Last updated: 1 October 2026
Quick answer: Under Article 20 of NIS2, the management bodies of essential and important entities must approve the cybersecurity risk-management measures required by Article 21, oversee their implementation and can be held liable for infringements. Their members must also follow cybersecurity training, and entities are encouraged to train employees regularly.
NIS2 management body accountability is the part of the Directive that most directly reaches the boardroom. Cybersecurity can no longer sit only with the IT department: directors are expected to approve the security programme, understand it well enough to challenge it, and answer for it when things go wrong.
This guide explains what Article 20 requires, who counts as the management body, how liability and enforcement work, what good board training looks like, and how to produce evidence a supervisor will accept. It ends with a practical board checklist.
What does NIS2 management body accountability mean under Article 20?
It means the board, or equivalent governing body, is personally responsible for approving and overseeing the entity’s cybersecurity risk-management measures. Operational work can be delegated; accountability cannot.
Directive (EU) 2022/2555 (NIS2) sets two obligations in Article 20:
- Article 20(1), governance: Member States must ensure that management bodies approve the cybersecurity risk-management measures taken to comply with Article 21, oversee their implementation, and can be held liable for the entity’s infringements of that Article. This is without prejudice to national liability rules for public institutions, public servants and elected or appointed officials.
- Article 20(2), training: members of management bodies are required to follow training, and entities are encouraged to offer similar training to employees on a regular basis, so that they gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services the entity provides.
The European Commission describes this as introducing “accountability of the top management” and bringing cybersecurity to the attention of the boardroom, as set out on its NIS2 policy page.
What exactly must the board approve?
The object of approval is the set of Article 21 measures. Article 21(2) lists at least ten areas, including risk analysis and information system security policies, incident handling, business continuity, supply chain security, security in acquisition and development, effectiveness assessment, basic cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication. The board does not need to approve every procedure, but it should approve the policy framework, the risk appetite and the treatment plan that together deliver these measures.
Who counts as the management body?
NIS2 does not define the term, so the answer depends on national company law and the national transposition. In practice it usually means the body with ultimate decision-making power: the board of directors in a one-tier structure, the management board in a two-tier structure, or the managing directors of a smaller company.
Common mistake: assuming the CISO or a risk committee is the management body. A committee can prepare decisions and monitor progress, but the approval required by Article 20(1) should be traceable to the body that national law treats as the entity’s management.
Check your national law. The Directive had to be transposed by 17 October 2024, and Member States have taken different approaches to naming the responsible persons. Germany, for example, transposed NIS2 through an act that entered into force in December 2025; its revised BSI Act (section 38) requires management to implement and monitor the measures and to attend training.
Can directors be held personally liable under NIS2?
Yes, within the limits of national law. Article 20(1) requires that management bodies “can be held liable” for infringements of Article 21, and the enforcement articles add specific tools.
- Article 32(6): any natural person responsible for, or acting as legal representative of, an essential entity must have the power to ensure its compliance and can be held liable for breach of their duties to ensure compliance. Article 33(5) applies this to important entities as well.
- Article 32(5): for essential entities, where enforcement measures are ineffective, authorities can request a temporary prohibition on any natural person discharging managerial responsibilities at chief executive officer or legal representative level from exercising managerial functions in that entity. This power is not extended to important entities by Article 33.
- Article 34: infringements of Articles 21 or 23 can lead to administrative fines of a maximum of at least EUR 10 million or 2% of total worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities, whichever is higher.
The fines hit the entity, but the prospect of personal liability and management bans is what has made boards pay attention.
What training must board members follow?
NIS2 requires training but does not prescribe a syllabus, duration or frequency. The test is outcome-based: members must gain enough knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on services.
That points to decision-making competence rather than technical depth. A good programme covers:
- the entity’s threat profile and its most critical services and assets;
- how the Article 21 measures are implemented, and where the gaps are;
- how to read risk reports, key indicators and audit findings;
- incident reporting duties under Article 23 and the board’s role in a crisis;
- supply chain dependencies and third-party risk;
- personal duties and liability under the national transposition.
In practice: generic awareness e-learning rarely meets the Article 20(2) standard for directors. A short session built around the entity’s own risk register and a tabletop exercise gives the board skills it can use, and produces better evidence.
How does the Implementing Regulation shape board duties?
For digital infrastructure and digital service providers, Commission Implementing Regulation (EU) 2024/2690 turns Article 21 into detailed technical and methodological requirements. It applies to entities such as cloud computing providers, data centre service providers, managed service providers and managed security service providers.
Two points in its Annex matter for governance: the policy on the security of network and information systems must be formally approved by the management bodies, and at least one person must report directly to the management bodies on matters of network and information system security. ENISA’s NIS2 technical implementation guidance, published in June 2025, offers practical advice and examples of evidence for these requirements. Even entities outside the Regulation’s scope can use it as a benchmark.
What evidence of board oversight will supervisors expect?
Supervisors assess what they can see in writing. Build an evidence trail that shows approval, oversight and competence over time.
| Obligation | Evidence to keep | Typical owner |
|---|---|---|
| Approve Article 21 measures | Board minutes approving the security policy, risk appetite and treatment plan | Company secretary, CISO |
| Oversee implementation | Quarterly security reports, KPI dashboards, decisions on overdue actions | CISO |
| Act on non-compliance | Records of corrective measures under Article 21(4) and their follow-up | CISO, internal audit |
| Follow training | Attendance records, agenda, materials, date of next session | HR, company secretary |
| Oversee incident reporting | Escalation criteria, exercise reports, post-incident reviews | CISO, legal |
Keeping these records together, linked to the underlying controls and risks, makes a supervisory request a retrieval task rather than a scramble. A policy management workflow with approval history and an enterprise risk register that reports into board packs cover much of this table.
If you want to see how that looks in one place, you can start your 14-day free trial of Enactia’s AI-powered GRC platform and load your own NIS2 controls.
A board checklist for NIS2 Article 20
Use this checklist to test whether your governance would stand up to scrutiny.
- Confirm which body is the management body under national law and record it.
- Confirm whether the entity is essential or important, and which national authority supervises it.
- Map the Article 21(2) measures to owners, policies and controls; run a gap assessment against them.
- Present the policy framework, risk appetite and treatment plan to the board for formal approval.
- Agree a reporting rhythm (for example quarterly) with defined indicators and escalation thresholds.
- Name the person who reports directly to the board on cybersecurity.
- Deliver tailored training to every board member and set a date for the next session.
- Rehearse the Article 23 incident reporting timeline with the board and document the exercise, supported by an incident management workflow.
- Review supplier risk at board level for critical ICT providers.
- Record corrective decisions and track them to closure.
If your entity is also subject to DORA or the EU AI Act, align board reporting across the regimes rather than running three parallel processes. Our article on managing the overlap between DORA, NIS2 and the EU AI Act covers that approach, our NIS2 compliance roadmap sets the wider programme around it, and cross-framework control mapping lets one board-approved control set serve several laws.
Is Article 20 likely to change?
There is no sign of it being weakened. On 20 January 2026 the Commission published a proposal for targeted NIS2 amendments focused on simplification, including a lighter regime for a new category of small mid-cap companies, clearer jurisdiction rules and more consistent supply chain requirements. It is still a proposal going through the legislative process. Until amendments are adopted and transposed, the current text of Article 20 and the national laws that implement it remain the rules to follow.
Key takeaways
- Article 20 makes management bodies approve, oversee and answer for the Article 21 cybersecurity measures.
- Personal liability and, for essential entities, temporary management bans depend on national transposition.
- Board training is mandatory and should build decision-making competence, not technical depth.
- Supervisors will look for written evidence: minutes, reports, training records and corrective actions.
- Check your national law for who the management body is and any extra requirements.
Frequently asked questions
Can the board delegate NIS2 responsibilities to the CISO?
The board can delegate the design and operation of security measures to the CISO and other managers, but it cannot delegate the Article 20 duties themselves. The management body must still approve the Article 21 measures, oversee implementation and remain accountable. Delegation should be documented, with regular reporting back to the board so oversight is visible.
How often must board members be trained under NIS2?
The Directive does not set a frequency. It requires members to follow training that gives them sufficient knowledge and skills to identify risks and assess risk-management practices. Many organisations refresh training at least annually and after major changes, but you should check whether your national law or supervisor sets a specific interval or content requirement.
Do the Article 20 duties apply to important entities as well as essential ones?
Yes. Article 20 applies to both essential and important entities, and Article 33(5) extends the Article 32(6) liability provision to important entities. The temporary prohibition on exercising managerial functions in Article 32(5) applies to essential entities only, and supervision of important entities is ex post, typically after evidence of non-compliance.
Is non-executive director training covered by Article 20(2)?
Article 20(2) refers to members of management bodies without distinguishing executive and non-executive members. Where national law treats non-executive directors as members of the management body, they should be included. Training can be adapted to their oversight role, focusing on challenging management and interpreting risk information rather than operational detail.
What if the entity is subject to DORA rather than NIS2?
DORA is a sector-specific act for financial entities and takes precedence over the corresponding NIS2 provisions for those entities. DORA has its own governance rules, including a requirement that the management body defines, approves, oversees and is responsible for the ICT risk management framework. Financial entities should follow DORA and confirm national treatment.
Making board accountability work in practice
NIS2 management body accountability is less about new paperwork and more about a regular, informed conversation between security leaders and the board. Define who the management body is, give it the training and information it needs, and keep a clear record of its decisions. That record is your best defence in a supervisory review.
If you would like help setting up board reporting, approvals and training evidence for NIS2, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
