← Back to knowledge base

NIS2 training obligation for boards, from Article 20 to national law

What Article 20 of NIS2 requires of boards, and how far the Netherlands, Germany, Austria, France and Spain have come in turning the training duty into national law.

Recently updated

From insight to action

See how to turn this topic into a practical awareness program with training, phishing simulations and clear management reporting.

Founder & Security Awareness Specialist · 2LRN4

Article 20 of the NIS2 directive (EU) 2022/2555 gives the management bodies of essential and important entities two duties. They must approve the cybersecurity risk-management measures and oversee their implementation, with members liable in case of negligence, and the members themselves must follow training that enables them to identify risks and to assess risk-management practices and their impact on the services the entity provides. Member states turn these duties into national law at their own pace, so the dates and details depend on where you operate.

What Article 20 asks of a board

The first paragraph of Article 20 places the approval of risk-management measures and the oversight of their implementation with the management body itself, even when the daily work sits with a CISO or an external partner. The directive states that members of the management body can be held liable for negligence in that task. For essential entities, the supervisor can in the extreme case seek a temporary ban on exercising managerial functions.

The second paragraph contains the training obligation. Members of management bodies must follow training that enables them to identify risks and to assess risk-management practices and their consequences for the services the entity provides. The level is managerial. No technical knowledge is expected, but a board member must be able to question a risk report, assess a measure and justify a decision. A generic awareness e-learning for employees therefore does not qualify as board training; it trains user behaviour, not decision-making.

One directive, five national timetables

Member states had to transpose the directive by 17 October 2024. Several missed that deadline, and the European Commission has started infringement procedures. The duties are the same everywhere, but the dates and the fine print differ per country.

The Netherlands has had the Cyberbeveiligingswet (Cbw) in force since 15 August 2026. Article 24 of that law requires executive directors to meet the training obligation within two years, so by 15 August 2028 at the latest, and introduces a certificate that must meet formal requirements.

Germany transposed the directive with the NIS2-Umsetzungsgesetz (NIS2UmsuCG), which has applied since 6 December 2025. Under § 38 BSIG, the management of particularly important and important entities must approve the risk-management measures, oversee their implementation and take part in cybersecurity training regularly. Fines can reach EUR 10 million for particularly important entities and EUR 7 million for important ones.

Austria follows on 1 October 2026, when the NISG 2026 enters into force for around 4,000 organisations in 18 sectors. § 31 of that law addresses the governance duties directly to managing directors and management boards, and makes participation in training designed specifically for leadership bodies mandatory. Penalties can reach EUR 10 million or 2% of worldwide annual turnover.

France is behind schedule. The transposition law passed its first reading in the Senate on 12 March 2025 but had not been definitively adopted as of June 2026, and the Commission opened an infringement procedure at the end of November 2024. ANSSI did publish the Référentiel Cyber France (ReCyF) on 17 March 2026, with 20 security objectives for essential entities and 15 for important ones, so the roughly 15,000 entities in 18 sectors that will be covered can already see what is coming.

Spain is also late. The council of ministers approved a draft law (anteproyecto) on 14 January 2025, but it has not yet been published in the official journal, and the Commission sent Spain a reasoned opinion in May 2025. Entry into force is expected in the course of 2026, with sanctions of up to EUR 10 million.

Who exactly is covered, the Dutch example

The directive speaks of members of management bodies and leaves it to national law to define that group precisely. The Netherlands shows how specific this can become. The Dutch national coordinator NCTV states that the training obligation rests on executive directors, and that supervisory directors and non-executive directors fall outside it. In a one-tier board, only the executive members are covered. Many organisations still let their supervisory board join the same training voluntarily, because that body must be able to judge whether the executives are fulfilling their cybersecurity role.

If you operate in several member states, check how each national law defines the group before you plan the training. The Dutch example shows that a plausible reading of the directive is no guarantee of what a national legislator decides.

What the training must achieve

Article 20 formulates a goal, not a curriculum. The training must put board members in a position to identify risks for network and information systems, to assess controls and to weigh their consequences for the services the organisation delivers. That is a governance skill, and it is trainable, but it asks for more than an information session.

That knowledge alone is not enough is a research finding, not an opinion. Bada, Sasse and Nurse showed in their widely cited study of security awareness campaigns that offering information by itself hardly changes behaviour; people must be able to apply the advice and be motivated to do so. For board members this means a good programme combines e-learning with exercises in which you have to take a decision while the facts are incomplete.

The governance role itself is also well documented. Uchendu, Nurse, Bada and Furnell analysed 58 studies on security culture in Computers & Security and conclude that support from top management is one of the decisive conditions for building such a culture. Seen in that light, the training obligation is no paper formality; a board that understands the subject and puts it on the agenda is exactly what a security culture needs.

The case for exercising at board level does not rest on our word either. The Dutch Scientific Council for Government Policy (WRR) argued as early as 2019, in its report “Voorbereiden op digitale ontwrichting” (preparing for digital disruption), that organisations should prepare for digital incidents with exercises, as they have long done for physical crises. A simulation in which the board lives through the first hours of an incident is the practical form of that advice.

Evidence and a training log

The Netherlands prescribes a certificate that states the training was completed and which subjects were covered. Whatever your own national law prescribes, you will at some point need to show that the board was trained and stayed current. A log per board member with completion dates, content versions and test results does that work. Records that cannot be altered afterwards, with timestamps, are considerably stronger in an inspection than loose certificates or e-mails.

Also record per board meeting when cybersecurity was discussed and what was decided. That too counts as evidence that the board fulfils its oversight role, and it is the first thing a supervisor or liquidator will ask about after an incident.

Common mistakes

  • Using generic awareness modules for the board instead of training at governance level. It ticks a box, but it does not train what the directive asks for.
  • Delegating cybersecurity entirely to the CISO without the board forming its own judgement. Article 20 places the approval of measures explicitly with the management body.
  • No record of board meetings where cybersecurity was discussed. Without an agenda item and minutes there is nothing to show afterwards.
  • Confusing compliance with security. An organisation can comply on paper and still be vulnerable. Board members must be able to tell the two apart.
  • Letting new board members join late. Every month between appointment and training is a month in which someone co-decides without a demonstrable basis.
Meet Article 20 with one complete programme

The 2LRN4 board training combines six e-learning modules with two workshops at your own board table, and delivers the certificate and the evidence file this article describes.

NIS2 for Board Members

Related articles

NIS2 transposition across Europe · Board reporting for awareness · Audit evidence for awareness

Sources

FAQ

Can board training be done online?

Yes. Article 20 describes what board members must be able to do, not the form in which they learn it. Online modules, hybrid sessions and classroom workshops all qualify, as long as completion is demonstrable and national requirements such as the Dutch certificate are met. Bear in mind that research shows information alone hardly changes behaviour; a programme that combines e-learning with exercises at the board table fits the purpose of the directive better.

Does the obligation apply to supervisory or non-executive directors?

That depends on national law. In the Netherlands, the NCTV states that supervisory directors and non-executive directors fall outside the obligation, which rests on the executive directors. Many organisations let their supervisory body join voluntarily, because it must be able to judge whether the executives are fulfilling their cybersecurity role.

We operate in several member states. Do we need separate training per country?

The duties come from the same Article 20, so one thorough programme can serve the whole group. Check per country what must be evidenced, such as the certificate requirements in the Netherlands, and reuse the same evidence file wherever possible.

What if our member state has not finished transposing NIS2?

The obligations in the directive are fixed; only the national timing is still open. France and Spain show how this plays out, with infringement procedures running while boards wait for a final law. Waiting shortens your preparation time and changes nothing about what will be required, so starting early is the safer route.

What does a board training cost?

That ranges from individual e-learnings per person to guided programmes per board. As an indication, the complete 2LRN4 programme, with six modules, two tests, two on-site workshops, a certificate and an evidence file, costs EUR 11,500 per board of up to eight participants, excluding VAT, plus EUR 950 per year for keeping it current. Compare providers on the evidence that remains afterwards, because that is what a supervisor asks for.

Next step

Use this article as the foundation and then see how 2LRN4 turns this topic into audience segmentation, training and reporting.