Legislation

NIS2 for directors: your personal obligations on one page

Required
Implementation
Download
The Cybersecurity Act has been in effect since August 15, 2026, and places some of the obligations directly on you as a director. Compliance is not something you can manage from the sidelines. This one-pager outlines exactly what the law requires of you personally, so you don't have to sift through the entire legal text first.
This article was last updated on
17.09.2026
Written by
Wouter
Vreeburg
Owner

‍

This one-pager is only available in Dutch.

What is on the one-pager?

 

  • Approval: which decisions regarding risk management measures must be made by the board itself, even if IT or an external party does the preparatory work.
  • Supervision: what you can delegate to a CISO or an external security provider and which responsibilities remain with you.
  • Training: which training you as a director are required to complete, when it must be finished, and why this obligation cannot be transferred.
  • Liability: when personal liability comes into play and exactly who falls under it.

 

In addition, the one-pager includes the five questions a regulator might ask you. Finally, you will find two routes to meet the training requirement, so that after reading it, you know what your first step should be.

Who is this one-pager for?

For directors of organizations that fall under the Cybersecurity Act, i.e., the management and board of directors of essential and important entities. Commissioners and members of a supervisory board are exempt from the training requirement, which does not affect their own role in supervising the board. Do you want to know all the requirements that apply to your organization? Then download our NIS2 checklist.

The difference from our NIS2 checklist

The NIS2 checklist goes through all the organization's legal obligations and provides you with a to-do list in fifteen minutes. This one-pager looks at what applies to directors personally, such as the decisions inherent to your role and the resulting liability. Most directors use them in tandem.

How to use the one-pager

Take this to your next board meeting and go through the five questions out loud. Wherever you get stuck, you’ll immediately know where the work lies. For each question, record who is responsible and when it needs to be completed, as this is exactly the documentation a regulator will ask for later.

Questions about NIS2 and the Cyber Security Act?

Feel free to contact us with no obligation. We would be happy to tell you more.

‍

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

Partnership Fendix x InventIT
Partners

New partnership: Fendix x InventIT for NIS2

by
Ruben
Blog
Five frequently asked questions about NIS2 and the Dutch Cybersecurity Act
Legislation

NIS2 and the Dutch Cybersecurity Act: 5 FAQs

by
Mathijs
Blog
Information Security

NIS2 & ISO 27001: the overlap, differences and how your organization becomes compliant

by
Mathijs
Download