Legislation

NIS2 for directors: your personal obligations on one page

Required
Implementation
Download

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

The Cybersecurity Act has been in effect since August 15, 2026, and places some of the obligations directly on you as a director. Compliance is not something you can manage from the sidelines. This one-pager outlines exactly what the law requires of you personally, so you don't have to sift through the entire legal text first.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
17.09.2026
Written by
Wouter
Vreeburg
Owner

This one-pager is only available in Dutch.

What is on the one-pager?

 

  • Approval: which decisions regarding risk management measures must be made by the board itself, even if IT or an external party does the preparatory work.
  • Supervision: what you can delegate to a CISO or an external security provider and which responsibilities remain with you.
  • Training: which training you as a director are required to complete, when it must be finished, and why this obligation cannot be transferred.
  • Liability: when personal liability comes into play and exactly who falls under it.

 

In addition, the one-pager includes the five questions a regulator might ask you. Finally, you will find two routes to meet the training requirement, so that after reading it, you know what your first step should be.

Who is this one-pager for?

For directors of organizations that fall under the Cybersecurity Act, i.e., the management and board of directors of essential and important entities. Commissioners and members of a supervisory board are exempt from the training requirement, which does not affect their own role in supervising the board. Do you want to know all the requirements that apply to your organization? Then download our NIS2 checklist.

The difference from our NIS2 checklist

The NIS2 checklist goes through all the organization's legal obligations and provides you with a to-do list in fifteen minutes. This one-pager looks at what applies to directors personally, such as the decisions inherent to your role and the resulting liability. Most directors use them in tandem.

How to use the one-pager

Take this to your next board meeting and go through the five questions out loud. Wherever you get stuck, you’ll immediately know where the work lies. For each question, record who is responsible and when it needs to be completed, as this is exactly the documentation a regulator will ask for later.

Questions about NIS2 and the Cyber Security Act?

Feel free to contact us with no obligation. We would be happy to tell you more.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

Legislation

Does the Cyber Security Act (NIS2) apply to me?

by
Mathijs
Download
Information Security

NIS2: mandatory training for management and management

by
Kilian
Training
Legislation

What are the main goals of NIS2?

by
Mathijs
Kennisartikel