NIS2 knowledge base

NIS2 training for directors: who must complete it?

Under the Dutch Cybersecurity Act, executive directors of essential and important entities must complete appropriate training. Supervisory boards and other governance roles also benefit from sufficient knowledge to fulfil their own responsibilities effectively.

What does NIS2 training involve and who is required to attend?

Appropriate NIS2 training gives directors enough knowledge and skill to identify cyber risks, assess risk-management practices and understand their consequences for the organisation. It connects the law with governance, critical services, protected interests, suppliers, incidents, measures, reporting and decisions.

The specific statutory training duty applies to executive directors of essential and important entities. Role-appropriate knowledge supports supervisory directors, advisory boards and audit committees even where that specific duty does not apply to them.

Which subjects should director training cover?

The programme and attendance should be documented. The organisation should be able to explain why the depth and content are appropriate to the director's role and the entity's risk profile.

  • scope and core obligations under the Dutch Cybersecurity Act;
  • executive responsibility, supervision and governance roles;
  • all-hazards risk management and protected interests;
  • duty-of-care measures, proportionality and effectiveness;
  • critical suppliers and supply-chain risk;
  • incident reporting, escalation and crisis governance;
  • management information, evidence, decisions and follow-up.

Webinar, briefing, masterclass or boardroom day?

A webinar provides orientation. The Boardroom Briefing creates a shared foundation and first agenda. The Boardroom Masterclass adds governance, risk assessment, reporting and cases. The In-company Boardroom Day applies the method to the organisation and produces a risk profile and priorities. Advanced Training offers a deeper multi-day route.

Select the format by working backwards from what participants need to understand, assess and decide afterwards.

When is a short briefing appropriate?

A briefing works well for a first shared overview, a board update or smaller organisation with a focused learning objective. It can also prepare participants for a later risk session or implementation decision.

Choose more depth when participants must assess management reporting, work through cases, evaluate proportionality or apply the framework to the organisation.

What should boards be able to do afterwards?

Participants should be able to discuss material cyber risks, understand the basis of proposed measures, ask for useful evidence, recognise supply-chain and incident implications and identify which decisions or follow-up are required.

Frequently asked questions

Who has the statutory NIS2 training duty in the Netherlands?

Executive directors of essential and important entities have the specific statutory training duty under the Dutch Cybersecurity Act.

Is a webinar sufficient?

A webinar provides orientation. Suitability for the statutory purpose depends on the documented learning objective, depth, role and ability to assess risks and measures.

Should supervisory directors attend?

Appropriate knowledge helps supervisory directors assess information, ask focused questions and oversee follow-up in their own role.

Can the training be delivered entirely in English?

Yes. Every format is available in English, including programme, discussion, cases and materials.

Choose the learning route that fits the role

We align briefing, masterclass, boardroom day or advanced training with the participants, statutory context and intended learning outcome.

Discuss the appropriate training route