NIS2 Article 20 management liability and governance obligations

NIS2 Article 20: Approve, Oversee, and Accept Personal Liability — What It Means for Management

Does Article 20 Apply to Your Organisation?

Article 20 of Directive (EU) 2022/2555 applies to all essential entities and important entities as defined in NIS2 Annexes I and II. If you have not confirmed your organisation’s scope, use the NIS2 scope checker before reading further — Article 20 obligations only activate once you are in scope.

The directive includes a limited carve-out for the public sector: Article 20(1) applies “without prejudice to national law as regards the liability of public authorities and public servants.” Public administration bodies in scope for NIS2 remain bound by the training obligation in Article 20(2), and entity-level liability continues to apply.

Entity type Art. 20(1) approval and oversight? Art. 20(2) training?
Essential entities (Annex I) Yes Yes
Important entities (Annex II) Yes Yes
Public administration bodies Yes (national liability rules apply) Yes
Out-of-scope organisations No No

Not sure whether your organisation is essential or important? The distinction affects which enforcement regime applies — see essential vs. important entities explained.

Article 20 Decoded: Three Verbs, Three Obligations

Article 20 contains two paragraphs. The first contains three verbs that carry the entire weight of the governance obligation. The second adds a training requirement that most organisations underestimate.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Article 20(1) — Member States shall ensure that management bodies of essential and important entities “approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements.”

Article 20(2) — Member States “shall ensure that the members of the management bodies of essential and important entities are required to follow training” and “shall encourage essential and important entities to offer similar training to their employees on a regular basis, in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity.”

Those three verbs in Article 20(1) — approve, oversee, be held liable — are not synonyms for passive board involvement. Each carries a specific, auditor-testable requirement. The sections below work through each in turn.

Obligation 1: Approve — What the Directive Actually Requires

The directive requires management bodies to “approve” the cybersecurity risk-management measures taken by the entity to comply with Article 21. That single word is the one most often misread — and the one that generates the most audit findings.

Approval is not a briefing. Receiving an annual IT security presentation does not satisfy Article 20(1). Neither does delegating all cybersecurity decisions to the CISO or a technical committee. And a board minute that reads “AOB — cybersecurity reviewed and noted” is treated by regulators as equivalent to no approval at all.

Approval is a documented board decision. It must record which specific measures were tabled, what discussion took place, and what the management body resolved. As one compliance analysis states: “Approval must be documented. A board minute, a signed approval record, or a system log showing who approved which policy version on which date. Verbal approval is insufficient.”

The ten domains across which management bodies must approve measures are set out in Article 21(2):

Article 21(2) domain What it covers
Risk analysis and security policies Organisational frameworks for identifying and addressing threats
Incident handling Detection, response, and management of security events
Business continuity Backup systems, disaster recovery, and crisis management
Supply chain security Oversight of direct suppliers and service provider relationships
Secure network acquisition and development Vulnerability management and disclosure for network and information systems
Effectiveness assessment Evaluation of cybersecurity risk-management measures
Cyber hygiene and training Foundational practices and employee security awareness
Cryptography and encryption Policies governing encryption technology deployment
Human resources, access control, and asset management Personnel security, access restrictions, and asset tracking
Multi-factor authentication and secured communications Authentication controls and secured voice, video, and text channels

Management bodies must not only approve the existence of policies across these ten domains — they must demonstrate ongoing approval as those measures evolve in response to changes in the threat landscape.

A note on “management body” definition. The NIS2 Directive provides no single EU-wide definition that maps cleanly to every corporate structure. In two-tier board arrangements (common in Germany, the Netherlands, and Austria), the obligation falls on the executive board, not the supervisory board. Germany’s implementing legislation — the BSI Act, Section 38 — explicitly captures only those with executive powers; supervisory board members are outside its scope. In single-tier structures (common in France, Ireland, and Nordic countries), the unitary board as a whole constitutes the management body.

Obligation 2: Oversee — Active Governance, Not Passive Awareness

The second verb in Article 20(1) is “oversee.” It appears after “approve” and before “be held liable” — and it is the obligation most easily satisfied on paper while failing in practice.

Oversight means the management body maintains documented, active engagement with how the Article 21 measures are being implemented — not that they receive a once-yearly slide deck from IT. Competent authorities look for evidence that management asked questions, tracked progress, and required remediation where gaps were found.

Quarterly reporting cadence. Management bodies should receive structured cybersecurity reporting at least four times per year. That reporting should include measurable KPIs: critical vulnerability counts, patch compliance rates, mean time to detect (MTTD), vendor risk assessment status. A once-annual briefing does not satisfy the directive’s “oversee its implementation” standard.

Incident escalation records. When significant incidents occur, there must be documented evidence that the management body was briefed promptly — including what questions they asked, what they decided, and what remediation they authorised. These records become primary evidence if a regulator investigates the board’s response to a breach.

Supply chain visibility at board level. Article 21(2) includes supply chain security as a required domain. Oversight means the management body receives regular updates on supplier assessments, material changes in vendor risk profiles, and the status of contractual security obligations — not that these topics are handled entirely below board level.

Documented follow-up on gaps. Each board review session must record not only what was reported but what the management body decided: which gaps were accepted, which were escalated, and what remediation timeline was set. Minutes that summarise a discussion without recording the resolution are insufficient.

The distinction between oversight and delegation becomes stark during incident investigations. When a regulator examines what the board knew and what it did, generic “cybersecurity was on the agenda” minutes carry the same evidential weight as no oversight record at all. See the board directors compliance guide for a full reporting framework.

Obligation 3: Be Held Liable — Personal Consequences Explained

Article 20(1) states that management bodies “can be held liable for infringements” of Article 21. That phrase is activated by two separate provisions in Article 32 of the directive, which set out what personal liability actually looks like.

Article 32(6) — personal liability for natural persons. Member States must ensure that natural persons who are responsible for or serve as the legal representative of essential and important entities “can be held liable for breach of their duties to ensure compliance with this Directive.” This moves accountability from the corporate entity alone to the individuals who hold management responsibility — in practice, the CEO, legal representative, or whoever holds the decision-making mandate.

Article 32(5)(b) — temporary management bans. If earlier enforcement measures prove ineffective for essential entities specifically, competent authorities may request courts or relevant tribunals to “prohibit temporarily any natural person who is responsible for discharging managerial responsibilities at chief executive officer or legal representative level from exercising managerial functions in that entity.” The ban remains in effect until the entity achieves compliance. Procedural safeguards apply: the right to an effective remedy and a fair trial must be preserved.

This is a provision without precedent in EU cybersecurity law. It can apply across any essential entity — not only the one where the violation occurred. A director banned from one essential entity cannot assume equivalent functions at another until the bar is lifted.

Member state variations. The directive sets the framework; member states implement the specific personal sanctions.

Germany’s BSI Act (Section 38) establishes direct personal liability for management body members and adds a restriction with no equivalent in the directive: shareholders cannot release directors from NIS2 liability through a corporate waiver — a deliberate departure from standard German corporate law. Italy’s national cyber agency (ACN) explicitly targets individual organ members rather than treating the management body as a collective. As of mid-2026, enforcement actions have been issued in Germany, the Netherlands, and France.

The D&O insurance gap. Directors and Officers insurance was designed for corporate governance liability, not regulatory cybersecurity exposure. The sanctions available under Articles 32(5)(b) and 32(6) — including temporary management bans and personal liability for compliance failures — may fall outside standard D&O coverage. Directors of essential entities should verify whether their policy explicitly includes NIS2 regulatory sanctions and whether legal defence costs for management bans are covered. Many standard policies require specific endorsement for regulatory fines.

For a full breakdown of entity-level penalties — up to €10 million or 2% of global turnover for essential entities — see the NIS2 penalties guide.

Training Requirements Under Article 20(2)

Article 20(2) splits training into two tiers with different levels of obligation, and most organisations get the split backwards.

Mandatory for management body members. Member States must require all members of the management body to follow training. This is not optional, not delegatable, and not satisfiable by having the CISO present at a board meeting. Every member of the management body — whether or not they have a technical background — must complete training that gives them sufficient knowledge to “identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity.”

Encouraged (not mandatory) for employees. The directive “encourages” entities to offer similar training to their employees on a regular basis. The training standard is the same — risk identification, practice assessment, service impact understanding — but the member state obligation is to encourage, not mandate.

The directive specifies no training frequency. Audit practice and national regulatory guidance have converged on the following practical framework:

Training type Practical standard Evidence required
Formal board cybersecurity training Annual or biannual Attendance records, certificates, content agenda
Quarterly risk and incident briefings Quarterly minimum Board minutes, briefing packs, KPI dashboards
Post-incident learning review After every significant incident Review minutes, management participation noted
Onboarding training Before assuming management responsibilities Completion record tied to appointment date

The directive’s goal is demonstrable competency, not a training log. Regulators look for evidence that management bodies can challenge security plans, evaluate proposed measures, and interrogate incident reports — not merely that they attended a session. See the dedicated guide to NIS2 training requirements for content requirements and role-specific frameworks.

The contractor acknowledgement gap. Many organisations track staff training completion but do not extend records to contractors, managed service providers, and vendors with access to critical systems. These third parties operate inside the entity’s risk perimeter and should be covered by equivalent awareness programmes with individual, timestamped acknowledgement records. The absence of contractor training evidence is one of the most consistent gaps found during NIS2 compliance assessments.

What Auditors Test: Building Your Article 20 Evidence Pack

Article 20 compliance is an evidence question as much as a process question. The five categories competent authorities systematically examine are:

1. Policy approval records. Named policies approved by the management body, with dates, version numbers, and a documented resolution. Not a forwarded email, not an implied sign-off — a recorded decision. Approval at a single point in time is also not sufficient: Article 20 requires ongoing supervision as policies are updated.

2. Board minutes with substantive content. Each meeting where cybersecurity was reviewed must show what the management body actually did: questions raised, risks accepted or escalated, remediation actions assigned with owners and deadlines. Minutes that record only topics without recording outcomes are the single most common audit finding.

3. Management training records. Attendance logs, certificates, and dates for every member of the management body. Training must be specific to the organisation’s risk profile and recurring — a one-time induction module from 2024 does not satisfy the ongoing training standard.

4. Quarterly reporting packs. Structured dashboards showing trend data: vulnerability counts, patch compliance rates, MTTD, vendor assessment status. A single snapshot does not demonstrate active oversight; regulators want to see a reporting cadence that proves the management body was engaged between incidents, not only after them.

5. Incident escalation records. Documentation that significant incidents were escalated to the management body, including what information was provided, what decisions were made, and what remediation was authorised. The absence of these records during an incident investigation is treated as evidence of failed oversight — regardless of how the incident itself was handled technically.

For organisations working through Article 20 gaps for the first time, a staged approach reduces the risk of trying to fix everything at once:

  • Days 1–30: Gap assessment — audit current evidence against the five categories above. Identify which are absent, incomplete, or undated.
  • Days 31–60: Complete board training; update the board’s quarterly briefing agenda to include structured KPI review.
  • Days 61–90: Produce the first compliant board minute; establish formal approval workflow for the Article 21 policy set.

The NIS2 audit preparation guide covers evidence requirements across all Articles, not just Article 20.

Article 20 Compliance Checklist

Use this checklist to assess your current position against Article 20’s three obligations.

Management body approval (Art. 20(1) — first verb)

  • Cybersecurity risk-management measures formally approved by the full management body — not delegated to CISO or IT committee alone
  • Approval documented: date, policy version, resolution text recorded in board minutes or signed approval record
  • All ten Article 21 domains covered by approved policies
  • Approval repeated when policies are materially updated

Active oversight (Art. 20(1) — second verb)

  • Quarterly cybersecurity reporting cadence established and in use
  • KPI dashboard reviewed and questions recorded in board minutes
  • Incident escalation threshold defined: which events trigger board notification and within what timeframe
  • Supply chain risk updates included in quarterly reporting cycle
  • Follow-up actions from each meeting assigned, tracked, and reported back

Personal liability readiness (Art. 20(1) — third verb + Art. 32)

  • Legal representative and CEO-level roles identified and briefed on Article 32(6) personal obligations
  • Two-tier board structure assessed: executive vs. supervisory board scope confirmed with legal counsel
  • D&O insurance policy reviewed for explicit NIS2 regulatory sanction coverage

Training (Art. 20(2))

  • All management body members completed role-appropriate cybersecurity training
  • Training records maintained: dates, content description, attendance per individual
  • Quarterly briefing programme in place with materials archived
  • Employee training programme operational with individual acknowledgement records
  • Contractor and vendor training or acknowledgement programme in place

Evidence pack

  • Policy approval records consolidated, dated, and accessible for audit
  • Board minutes archive complete, substantive, and searchable by topic
  • Incident escalation records maintained for all significant incidents
  • Quarterly reporting packs archived with trend data visible

Sources

This article draws on the following primary and secondary sources. Each claim traced to a numbered source in the text above.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: