Current

Cybersecurity & Certifications:
from awareness to legislation and certification

Six in-company courses around one question: how do you keep your organisation digitally safe, and how do you show that you do? From awareness for all staff and the obligations of the Dutch Cybersecurity Act to officially recognised Microsoft exams for your administrators.

Beginner to expert
Online or on-site
Max. 12 participants
Cybersecurity training at Mellaart Trainingen
The offer

Choose the training that suits your team

From digital awareness for all staff to recognised Microsoft certifications for IT professionals. Every training is in-company and fully tailored.

Cybersecurity Awareness

Half or full day · All staff

Your team learns to recognise and prevent digital threats: phishing, social engineering, password security and safe remote working. Practical, recognisable and immediately applicable.

Phishing recognition Password security Safe working

NIS2 Compliance

Full day · Beginner-Advanced

What does the NIS2 directive mean for your organisation? Your team learns what obligations apply, what risks exist and how to remain demonstrably compliant.

Legislation & compliance Risk analysis Policy

SC-900

1 day · Beginner

Microsoft Security, Compliance and Identity Fundamentals. The entry-level certification for anyone working with Microsoft 365 or Azure who wants to understand the basics.

Microsoft exam Security basics Compliance

AZ-900

2 days · Beginner

Microsoft Azure Fundamentals: cloud concepts, Azure services, security and pricing models. A solid foundation for further Azure certifications.

Cloud fundamentals Azure Microsoft exam

MS-700

4 days · Advanced

Managing Microsoft Teams: administrator skills for Teams admins, from configuration and policy to security, compliance and lifecycle management.

Teams management Security Policy settings

AB-900

1 day · Beginner

Microsoft 365 Copilot & Agent Administration Fundamentals: the basics of Copilot administration, AI agents and governance within Microsoft 365. Prepares you for the official AB-900 exam.

Copilot administration AI agents Microsoft exam
Choice guide

Awareness, legislation or a certificate: where do you start?

These six courses solve different problems and are poor substitutes for one another. A certification track does not make your people more alert, and a day of awareness produces no exam result. Below is what each of the four groups is good at, and where the limit lies.

Awareness for all staff

Phishing, fake invoices, someone following a colleague through the door, and these days a phone call in a voice that sounds like the director. The value is not in listing threats but in practising with messages that resemble your own: your house style, your suppliers, your payment process. The conversation is then about what should have stood out, rather than about an example from a leaflet.

Where it stops: one day changes behaviour for about six weeks. Without repetition, without a reporting button that works and without a culture in which a wrong click can be reported without fuss, it fades. We would rather plan two shorter sessions with time in between than one long day.

Cybersecurity Awareness training

Complying with the Dutch Cybersecurity Act

Since 15 August 2026, NIS2 is law in the Netherlands. If your organisation is covered, you register with the NCSC, take risk management measures and report significant incidents within 24 hours. The board approves those measures and, since this Act, carries a training obligation of its own, with a transition period until 15 August 2028.

Where it stops: training does not make you compliant. Your inventory, your policy and the evidence behind it stay your own work. What the day does do is put the board in a position to judge whether what exists is enough, and make visible where the gaps are.

NIS2 Compliance training

Microsoft fundamentals: SC-900 and AZ-900

Two entry-level certifications that are often requested together. SC-900 covers security, identity and compliance across Microsoft 365 and Azure: who may access what, how conditional access works, what happens with labels and retention. AZ-900 covers the cloud itself: what a region is, what you are buying and what you are paying for. For most teams AZ-900 is the logical first, because SC-900 leans on concepts explained there.

Where it stops: a fundamentals certificate gives a shared vocabulary, not professional competence. It is meant for people who need to follow the conversation, such as procurement, project management and functional administration, not as training for whoever actually configures the environment. What such an exam does and does not test, and why a fundamentals certification never expires while a role-based one has to be renewed every year, is set out in AZ-900: what the certification is and is not.

AZ-900 Azure Fundamentals SC-900 Security, Compliance & Identity

Administration and governance: MS-700 and AB-900

For the people who actually configure the environment. MS-700 covers Microsoft Teams: policies, guest access, meeting settings and the life cycle of teams and channels, including what happens to a team nobody uses any more. AB-900 is the newest in the series and covers the administration of Microsoft 365 Copilot and the agents your colleagues build themselves: who may create one, which data it may reach and how you can see that afterwards.

Where it stops: both are about settings you control. Whether your colleagues also do what the policy intends is a different question, and it belongs with awareness, or with training on the application itself.

MS-700 Managing Microsoft Teams AB-900 Copilot & Agent Administration
Choice guide

Which training suits you?

From awareness for all staff to official Microsoft certifications for IT professionals. Here's how to choose the right training.

Awareness & compliance

For all staff who want to work consciously and safely with digital tools.

Microsoft certifications

For IT professionals and administrators who want to obtain an official Microsoft certificate.

Legislation

What the Dutch Cybersecurity Act asks of you

Of all the questions we were asked on this subject this year, most concern one law. NIS2 is a European directive and does not apply directly; in the Netherlands it has been translated into the Cyberbeveiligingswet, the Dutch Cybersecurity Act, which entered into force on 15 August 2026. More than eight thousand organisations across eighteen sectors are covered. Whether you are one of them is something you determine yourself, based on your sector and your size, and nobody will notify you.

  • Registration. If the Act applies to you, you register in the entity register held by the NCSC. That obligation has applied since the day the Act took effect.
  • Duty of care and reporting duty. You carry out a risk analysis, take appropriate and proportionate measures, and report a significant incident within 24 hours to the CSIRT and to the supervisor for your sector. A substantive notification follows within 72 hours, and a final report after one month at the latest.
  • Training obligation for the board. Executive directors of essential and important entities must be able to assess the risks themselves. Directors already in post have until 15 August 2028, and keep that knowledge current afterwards. Employees are not under a personal training obligation, but cyber hygiene and cybersecurity training are among the measures you take under the duty of care.

Those last two rules explain why organisations usually ask us for two things at once: a session for the board and recurring awareness for everyone. What the Act contains, who it applies to and what you have to be able to show afterwards is set out on the page about the NIS2 Compliance training.

Certifying

Do you need a certificate, or a habit?

“Which cybersecurity certificates do we need?” is a question we hear often, and the honest answer is usually: fewer than you think, and for different people than you thought. A certificate is evidence of knowledge at a moment in time. It says nothing about how your environment is configured and nothing about how your colleagues handle a suspicious email. Two reasons to choose one anyway do hold up.

  • Someone asks for it. In tenders, in an audit, or from a client who wants to know whether your administrators know what they are doing. An official Microsoft exam is then the shortest route to an answer that counts.
  • It forces completeness. An exam syllabus walks through topics you would skip in a tailored course because they do not apply to you right now. That is sometimes exactly where the gap is.

If neither applies, a course built on your own environment usually delivers more than an exam. We say so even when you ask for the exam: it saves you a day and gives your team more. And the other way round, if you do certify, we prepare for the real exam, including the question formats, so the result is no surprise. You sit the exam itself at a Microsoft test centre or online; we do not administer it.

One thing holds for everyone: there is no awareness certificate worth having. What counts there is repetition, and the number of reports that reach you. That second figure should rise when an awareness programme works, which tends to surprise boards.

By role

The same threat, different work

A director, a management assistant and a systems administrator run into very different versions of the same problem. The director has to weigh a risk without knowing the technology, the assistant is the first to see the fake invoice and the urgent request, and the administrator has to be able to configure the policy. We match the examples to the role; for three groups we have set that out in an entry of its own.

Managers and leaders

Weighing risks without knowing the technology, approving measures and being able to show that you did so carefully.

Secretaries and assistants

Fake invoices, urgent requests on behalf of a director, other people's calendars and mailboxes, and sharing safely with parties outside the organisation.

Teams and departments

Agreements everyone keeps: what you report, to whom, and what happens when someone clicks anyway.

Does your team work in another field? Every course is in-company and is built around your own work. These three are simply the entries the question came from most often.

Where and how

At your location, online or blended

We are based in The Hague and train throughout the Netherlands. In practice we are most often with organisations in the Randstad, in The Hague, Rotterdam, Amsterdam, Utrecht, Leiden and Delft, but distance is no obstacle: a day in Eindhoven, Zwolle or Groningen takes the same preparation.

  • At your location. The most common choice, and clearly the best one for awareness: we use your own house style, your supplier names and your own payment process in the examples.
  • Online. In Teams, preferably in half-days. Practical for organisations spread across several sites, and for a board that struggles to free up a whole day.
  • Blended. A day on site and a shorter follow-up session online a few weeks later. For awareness that is not a luxury but the difference between remembering and forgetting.

A course runs for a day as standard, with a maximum of twelve participants. A half-day workshop on a single subject is possible too, for instance a session for the board or a phishing workshop for one department. The certification courses follow the length of the exam syllabus: SC-900 and AB-900 one day, AZ-900 two days, MS-700 four. We train in English and in Dutch.

Our approach

From need to result

Every training is tailored to your organisation, your work processes and the level of your team.

1

Explore

What's really going on? Through intake and observation we map your reality.

2

Design

Materials and methods tailored to your team, tools and daily context.

3

Practise

Doing, not just listening. Cases from your own practice, immediately applicable.

4

Embed

Commitments and follow-up so what's learned sticks beyond the training day.

Frequently asked questions

What people usually want to know

All our courses in this category are in-company, which means there is no rate per participant. What a day costs depends on group size, duration, format and how much preparation is needed to work with your own situation. Tell us what you are looking for and you will have a tailored proposal within two working days.

Yes, if your organisation is covered by the Dutch Cybersecurity Act. That Act places a training obligation on the executive directors of essential and important entities: they must be able to assess the risks to their network and information systems. Supervisory board members and non-executive directors are not covered. Directors already in post have until 15 August 2028.

Employees are not under a personal training obligation. Cyber hygiene and cybersecurity training are, however, among the measures you have to take under the duty of care, which makes them recurring rather than one-off. What works in practice is an annual session with a short refresher in between, and a reporting process people actually dare to use.

No. We prepare for SC-900, AZ-900, MS-700 and AB-900, including the question formats you will meet in the exam, so the result is no surprise. You sit the exam itself at a Microsoft test centre or online through their own exam environment. We do help with planning and with the question of which exam fits which role.

The full-day Cybersecurity Awareness course includes an exercise with phishing messages that resemble your own. We do not offer a running simulation service in which test emails go out to your staff for months on end; that works better through your own managed service provider or through the tooling already in your Microsoft 365 environment. We are happy to help read the results.

Yes. We are based in The Hague and train throughout the Netherlands, at your own location. Rotterdam, Amsterdam, Utrecht and the rest of the Randstad are the familiar route, but Eindhoven, Zwolle or Groningen works just as well. We also train online, which for a board that struggles to free up a whole day is often the practical choice.

Awareness is half a day or a full day, NIS2 Compliance a full day. The certification courses follow the length of the exam syllabus: SC-900 and AB-900 one day, AZ-900 two days, MS-700 four days. A half-day workshop on a single subject is possible too, for instance a session for the board alone.

The courses in this category are delivered to teams within one organisation. Which courses start on fixed dates and can be booked individually is shown on the open enrolment calendar.

Get started

Want to know more about cybersecurity training?

Whether it's awareness for your entire team or preparation for a Microsoft certification: we'll help you choose. Get in touch.