← All insights

Dutch cyber law can fine a director €25,000 — for not knowing enough

Jacques Domenie · August 17, 2026 · 6 min read

Most commentary on the Cyberbeveiligingswet has gone to the entity fines — up to €10 million or 2% of worldwide turnover for essential entities, €7 million or 1.4% for important ones, whichever is higher. Those are the numbers that make the slide. They are also the numbers the company pays.

There is a smaller one that comes out of a director's own pocket, and it is aimed somewhere unexpected.

Article 93 caps a personal administrative fine at €25,000. It has two grounds: breaching the article 24 duty, and obstructing the supervisor. Article 92 allows a last onder dwangsom — an order backed by a running penalty — against a named member of the board, and that one is scoped to article 24 alone.

Read what those provisions attach to and the picture inverts. Among the substantive obligations in this law, the one that reaches your own bank account is not securing anything. It is knowing.

What does article 24 Cbw require of a director?

The directive already asked for most of this. NIS2 article 20(2) requires members of management bodies to follow training so they can identify risks and assess cybersecurity risk-management practices and their impact on the entity's services, and article 24(2) Cbw transposes that almost verbatim. The Cyberbeveiligingsbesluit's explanatory notes say so plainly: "Dit is een vereiste uit de NIS2-richtlijn."

What the Netherlands added is the paperwork and the price.

Article 24(4) requires you to keep that knowledge and those skills aantoonbaar actueel — demonstrably current, meaning you have to be able to show it, not merely assert it. Article 24(5) requires you to hold "een certificaat, waaruit de deelname blijkt aan een training die de onderwerpen, bedoeld in het tweede lid, behandelt" — a certificate evidencing attendance at a training that covers the article 24(2) subjects.

A certificate. With your name on it.

The Cyberbeveiligingsbesluit, in force the same day as the Act, sets out what that certificate must contain, and it is four things, not two: the name of the board member, the date or dates of the training, the subjects covered, and the name of the training provider. It must be drawn up in Dutch or English. The Decree also fixes what the training itself must address — types of risk to network and information systems, risk-management processes, risk-assessment methodology, and the measures required under article 21(3) of the Act.

Who does the training obligation actually apply to?

This is where boards tend to assume it lands somewhere else, and where a lot of Dutch commentary is loose.

It reaches executive directors. It extends to the natural person acting on behalf of a legal-person director, to executive directors in a one-tier board under articles 2:129a and 2:239a BW, and to the partners of a maatschap, the partners of a vennootschap onder firma, and the managing partners (beherende vennoten) of a commanditaire vennootschap — all three Dutch partnership forms, named separately in article 24(9) to (11).

It does not reach supervisory directors. The NCTV is explicit that members of a raad van commissarissen and non-executive directors fall outside this particular duty. If you sit on an RvC, article 24 is not your obligation — though the board you supervise still has to satisfy it, and asking whether they have is squarely your job.

When is the deadline?

15 August 2028 for anyone in post when the law took effect. That date is arithmetic rather than a published deadline: two years from the 15 August 2026 commencement.

Two carve-outs matter. A director appointed after commencement gets two years from their own appointment, not from 2026. And designated higher-education institutions run on a separate 36-month clock from the moment they are designated.

Why the personal exposure sits on competence

Dutch law did not create a new personal liability regime for security failures. If an incident occurs and the question becomes whether you are personally on the hook, the answer still runs through the ordinary director-liability routes — article 2:9 BW toward the company itself, article 6:162 toward third parties — and their deliberately high ernstig verwijt bar: serious personal blame, not merely a bad outcome. That threshold has not moved. Anyone telling a Dutch board that NIS2 makes directors personally liable for breaches is selling something.

One qualifier, because the picture is not quite as clean as the inversion suggests: article 78 lets a competent authority ask the civil court to suspend one or more board members of an essential entity that has missed the end date in a remediation decision. That is a personal consequence, and it does follow from substantive non-compliance. It is not a fine, but it is not nothing.

What remains true is the narrower and more interesting point. The place this law reaches into a director's own pocket for a substantive duty is not the control that failed. It is the inability to show you had the knowledge to govern the risk. The legislature aimed the personal fine at the governance, not at the incident.

Which training satisfies article 24?

Here is the part that is a freedom and a trap in equal measure.

The government declined to say. The NCTV's guidance is explicit: "De Rijksoverheid schrijft geen specifieke training of opleidingsaanbieder voor." No approved-provider list, no accreditation regime, no prescribed duration and no prescribed level — the Decree could have set both under article 24(6) and chose not to. Organisations may run the training internally, with support from their own CISO.

Read that as permission and you will buy the cheapest thing that produces a PDF. Read it correctly and the consequence is sharper: the standard your board is held to is the standard your board can defend. No certificate ends the argument, because no authority has blessed any particular certificate.

There is also a moving target inside the syllabus. The Decree's four subject areas say nothing about AI, yet the risk landscape a board is meant to assess now includes AI-assisted intrusion, AI systems inside your own operations, and the AI Act obligations layered on top. A board defending aantoonbaar actueel in 2029 against a 2027 training that never mentioned any of it will find "we did the course" a thin answer. Currency is the obligation, not attendance.

What evidence should a Dutch board have on file by 2028?

Four things, and they should be true rather than merely present.

  1. A certificate per executive director, carrying all four elements the Decree requires. That is the floor, not the answer.
  2. Evidence behind the subject list the certificate already names. The certificate says what was covered; a supervisor may ask what was actually learned. "It was in the deck" is a weak reply on risk-assessment methodology.
  3. A recurrence plan, because aantoonbaar actueel is continuing. Knowledge current in 2026 is not self-evidently current in 2029. Decide the cadence deliberately and write down why it is the right one.
  4. One occasion on which the board actually challenged a risk framework, minuted. That is the artefact separating a governed risk from a documented one.

None of that requires a vendor. It requires deciding what standard you intend to hold yourselves to, before someone else decides it for you.

Next

The wider argument — what DORA, NIS2 and the AI Act now ask of the people who govern, and the competence gap most supervisory boards still carry — is in the companion piece. If you are looking at this through a transaction, the obligation travels with the entity at closing.

Every other duty in this law can be delegated to someone who does it for you. The knowledge cannot. If your board is working out what "demonstrably current" should mean for you, that is a conversation worth having — delfen.com.

Sources & further reading

  • Cyberbeveiligingswet — Staatsblad 2026, 187, Wet van 8 juli 2026. Article 24 sets the individual knowledge, currency and certificate duty and its transition; article 78 the suspension power; article 92 the last onder dwangsom; article 93 the €25,000 personal fine and its two grounds; articles 80 and 87 the entity fine ceilings.
  • Cyberbeveiligingsbesluit — Staatsblad 2026, 189, Besluit van 8 juli 2026. Articles 20–22 set the training's purpose, its required content, and the four elements plus language requirement for the certificate; article 35 brings both the Act and the Decree into force on 15 August 2026.
  • Bestuurlijke aansprakelijkheid en trainingsplicht — NCTV. The two-year deadline, the scope limited to executive directors, and the confirmation that no specific training or provider is prescribed.
  • Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van kracht — Rijksoverheid, July 2026. Entry into force, and a scope of more than 8,000 organisations.
  • Directive (EU) 2022/2555 — NIS2 — the parent directive. Article 20(2) already requires management-body training; the certificate, the currency duty and the personal fine are Dutch additions.

Recognise this question in your own organisation? That is worth a conversation.

Get in touch