Summary: Two sets of rules make management training an explicit requirement. The Swedish Cybersecurity Act states that the persons who make up an entity’s management must undergo training on security measures, and from 1 October 2026 MCFFS 2026:11 specifies what that training must deliver. DORA requires the management body of a financial entity to keep its knowledge of ICT risk up to date through regular, specific training. The details differ, but the message is the same: management must be able to set direction, assess measures and follow up, not merely delegate. A general security awareness course for all staff does not meet that bar.
Two sets of rules, one message
For a long time security training was aimed at staff: recognise phishing, choose good passwords, report anything that looks odd. That still matters, but it is not what the legislator means when management is to be trained.
The NIS2 Directive, implemented in Sweden through the Cybersecurity Act, and DORA, the EU regulation on digital operational resilience for the financial sector, each contain their own provision on management knowledge. The idea is the same: whoever approves the risk management and carries responsibility for it must understand what it involves.
This article covers what each set of rules actually requires, where they differ, what a training session for management and the board should contain, and how to document it so that it holds up under supervision.
What the Swedish Cybersecurity Act requires
The Cybersecurity Act (2025:1506) entered into force on 15 January 2026. The requirement on management is brief: the persons who make up the management of an entity must undergo training on security measures (chapter 2, section 4). The Act does not say how often, how long or in what form.
The background is Article 20 of the NIS2 Directive. Member States must ensure that management bodies approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements. Members of management bodies are required to follow training so that they can identify risks and assess risk-management practices and their impact on the services the entity provides. Similar training for employees is to be encouraged, but is not an equally firm requirement.
The regulations specify what the training must deliver
On 15 June 2026 the Swedish Agency for Civil Defence, formerly MSB, adopted regulations and general guidance on security measures and management training for essential and important entities, MCFFS 2026:11. They enter into force on 1 October 2026. Since 1 July 2026 the National Cyber Security Centre (NCSC) at FRA is responsible for guidance on the regulations.
The training chapter is short but concrete. The training must give management the knowledge and competence required to:
- set objectives and direction for the entity’s cybersecurity,
- assess which security measures the entity needs to implement to maintain an appropriate level of cybersecurity based on identified risks, and
- monitor the implementation of the security measures.
The general guidance sets out what the training should cover: management’s role in systematic, risk-based cybersecurity work, including relevant terminology and regulation; the significance of cybersecurity for maintaining the entity’s operations and important societal functions; risk management and monitoring as support for leading and steering the work; and the internal rules, working methods and support that are relevant to management.
The training is tied to management’s other duties in the same regulations. Management must approve and monitor the implementation of the security measures, ensure that there are established objectives, resources and clear roles, and be informed about implementation and the entity’s level of cybersecurity when needed, but at least once a year. A management team that has not been trained will struggle to do that meaningfully.
One detail that is easy to miss: for entities that operate exclusively in digital infrastructure, digital providers, business-to-business ICT service management, postal and courier services or space, only the management training requirement in these regulations applies. Their other security measures are regulated elsewhere. The training requirement therefore applies even where the regulations’ catalogue of measures does not.
What DORA requires
DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025 and is directly binding on banks, insurers, investment firms, payment institutions and other financial entities, without a Swedish implementing act.
Article 5 places responsibility for ICT risk management with the management body. It must define, approve, oversee and be responsible for the implementation of the entire ICT risk management framework. That includes bearing ultimate responsibility for ICT risk, setting the digital operational resilience strategy and the risk tolerance level, approving and periodically reviewing the ICT business continuity policy and the response and recovery plans, approving the ICT audit plans, allocating budget, approving the policy on the use of ICT third-party service providers, and having reporting channels that keep the management body informed of major incidents and material changes at those providers.
The training requirement is in Article 5(4): members of the management body must actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk and its impact on the operations of the financial entity, including by following specific training on a regular basis, commensurate to the ICT risk being managed.
Three words carry the requirement. Actively: keeping the knowledge current is the management body’s own responsibility, not something the security function delivers once. Regularly: a single session when DORA was introduced is not enough. Commensurate: a bank with extensive in-house IT operations and many providers needs more than a small institution with a simple business.
How the requirements differ
| Aspect | Swedish Cybersecurity Act (NIS2) | DORA |
|---|---|---|
| Who must be trained | The persons who make up the management of an essential or important entity | The members of the management body of a financial entity |
| Legal basis | Chapter 2, section 4 of the Cybersecurity Act and chapter 2 of MCFFS 2026:11 | Article 5(4) of Regulation (EU) 2022/2554 |
| What the training must deliver | Knowledge to set objectives and direction, assess which security measures are needed and monitor implementation | Sufficient knowledge to understand and assess ICT risk and its impact on operations |
| How often | No interval stated in the Act or the regulations | On a regular basis, commensurate to the ICT risk being managed |
| In force since | The Act on 15 January 2026, the regulations on 1 October 2026 | 17 January 2025 |
Organisations covered by both are rare: DORA is lex specialis in relation to NIS2, so for the financial entities it covers, DORA’s requirements on risk management and incident reporting take precedence, while other obligations under the Cybersecurity Act, such as registration, may remain. But groups with both financial operations and other essential services may well need to train several management bodies against different requirements. In that case it is better to build a common foundation and add the specifics of each set of rules than to run two entirely separate programmes.
What a good management training session contains
Both the general guidance to the Swedish regulations and Article 5 of DORA point the same way: the training must enable management to take its own decisions, not teach it to do the security function’s job. A format that works for both the board and the management team usually contains:
- The requirements and the responsibility. What the Act or the regulation actually requires of you, who the supervisory authority is and what a supervisory case or a sanction involves.
- Your own risk picture. Your critical services, systems, providers and dependencies, with real examples rather than generic threat scenarios.
- Management’s decisions. Which objectives, risk tolerances, policies, plans and budgets management must set and follow up, and how often.
- Reporting upwards. What information management should receive, from whom and when, so that it can genuinely monitor implementation.
- Incidents and crisis. How the reporting duty works, what happens in the first days and where management’s role begins.
- The right questions. The questions management should put to the security function, IT and the providers, and what a good answer looks like.
We have collected the questions management should be able to answer in the guide The Swedish Cybersecurity Act: ten questions for management. It works well as the starting point for a first session.
Common mistakes
- The staff e-learning is sent to the board. It is about phishing and passwords, not objectives, risk tolerance and oversight. It does not meet the requirements on management knowledge.
- Only the security lead attends. The requirement applies to the persons who make up management, or the members of the management body. A briefing to the management team without the board does not cover the board.
- Once and never again. DORA explicitly requires regularity, and new members join. Decide an interval and a routine for newly appointed members.
- No documentation. Under supervision you need to show what was delivered, when and to whom. A calendar entry without an agenda and an attendance list is hard to present.
- No decisions afterwards. If the training does not lead management to set objectives, approve measures or request reporting, it has not done its job, however good it was.
How to document the training
Neither the Cybersecurity Act, the regulations nor DORA states exactly how the training must be documented. But both frameworks rest on the supervisory authority being able to check that the requirements are met, and the general guidance to the Swedish regulations says that decisions, analyses, assessments, plans and follow-up results should be documented and kept for supervisory purposes. A practical minimum:
- date, format and duration of each session,
- an agenda showing which areas were covered, ideally mapped to the general guidance or to Article 5 of DORA,
- an attendance list with roles, and which members were absent,
- the training material, kept in the version that was used,
- decisions or assignments that resulted from the training, with a reference to the minutes,
- a plan for the next session and for training newly appointed members.
Keep the documentation where the other governing documents of your management system live, so that it is found when a supervisory authority or an auditor asks. If you work to ISO 27001 it fits naturally under the requirements on competence and awareness.
How Kristensson i Skåne can help
Kristensson i Skåne trains management teams and boards in what the Swedish Cybersecurity Act and DORA require of them, as part of our work on information security and governance. We adapt the content to your sector, your risk picture and the rules that apply to you, use your real systems and providers as examples, and leave behind an agenda, an attendance list, the materials and a list of decision points for management.
If you want to move from training to actually testing the capability, we recommend combining it with an exercise. How the wider work on operational resilience relates to these rules is covered in our insight on operational resilience under FI, DORA and NIS2, and what should be in place before 1 October in five things to check before 1 October.
Frequently asked questions
Is management training a legal requirement?
Yes, for entities covered by the Swedish Cybersecurity Act: the persons who make up management must undergo training on security measures, and from 1 October 2026 MCFFS 2026:11 specifies what the training must deliver. For financial entities DORA applies, which requires the members of the management body to follow specific training on ICT risk on a regular basis.
Is the staff security training enough for management?
No. Staff training is about safe everyday behaviour. Management training must provide the knowledge to set objectives and direction, assess which security measures are needed and monitor implementation, or, under DORA, to understand and assess ICT risk and its impact on operations.
How often should management be trained?
The Swedish Cybersecurity Act and the regulations state no interval. DORA requires regular training commensurate to the ICT risk being managed. In practice we recommend an annual session, an induction session for newly appointed members and an extra briefing when the rules, the business or the threat picture change materially.
Who counts as management?
The Swedish Cybersecurity Act refers to the persons who make up the management of an entity, and DORA to the members of the management body. In a limited company that normally means the board and the executive management. In a municipality or a public authority, management is delimited by how the organisation is governed. It is wise to include those who decide on budget, procurement and outsourcing.
What must we be able to show under supervision?
That the training took place, when, for whom and with what content. Keep the date, the agenda, the attendance list, the material and the decisions that followed. The rules do not prescribe the form, but without documentation the requirement is hard to show as met.
Does your management team or board need training before the end of the year? Read more about our offer management cybersecurity training or contact us for a no-obligation conversation.
Sources: Cybersäkerhetslag (2025:1506), chapter 2, section 4 and the entry-into-force provisions, riksdagen.se; MCFFS 2026:11, the Swedish Agency for Civil Defence’s regulations and general guidance on security measures and management training for essential and important entities, adopted 15 June 2026, chapter 1 section 1, chapter 2 section 1 and chapter 3 sections 3–4; Directive (EU) 2022/2555 (NIS2), Article 20; Regulation (EU) 2022/2554 (DORA), Articles 5 and 64, EUR-Lex. Verified 24 September 2026.
This text is general information, not legal advice. Which requirements apply to you depends on your sector, the scale of your operations and which supervisory authority you fall under.

