The Dutch Cybersecurity Act calls not only for secure systems, but also for people who recognize risks and know how to act. This masterclass makes that awareness concrete and demonstrable.
Since 15 August 2026 more than 8,000 organizations face new cybersecurity obligations. Those obligations are not only about technology. Cyber hygiene, awareness and training are part of the statutory approach as well.
This masterclass helps organizations give concrete substance to that. Staff learn how they can be used as the way in and which signals precede an approach. With this masterclass your organization demonstrably invests in cyber awareness and safe behavior. Participation is demonstrable with the IACA certificate of attendance.
On 15 August 2026 the Dutch Cybersecurity Act (Cyberbeveiligingswet) and the Critical Entities Resilience Act came into force. The Cybersecurity Act implements the European NIS2 Directive. The Critical Entities Resilience Act separately implements the European CER Directive. Organizations covered by the act are classified as essential or as important entities. Suppliers that do not fall under the act themselves can still be affected through the requirements their clients impose.
The duty of care is set out in article 21 of the act. Organizations take appropriate technical, operational and organizational measures to manage their risks. Cyber hygiene and cybersecurity training are named explicitly among the minimum measures. A reporting duty and a registration duty apply as well.
Staff do not carry a general, personal training and certificate obligation. The responsibility sits with the organization. Article 12 of the Cyberbeveiligingsbesluit covers personnel and other people working within the entity. They must be aware of the risks to the network and information systems, in so far as this is relevant to their role. They must also apply cyber hygiene practices.
The organization additionally designates the people whose roles require knowledge and expertise in cybersecurity. They must receive regular training. According to the official explanatory notes, a course or training program can be used for this.
Executive board members carry a separate, personal obligation, laid down in article 24 of the act. They must have the knowledge and skills to identify risks and to assess risk management measures. For that they follow appropriate training and must be able to show a certificate. Supervisory board members and non-executive directors are exempt.
The term is two years. Board members already in office on 15 August 2026 therefore have until 15 August 2028 at the latest. Anyone appointed after 15 August 2026 has two years from their appointment. From then on the knowledge must be kept demonstrably up to date.
The Cyberbeveiligingsbesluit sets out what that board-level certificate must state as a minimum. That is the name of the board member, the dates of the training, the topics covered and the name of the provider. The certificate is drawn up in Dutch or English.
All of this aligns with basic principle 2 of the Dutch National Cyber Security Centre, Promote safe behavior. The NCSC advises organizations to build a security culture, to support staff with awareness and training and to facilitate safe behavior technically. That is practical guidance rather than a legal standard. The legal basis sits in article 21 of the act and article 12 of the Cyberbeveiligingsbesluit.
Finally, an important caveat: this masterclass is an awareness program, not legal advice. For staff a personal certificate is not a legal requirement; the IACA certificate evidences that the training was completed. For board members a statutory training and certificate obligation does apply. Whether a board-level course meets all legal requirements in a specific situation is for the competent regulator to assess.
The Dutch Cybersecurity Act also calls for appropriate technical, operational and organizational measures, a working reporting process and registration in the entity register of the NCSC. A single training course therefore does not make an organization compliant, but it is a concrete and demonstrable step within the wider approach to cyber resilience.