NIS2 Scoring
EUEuropean Union · English
a service bySightadel

NIS2 guide

NIS2 duties of the management body

NIS2 makes cybersecurity a matter for the top of the organisation. The management body must approve the risk-management measures, oversee their implementation and follow training. Its members can be held liable for infringements. How exactly is set by national law.

Last updated: October 2026 · Legal basis: Directive (EU) 2022/2555 (NIS2); details depend on national law

What Article 20 requires

Article 20(1) obliges Member States to ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken under Article 21, oversee their implementation and can be held liable for infringements of that article by the entity. Article 20(2) requires members of management bodies to follow training, and encourages entities to offer similar training to their employees on a regular basis.

The term “management body” is not defined uniformly. It covers the persons who manage the entity under national company law: the board of directors, the executive board, the managing directors. In a two-tier structure, national law decides how duties are divided between executive and supervisory boards. Check your national transposition law and company law for the precise allocation.

Approve and oversee

Approval means more than a signature on a document prepared by IT. The management body should understand what risks the organisation faces, which measures address them and which risks remain. Evidence is a formal resolution with date, the list of approved measures and the basis for the decision, such as the risk assessment.

Oversight is a continuing duty. A one-off approval is not enough. A practical approach is a fixed report to the management body, at least every quarter, covering:

  • status of the measures under Article 21 and any delays,
  • significant incidents and near misses since the last report,
  • open findings from audits or authority inspections,
  • top risks and decisions needed, for example on budget or risk acceptance.

Record that the management body has received and discussed the report. Minutes are your evidence of oversight.

Training for the management body

Members of management bodies must follow training so that they have sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services the entity provides (Art. 20(2)). The directive does not set a format or frequency. Some national laws add details, such as a regular interval or proof of attendance.

Useful content includes the current threat landscape for your sector, the national legal duties, how incident reporting works in your organisation and what decisions the management body must take during an incident. Keep attendance certificates for every member. A tabletop exercise with the management body is often more effective than a lecture and counts as a test of your incident process at the same time.

Liability

NIS2 requires that members of the management body can be held liable for infringements of Article 21 by the entity (Art. 20(1)). The directive leaves the form of liability to national law. It applies without prejudice to national rules on liability in public institutions and on the liability of public servants and elected officials.

For essential entities, Article 32(6) goes further: Member States must ensure that any natural person responsible for or acting as a legal representative of an essential entity has the power to ensure compliance, and can be held liable for breach of their duties to ensure compliance with the directive.

In practice, national laws take different routes. Some refer to existing company law, so that directors are liable to the company for damage caused by a culpable breach of duty. Others provide for administrative fines on individuals. Our country versions describe the national rules where we have them.

Important: Responsibility cannot simply be delegated. Appointing a CISO or an external provider is sensible, but the management body remains responsible for approval and oversight.

Temporary bans and other measures

For essential entities, the directive provides a further step where earlier enforcement measures fail. If an entity does not take the required action within the deadline set by the authority, the authority may request that a natural person discharging managerial responsibilities at chief executive officer or legal representative level be temporarily prohibited from exercising managerial functions in that entity (Art. 32(5)(b)). It may also suspend a certification or authorisation for the services concerned (Art. 32(5)(a)). These measures apply only until the entity has remedied the deficiencies.

Such bans are not part of the minimum regime for important entities. Some Member States have extended them, others have not. They are a last resort, but their existence shows how seriously the directive takes the role of management.

First steps for the management body

  • Have the scope assessment and classification presented and record the result.
  • Appoint a person responsible for information security with a written mandate and budget.
  • Approve the security policy and the plan for the ten measures by formal resolution.
  • Set up the quarterly report and keep minutes.
  • Book training for every member and take part in a tabletop exercise.
  • Confirm who decides on incident reports out of hours.

The NIS2 scoring checks these points in the area “Management body” and weights them highly, because gaps here have direct legal consequences. The possible fines are explained on a separate page.

Frequently asked questions

Can the board delegate NIS2 to the IT department?

Implementation, yes. Approval and oversight remain with the management body under Article 20(1). Members can be held liable for infringements of Article 21 by the entity.

How often must managers be trained?

The directive requires training but sets no interval (Art. 20(2)). Several national laws require it regularly. A yearly session plus an exercise is a sensible minimum.

Are directors personally liable under NIS2?

The directive requires that they can be held liable; national law decides how, for example through company law or administrative fines. For essential entities, Article 32(6) also requires liability of legal representatives.

Can a CEO be banned from managing?

For essential entities, yes, as a last resort. If an entity fails to act on an authority’s order, the authority can request a temporary prohibition from exercising managerial functions (Art. 32(5)(b)).