise and assess cyber risks and to steer how they are managed. Three rules apply:
The word "demonstrably" is the crux here. According to the NCTV, board members receive a certificate after training, listing the topics covered. That certificate is the evidence, but only if you keep it, link it to the right person and monitor its expiry date. And when a board member is replaced, the clock starts again for the new member.
Personal liability and sanctions
Supervisory authorities, including the RDI (the Dutch Authority for Digital Infrastructure) and other sector-specific regulators, can impose administrative sanctions. These include an order subject to a periodic penalty payment or an administrative fine. What is new is that these sanctions can also be imposed on individual board members, for example where the training obligation is not met. For essential entities, the ultimate measure can even be a temporary ban on holding management positions.
For the organisation itself, fines can reach 10 million euros or 2% of worldwide annual turnover for essential entities, and 7 million euros or 1.4% for important entities.
This is not about scaremongering. It is about the legislator having deliberately chosen to stop treating cyber security as a departmental problem and to treat it instead as a board responsibility with personal consequences.
How to organise it demonstrably
What can you, as a board, do right now? A practical checklist:
How uComply helps
uComply makes the role of the board visible in the compliance loop. The CBW/NIS2 control framework developed by the NCSC, including the underlying Cyber Security Decree, is built into the platform as a working set of standards. You record policy and measures with an owner and evidence, and you attach the board's approval decision directly to them, so that the approval is traceable. You document the management review in uComply, including findings, decisions and assigned actions, with follow-up that does not slip out of sight.
Training and refresher training for board members are recorded as tasks with an owner and a deadline; the certificate is attached as evidence. With Reminders and scheduled tasks you plan the periodic refresher as a series in one go, and uComply taps the board member on the shoulder in time. And with the Flightdeck dashboard the board sees at a glance the compliance score, open risks, findings, progress per standard and the status of legal obligations. Exactly the up-to-date insight the Act requires of board members.
Summary
The Dutch Cyber Security Act has been in force since 15 August 2026 and places responsibility for cyber security with the board. By 15 August 2028 at the latest, board members must demonstrably have the required knowledge and keep it up to date thereafter. Sanctions can also be imposed personally. Those who set up approval, the management review and training records properly now will not have to hunt for evidence later.
Would you like to see how your board can demonstrably take control? Book a no-obligation demo or view our pricing.



