Does DORA Require Training for the Board and Executives Team?

Date: 31 July 2026

Featured Image

Is Board Cyber Crisis Training mandated by EU DORA? Short answer: yes, and it's more specific than most boards assume. DORA doesn't leave board-level cyber competence as a best-practice recommendation. It writes an individual training obligation directly into the regulation, alongside a separate organisation-wide training mandate that explicitly names senior management. 

Here's exactly what the text requires, article by article. 

Does DORA Require Training for the Board and Executive Team?

Most DORA readiness programmes focus on ICT risk frameworks, incident classification and reporting templates. Boards often assume their own obligation is oversight in the abstract — approving policies, reviewing budgets, signing off on frameworks other people built. DORA doesn't allow that distance. It places a personal, individual training duty on every member of the management body, separately from the training it requires for the wider organisation.

The Board-Level Obligation: Article 5(4)

The clearest answer sits in Article 5(4) of DORA:

"Members of the management body of the financial entity shall actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk and its impact on the operations of the financial entity, including by following specific training on a regular basis, commensurate to the ICT risk being managed."

Three things in that sentence matter more than they first appear:

  • "Members," not "the board." The obligation is individual, not collective. A board that has one cyber-literate non-executive director and several members with no ICT risk grounding has not satisfied Article 5(4) — every member carries the duty personally.
  • "Actively keep up to date," not a one-off induction. This is a continuous obligation, not a certificate earned once at appointment.
  • "Commensurate to the ICT risk being managed." The depth of training scales with the entity's actual risk exposure — a systemically important bank's board needs materially more than a small investment firm's.

Why the Board Can't Discharge Article 5(2) Without It

Article 5(4) doesn't exist in isolation. — it's the knowledge foundation the rest of Article 5 assumes the board already has. Article 5(2) sets out what the management body must actually do, and it reads as a list of decisions that are impossible to make competently without the understanding Article 5(4) requires:

  • (a) bear the ultimate responsibility for managing the entity's ICT risk.
  • (d) bear overall responsibility for setting and approving the digital operational resilience strategy, including the entity's ICT risk tolerance level.
  • (e) approve, oversee and periodically review the ICT business continuity policy and the ICT response and recovery plans.
  • (f) approve and periodically review the entity's ICT internal audit plans and material modifications to them.
  • (h) approve and periodically review the policy on the use of ICT services from third-party providers.

None of these are rubber-stamp approvals. A board asked to set an ICT risk tolerance level or approve a response and recovery plan has to be able to interrogate what it's approving, which is precisely the "sufficient knowledge and skills" Article 5(4) exists to guarantee.

The Board Also Owns the Training Budget: Article 5(2)(g)

DORA closes an obvious loophole by making the board financially accountable for training, not just personally subject to it. Article 5(2)(g) requires the management body to:

"...allocate and periodically review the appropriate budget to fulfil the financial entity's digital operational resilience needs in respect of all types of resources, including relevant ICT security awareness programmes and digital operational resilience training referred to in Article 13(6), and ICT skills for all staff."

In practice, this means a board cannot claim organisational readiness while quietly under-resourcing the training line item, funding adequacy is itself a governance obligation the board is accountable for, reviewable by supervisors alongside everything else in Article 5.

The Organisation-Wide Obligation: Article 13(6)

Article 5(4) covers the board specifically. Article 13(6) sets a separate, broader requirement that explicitly pulls senior management back in alongside every other employee:

"Financial entities shall develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes. Those programmes and training shall be applicable to all employees and to senior management staff, and shall have a level of complexity commensurate to the remit of their functions. Where appropriate, financial entities shall also include ICT third-party service providers in their relevant training schemes in accordance with Article 30(2), point (i)."

Two details worth flagging for compliance teams building the programme:

  • Complexity is role-based, not uniform. A single generic e-learning module for the whole organisation doesn't satisfy this — the CEO's training needs to be commensurate with executive-level accountability, not identical to a front-line employee's awareness module.
  • Third-party providers can be in scope. Where appropriate, ICT third-party service providers should be included in training schemes, which the DORA Incident Response Document Library treats as part of third-party incident management documentation, not a training afterthought.

The Reporting Loop That Keeps the Board Accountable

DORA doesn't let board-level knowledge go stale between training sessions. Article 13(5) requires:

"Senior ICT staff shall report at least yearly to the management body on the findings referred to in paragraph 3 and put forward recommendations."

Paragraph 3 covers lessons from resilience testing, real ICT-related incidents (particularly cyber-attacks), and challenges faced activating business continuity and response plans. That means the board isn't just trained in the abstract once a year — it's structurally required to sit through a yearly confrontation with what actually happened, and to act on the recommendations that follow. A board unable to engage critically with that report has failed the intent of Article 5(4), regardless of whether a training certificate is on file.

What "Sufficient Knowledge and Skills" Looks Like in Practice

DORA doesn't prescribe a curriculum, but the obligations in Articles 5 and 13 point to a fairly specific shape:

  • Understanding how ICT risk translates into business risk, well enough to set a genuine risk tolerance level rather than approving a number someone else picked.
  • Fluency with the entity's incident classification criteria and reporting clock — the initial notification, intermediate report and final report deadlines a major ICT-related incident triggers.
  • The ability to make and defend real-time decisions under pressure: when to escalate, what to disclose, how to communicate with regulators, clients and the market during a live incident.
  • Enough grounding in the ICT third-party risk landscape to interrogate the third-party policy the board is required to approve under Article 5(2)(h).

This is exactly the gap a structured executive programme is built to close. Cybersecurity Training for Executives maps directly onto Article 5(2)(g) budget accountability and Article 5(4)'s knowledge requirement, while the Board Cyber Crisis Programme puts the board through realistic tabletop exercises — testing exactly the decision-making, crisis communications and regulatory response competence Article 5(4) is designed to guarantee, rather than leaving it untested until a real incident does the testing instead.

Where Training Meets Documentation

Board training and incident response documentation aren't separate compliance streams — Article 5(2)(e) makes the board directly responsible for approving and periodically reviewing the ICT business continuity policy and response and recovery plans. A board can't discharge that duty by delegating it entirely; it needs to actually engage with what those documents contain.

That's easier when the documentation itself is structured for board-level review rather than buried across scattered files. The DORA Incident Response Document Library profiles the 15 mandatory artefacts DORA requires — including incident classification criteria and the reporting templates the board is ultimately accountable for, while the DORA Master Document Register for ICT Incident Response gives the board a single, maintained view of ownership, review dates and regulatory mapping across the entire set, which is what a genuinely engaged board actually reviews at each periodic sign-off.

Common Mistakes Boards Make on DORA Training

  • Treating one induction session as compliance. Article 5(4)'s "regular basis" language rules out a single onboarding module years ago as ongoing evidence of currency.
  • Uniform training across all seniority levels. Article 13(6) explicitly requires complexity commensurate to role. A board member and a junior analyst should not be sitting through the same module.
  • No individual record per board member. Because the obligation in Article 5(4) is personal, "the board was trained" isn't defensible without evidence against each named member.
  • Treating the annual Article 13(5) report as an information item. It's designed to drive board decisions and recommendations, not simply be noted and filed.
  • No connection between training and the documents being approved. A board that hasn't engaged with the actual incident response plan and reporting templates it's approving under Article 5(2)(e) hasn't met the substance of the requirement, even with a training certificate on record.

Getting Started

  1. Map current board and executive competence against what Article 5(4) and Article 13(6) actually require, individually per member rather than as a collective assumption.
  2. Separate the two training tracks: Board-level strategic and decision-making competence under Article 5(4), and organisation-wide (including senior management) awareness training under Article 13(6).
  3. Budget for both explicitly, since Article 5(2)(g) makes funding adequacy itself a reviewable governance decision.
  4. Test the knowledge, don't just deliver it. A live tabletop exercise through the Board Cyber Crisis Programme surfaces gaps a slide deck never will.
  5. Tie training to the real documentation the board is accountable for approving, using the DORA Master Document Register as the working reference point at each review cycle.

Key Terms

  • Management Body: The board of directors or equivalent governing body of a financial entity, bearing ultimate responsibility for ICT risk under DORA Article 5.
  • Digital Operational Resilience Strategy: The strategy the management body must set and approve under Article 5(2)(d), including the entity's determined ICT risk tolerance level.
  • ICT Security Awareness Programme: The compulsory training and awareness programme required under Article 13(6), applicable to all employees and senior management staff.
  • Senior ICT Staff Report: The report senior ICT staff must deliver at least yearly to the management body under Article 13(5), covering incident and testing findings with recommendations.
  • ICT Risk Tolerance Level: The level of ICT risk exposure the management body determines is acceptable for the entity, set as part of the digital operational resilience strategy under Article 5(2)(d).
  • Post ICT-Related Incident Review: The review required under Article 13(2) after a major ICT-related incident disrupts core activities, analysing causes and identifying improvements.

Frequently Asked Questions About DORA Requirements for Training Board Members 

1. Does DORA legally require cybersecurity training for board members?

Yes. Article 5(4) requires every member of a financial entity's management body to actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk, including through specific, regular training commensurate to the ICT risk being managed.

2. What exactly does DORA Article 5(4) require of the board?

It requires each individual board member — not the board collectively — to maintain current knowledge and skills on ICT risk and its impact on the entity's operations, through regular, risk-proportionate training rather than a one-time induction.

3. Is DORA training only required for the board, or for executives and staff too?

Both. Article 5(4) imposes an individual obligation on management body members, while Article 13(6) separately requires ICT security awareness programmes and digital operational resilience training as compulsory modules applicable to all employees and senior management staff, scaled in complexity to each role.

4. Who is responsible for funding board and executive training under DORA?

The management body is. Article 5(2)(g) requires the board to allocate and periodically review the appropriate budget for ICT security awareness programmes and digital operational resilience training, making funding adequacy a reviewable governance decision in its own right.

5. How often must board members complete DORA-required training?

DORA specifies "on a regular basis" rather than a fixed interval, with the frequency and depth commensurate to the ICT risk the entity manages. In practice, most financial entities treat this as at least annual, aligned with the yearly senior ICT staff report the board receives under Article 13(5).

6. What happens if a board member doesn't complete the required ICT risk training?

DORA doesn't set out a specific fine for individual non-training, but it undermines the board's ability to discharge its broader Article 5(2) governance responsibilities, exposes the entity to supervisory findings during a DORA assessment, and weakens the defensibility of decisions that member participated in approving.

7. Does DORA require training for ICT third-party service providers as well?

Where appropriate, yes. Article 13(6) states that financial entities shall also include ICT third-party service providers in their relevant training schemes, in accordance with Article 30(2), point (i), which governs contractual arrangements with critical ICT providers.

8. How does board training connect to DORA incident response documentation?

The management body is directly responsible under Article 5(2)(e) for approving and periodically reviewing the ICT business continuity policy and response and recovery plans, and under 5(2)(f) for the entity's ICT audit plans. Board training needs to build the competence to engage substantively with those specific documents, not just general cyber awareness.