why do I need a certificate of participation for a cybersecurity training
Evidence that cyber hygiene and training are in place
A certificate of participation serves as evidence that staff training has actually taken place, and that is precisely what both internal records and a customer's security questionnaire require. Cybersecurity is not only about technology, but also about people who know how to recognise phishing, manage passwords, and report incidents. Training is therefore one of the recurring components within the due care obligations, and a certificate of participation is the tangible result with which that training can be demonstrated — not only to a supervisory authority, but also to a client who requests substantiation.
For organisations subject to obligations, a certificate of participation is part of the evidence document to be submitted per security measurenot the measure itself ("we train personnel") but the concrete proof that it has actually been carried out, with name, date and subject. For supply chain-affected SME suppliers who are not themselves subject to the law, it is equally relevant: who has to fill in a security questionnaire from a client often receives this particular question, because a client needs to be able to demonstrate that the supply chain is also sufficiently resilient. Without a certificate of attendance, "we train our staff" remains an unsupported claim, and that is usually not sufficient.
Where this follows from the duty of care
Article 21(2) of the NIS2 Directive lists basic cyber hygiene and cybersecurity training among the ten mandatory measures as part of the duty of care, which is adopted in the Dutch Cybersecurity Act as the national transposition. ISO/IEC 27001 elaborates on this in Annex A as a control measure regarding awareness and staff training, where demonstrability — that is, a record of who received which training when — is a recurring element. The NCSC emphasises in its guidance on the duty of care that measures must not only be taken but also be demonstrable.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.