Is Board Cyber Crisis Training mandated by EU DORA? Short answer: yes, and it's more specific than most boards assume. DORA doesn't leave board-level cyber competence as a best-practice recommendation. It writes an individual training obligation directly into the regulation, alongside a separate organisation-wide training mandate that explicitly names senior management.
Here's exactly what the text requires, article by article.
Most DORA readiness programmes focus on ICT risk frameworks, incident classification and reporting templates. Boards often assume their own obligation is oversight in the abstract — approving policies, reviewing budgets, signing off on frameworks other people built. DORA doesn't allow that distance. It places a personal, individual training duty on every member of the management body, separately from the training it requires for the wider organisation.
The clearest answer sits in Article 5(4) of DORA:
"Members of the management body of the financial entity shall actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk and its impact on the operations of the financial entity, including by following specific training on a regular basis, commensurate to the ICT risk being managed."
Three things in that sentence matter more than they first appear:
Article 5(4) doesn't exist in isolation. — it's the knowledge foundation the rest of Article 5 assumes the board already has. Article 5(2) sets out what the management body must actually do, and it reads as a list of decisions that are impossible to make competently without the understanding Article 5(4) requires:
None of these are rubber-stamp approvals. A board asked to set an ICT risk tolerance level or approve a response and recovery plan has to be able to interrogate what it's approving, which is precisely the "sufficient knowledge and skills" Article 5(4) exists to guarantee.
DORA closes an obvious loophole by making the board financially accountable for training, not just personally subject to it. Article 5(2)(g) requires the management body to:
"...allocate and periodically review the appropriate budget to fulfil the financial entity's digital operational resilience needs in respect of all types of resources, including relevant ICT security awareness programmes and digital operational resilience training referred to in Article 13(6), and ICT skills for all staff."
In practice, this means a board cannot claim organisational readiness while quietly under-resourcing the training line item, funding adequacy is itself a governance obligation the board is accountable for, reviewable by supervisors alongside everything else in Article 5.
Article 5(4) covers the board specifically. Article 13(6) sets a separate, broader requirement that explicitly pulls senior management back in alongside every other employee:
"Financial entities shall develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes. Those programmes and training shall be applicable to all employees and to senior management staff, and shall have a level of complexity commensurate to the remit of their functions. Where appropriate, financial entities shall also include ICT third-party service providers in their relevant training schemes in accordance with Article 30(2), point (i)."
Two details worth flagging for compliance teams building the programme:
DORA doesn't let board-level knowledge go stale between training sessions. Article 13(5) requires:
"Senior ICT staff shall report at least yearly to the management body on the findings referred to in paragraph 3 and put forward recommendations."
Paragraph 3 covers lessons from resilience testing, real ICT-related incidents (particularly cyber-attacks), and challenges faced activating business continuity and response plans. That means the board isn't just trained in the abstract once a year — it's structurally required to sit through a yearly confrontation with what actually happened, and to act on the recommendations that follow. A board unable to engage critically with that report has failed the intent of Article 5(4), regardless of whether a training certificate is on file.
DORA doesn't prescribe a curriculum, but the obligations in Articles 5 and 13 point to a fairly specific shape:
This is exactly the gap a structured executive programme is built to close. Cybersecurity Training for Executives maps directly onto Article 5(2)(g) budget accountability and Article 5(4)'s knowledge requirement, while the Board Cyber Crisis Programme puts the board through realistic tabletop exercises — testing exactly the decision-making, crisis communications and regulatory response competence Article 5(4) is designed to guarantee, rather than leaving it untested until a real incident does the testing instead.
Board training and incident response documentation aren't separate compliance streams — Article 5(2)(e) makes the board directly responsible for approving and periodically reviewing the ICT business continuity policy and response and recovery plans. A board can't discharge that duty by delegating it entirely; it needs to actually engage with what those documents contain.
That's easier when the documentation itself is structured for board-level review rather than buried across scattered files. The DORA Incident Response Document Library profiles the 15 mandatory artefacts DORA requires — including incident classification criteria and the reporting templates the board is ultimately accountable for, while the DORA Master Document Register for ICT Incident Response gives the board a single, maintained view of ownership, review dates and regulatory mapping across the entire set, which is what a genuinely engaged board actually reviews at each periodic sign-off.
1. Does DORA legally require cybersecurity training for board members?
Yes. Article 5(4) requires every member of a financial entity's management body to actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk, including through specific, regular training commensurate to the ICT risk being managed.
2. What exactly does DORA Article 5(4) require of the board?
It requires each individual board member — not the board collectively — to maintain current knowledge and skills on ICT risk and its impact on the entity's operations, through regular, risk-proportionate training rather than a one-time induction.
3. Is DORA training only required for the board, or for executives and staff too?
Both. Article 5(4) imposes an individual obligation on management body members, while Article 13(6) separately requires ICT security awareness programmes and digital operational resilience training as compulsory modules applicable to all employees and senior management staff, scaled in complexity to each role.
4. Who is responsible for funding board and executive training under DORA?
The management body is. Article 5(2)(g) requires the board to allocate and periodically review the appropriate budget for ICT security awareness programmes and digital operational resilience training, making funding adequacy a reviewable governance decision in its own right.
5. How often must board members complete DORA-required training?
DORA specifies "on a regular basis" rather than a fixed interval, with the frequency and depth commensurate to the ICT risk the entity manages. In practice, most financial entities treat this as at least annual, aligned with the yearly senior ICT staff report the board receives under Article 13(5).
6. What happens if a board member doesn't complete the required ICT risk training?
DORA doesn't set out a specific fine for individual non-training, but it undermines the board's ability to discharge its broader Article 5(2) governance responsibilities, exposes the entity to supervisory findings during a DORA assessment, and weakens the defensibility of decisions that member participated in approving.
7. Does DORA require training for ICT third-party service providers as well?
Where appropriate, yes. Article 13(6) states that financial entities shall also include ICT third-party service providers in their relevant training schemes, in accordance with Article 30(2), point (i), which governs contractual arrangements with critical ICT providers.
8. How does board training connect to DORA incident response documentation?
The management body is directly responsible under Article 5(2)(e) for approving and periodically reviewing the ICT business continuity policy and response and recovery plans, and under 5(2)(f) for the entity's ICT audit plans. Board training needs to build the competence to engage substantively with those specific documents, not just general cyber awareness.