Cybersecurity & Compliance

NIS2 Compliance training: demonstrably compliant with the Dutch Cybersecurity Act

Practical in-company training for board members, compliance officers and IT-security. Learn what the Dutch Cybersecurity Act asks of your organisation, how to meet the ten mandatory measures, how to set up your reporting process and how your board makes that accountability demonstrable.

Full day
Max. 12 participants
Online or on-site
No prior knowledge required
★★★★★Rated 4.9 · over 15 years of training experience
NIS2 Compliance training at Mellaart Trainingen

The Dutch Cybersecurity Act (Cyberbeveiligingswet) entered into force on 15 August 2026. In the Netherlands, NIS2 is no longer a directive you prepare for but law you have to comply with. Essential and important entities that cannot demonstrate compliance risk fines of up to €10 million or 2% of global annual turnover, and board members can be held personally liable.

The urgency of NIS2

NIS2 in numbers

The Dutch Cybersecurity Act places far-reaching obligations on thousands of organisations. Since 15 August 2026 this is no longer about preparing, but about compliance you must be able to demonstrate.

8,000+
organisations in the Netherlands fall under the Dutch Cybersecurity Act
24 hrs
reporting obligation for significant incidents to the CSIRT or competent authority
€10M
maximum fine for essential entities in case of non-compliance
10
categories of risk management measures under Article 21 of the NIS2 directive
The Act

What applies since 15 August 2026

NIS2 is a European directive, which means it does not apply directly. In the Netherlands it has been translated into the Cyberbeveiligingswet, the Dutch Cybersecurity Act, and that Act entered into force on 15 August 2026. For more than eight thousand organisations, meeting NIS2 is no longer an intention but a legal obligation with supervision behind it.

Registration

If your organisation falls under the Act, you have to register in the entity register held by the NCSC, through mijn.ncsc.nl. That obligation has applied since the day the Act took effect. The first question is therefore not which measures you take, but whether you know that the Act applies to you: you determine that yourself, based on your sector and your size, and nobody sends you a letter about it.

Duty of care

You carry out a risk analysis and take appropriate and proportionate measures to manage the risks to your network and information systems. What counts as appropriate depends on your size, on how dependent your work is on digital systems and on what goes wrong when they fail. The ten categories those measures have to cover come back in the programme below.

Reporting duty

In the event of a significant incident you submit an early warning within 24 hours to the CSIRT and to the supervisor that belongs to your sector. A substantive notification follows within 72 hours, and a final report after one month at the latest. Twenty-four hours sounds generous until the moment it happens. What counts then is who makes the call, with which details, and who takes that decision when the person who normally would is on holiday.

Board responsibility

The board approves the measures and supervises their implementation. That responsibility cannot be passed on to a supplier or to the IT department, and since this Act it comes with a training obligation of its own. That obligation is set out below, because it is the question we have been asked most often since August.

Training obligation

Are your directors required to follow training?

Yes. The Dutch Cybersecurity Act places a training obligation on the executive directors of essential and important entities. It concerns the people who actually run the organisation: those who approve the measures and supervise their implementation. Supervisory board members and non-executive directors are not covered.

  • What has to be covered. The risks to network and information systems, what those risks mean for your organisation, how to identify and manage them and which measures counter them. Enough to weigh the risks yourself and take a well-founded decision on them as a board.
  • When it has to be in place. Directors already in post have until two years after the Act took effect, so until 15 August 2028, to hold that knowledge. After that you keep it current. It is not a one-off exercise.
  • What you have to be able to show afterwards. Participants receive a record of attendance stating which topics were covered, in Dutch or in English. That document is what you hold towards the supervisor.
  • And employees? There is no personal training obligation for them. Cyber hygiene and cybersecurity training are among the measures you have to take under the duty of care, which in practice means recurring awareness for everyone. That is what our Cybersecurity Awareness training is for.

Our training day is built so that these topics are covered and every participant leaves with such a record of attendance. If you want the board on its own, in a shorter half-day session, that is possible too. That format is often called a boardroom session: the same content, with less time for the technical detail and more for the question of what the board has to decide now.

The programme

What your organisation will learn

An intensive full-day training for everyone involved in NIS2 compliance. From scope assessment to reporting procedures and board liability. Content is fully tailored to your sector and organisation.

1

NIS2 framework & your organisation

Understand what the NIS2 directive entails, who the Dutch Cybersecurity Act applies to and what that means for your organisation.

  • From NIS1 to NIS2, and from European directive to Dutch law
  • Scope: essential versus important entities and the 18 sectors
  • The NCSC as CSIRT and the supervisor that belongs to your sector
  • Registering in the entity register: who, when and with what
  • Self-assessment: does your organisation fall under the Act?
2

Risk management & technical measures

Implement the ten mandatory measures of Article 21 in a practical and proportionate way.

  • Risk analysis and information security policy
  • Incident handling, business continuity and backup management
  • Supply chain security and supplier security
  • MFA, encryption, access control and patch management
3

Reporting duty & incident response

Establish a working reporting procedure and know exactly what to do when a significant incident occurs.

  • What is a 'significant incident' under NIS2?
  • The three-phase reporting cycle: early warning (24h), notification (72h) and final report (1 month)
  • Reporting to the CSIRT and the sector-specific supervisor
  • Drafting and testing your incident response plan
4

Governance, audit & accountability

Ensure your board can demonstrate its responsibility and prepare for supervision and audit.

  • Board liability: what does this mean in practice?
  • Documentation, policy and evidence of compliance
  • Internal audit and NIS2 gap analysis
  • The training obligation for directors and the record of attendance
  • Roadmap to full compliance: priorities and first steps
Your benefits

Why this training?

No dry legal texts, but a practical training that lets you get to work immediately with NIS2 implementation in your organisation.

Practical and immediately applicable

No abstract legal analysis, but concrete steps, templates and checklists that you can put to use straight after the training in your compliance process.

For board and IT together

The training is structured so that board members, compliance officers and IT-security can participate simultaneously, creating shared understanding and joint ownership of the NIS2 approach.

Tailored to your sector

Whether you operate in healthcare, government, energy or financial services: we adapt the examples, case studies and sector-specific supervisors to your specific situation.

Who is it for

Is this training right for your organisation?

The NIS2 training is intended for everyone who plays a role in the implementation and governance of information security within an NIS2-obligated organisation.

Board & Management

Board members are personally liable under NIS2. Understand your responsibilities, the risks of non-compliance and how to demonstrably steer your cybersecurity strategy.

Compliance & Legal

Translate legal requirements into policy, procedures and demonstrable compliance. Learn how to conduct a gap analysis, build documentation and be ready for supervision and audit.

IT-security & CISO

Translate the ten mandatory measures into technical implementations. Learn how to assess your current security measures against NIS2 requirements and which gaps to address first.

Risk Management

Integrate NIS2 requirements into your existing risk management framework. Learn how to conduct a NIS2 risk analysis and link it to your business continuity plan.

Practical information

Everything you need to know

How it works

The training combines clear explanation of the legislation with practical case studies and working methods. Participants work on a gap analysis for their own organisation and leave with a personal action plan for NIS2 implementation. There is ample time for questions and discussion of your organisation's specific situation.

Preparation

We ask participants to complete a short questionnaire in advance about the organisation's sector, size and current security measures. This allows us to tailor the training optimally and work directly with recognisable situations.

Prior knowledge

A technical or legal background is not required. The training is deliberately designed to be accessible, so that both board members without an IT background and IT professionals without legal experience benefit fully.

Materials & follow-up

Each participant receives a comprehensive handout with the ten NIS2 measures, a gap analysis template, a reporting procedure template and an overview of relevant guidelines and sources. Follow-up is available after the training for further questions or a deepening session.

Custom combinations

Would you like to combine the NIS2 training with a Cybersecurity Awareness training for your employees, an SC-900 Microsoft Security Fundamentals certification or a technical deep-dive into Microsoft 365 security? We are happy to put together a suitable programme.

Frequently asked questions

Everything about the NIS2 Compliance training

The training is aimed at board members, compliance officers, CISOs, IT managers, risk managers and anyone responsible for complying with the Dutch Cybersecurity Act within an essential or important entity. No technical or legal background is required.

NIS2 is the European directive. A directive does not apply directly: every member state turns it into national law. In the Netherlands that law is the Cyberbeveiligingswet, the Dutch Cybersecurity Act. What you have to do is therefore set out in Dutch law, while the numbering everyone refers to, such as the ten measures of Article 21, comes from the directive.

On 15 August 2026. In the Netherlands, NIS2 is no longer a directive you prepare for but law. Registration in the NCSC entity register has been mandatory since that same date. For the training obligation for directors there is a transition period until 15 August 2028.

The Act applies to medium-sized and large organisations in 18 designated sectors, including energy, transport, banking, healthcare, drinking water, digital infrastructure, ICT services and government. You assess this yourself; you will not be notified. During the training we go through that assessment together for your situation.

Yes. The Dutch Cybersecurity Act places a training obligation on the executive directors of essential and important entities: they must be able to assess the risks to their network and information systems and know which measures counter them. Supervisory board members and non-executive directors are not covered. Directors already in post have until 15 August 2028, and keep that knowledge current afterwards.

Employees are not under a personal training obligation the way directors are. Cyber hygiene and cybersecurity training are, however, among the measures you have to take under the duty of care, which in practice means recurring awareness for everyone. That is what our Cybersecurity Awareness training is for.

Article 21 of the NIS2 directive, carried over into the Dutch Cybersecurity Act, requires organisations to implement: (1) risk analysis and security policy, (2) incident handling, (3) business continuity and crisis management, (4) supply chain security, (5) security in the acquisition and development of systems, (6) assessment of the effectiveness of measures, (7) cyber hygiene and cybersecurity training, (8) cryptography and encryption, (9) human resources security and access control, and (10) multi-factor authentication and secure communications.

In the event of a significant incident you submit an early warning to the CSIRT or the competent supervisor within 24 hours. A full notification with an initial assessment of severity and impact follows within 72 hours. After one month at the latest you submit a final report with a full description, a root cause analysis and the measures taken.

For essential entities the maximum fines are €10 million or 2% of global annual turnover, whichever is higher. For important entities that is €7 million or 1.4% of annual turnover. Board members can also be held personally liable.

Yes, all our training is available in-company, at your location or online. Content, sector-specific examples and level are fully tailored to your organisation. A shorter half-day session for the board alone is possible as well.

Yes. Popular combinations are the NIS2 training for the board alongside a Cybersecurity Awareness training for all staff, or a deeper dive into SC-900 Microsoft Security Fundamentals for the IT team. We are happy to put together a programme that fits.

Ready to get started?

Make your organisation NIS2-compliant

Fill in the form on our contact page or call us directly. We will contact you within two business days to discuss your needs. Completely without obligation.