What NIS2 Article 20 Actually Requires Your Board to Sign — and the 3 Evidence Types Regulators Will (and Won’t) Accept
Article 20 of the NIS2 Directive does not ask your board to run cybersecurity. It asks them to personally approve it, personally oversee it, and personally answer for it if the paperwork is missing. That last part is where most entities discover a gap: the measures exist, the policy exists, but nothing proves the management body actually signed off on either — and a regulator treats an undocumented approval the same as no approval at all.
This guide is deliberately narrow. It does not re-cover meeting cadence or oversight-committee design (that is covered in detail here), and it does not re-run the board-KPI reporting pack (see the board-metrics guide). What it does is answer two questions those articles leave open: exactly which decisions require your board’s own signature rather than your CISO’s, and which form of evidence — a board minute, an email, or a system log — actually survives a regulator’s request to see it.
Who Article 20 Applies To — and What “the Board” Means in Practice
Article 20 binds the management body of every essential and important entity in scope of NIS2 — not a subset chosen by sector. If your organisation clears the NIS2 scope test and lands in the essential or important tier under Article 3’s entity categorisation (see essential vs. important for how that split changes your fine exposure), Article 20 already applies to whoever legally directs the entity — a full board, a two-tier supervisory board, or a single managing director at a smaller company. There is no size carve-out for governance duties the way there sometimes is for specific Article 21 measures: a five-person SME with one founder-director still has a “management body” under the Directive, and that founder carries the sign-off duty alone. In a two-tier structure — a management board plus a separate supervisory board, common in Germany and the Netherlands — the same question comes up in every engagement: which tier actually holds the Article 20 duty? The Directive doesn’t legislate corporate-law structure; it binds whichever body has legal responsibility for directing the entity under national company law, so the honest answer is “check your own articles of association,” not “assume it’s the supervisory board because that sounds more senior.”
| Question | Answer |
|---|---|
| Does Article 20 apply if we’re an “important” entity, not “essential”? | Yes — the governance duty applies equally; only the fine ceiling differs (see the penalty section below) |
| Does it apply to a sole-director SME? | Yes — that director is the entire management body |
| Does it apply to public-sector bodies? | Yes, though national law can set separate liability rules for public servants and elected officials [1] |
| Can the board delegate the sign-off itself? | No — approval, oversight, and liability all sit with the management body under Article 20(1) [1] |
What Article 20 Actually Requires: Approve, Oversee, Be Personally Liable
The operative text is short. Article 20(1) requires Member States to ensure management bodies approve the cybersecurity risk-management measures taken to comply with Article 21, oversee their implementation, and can be held liable for the entity’s infringements of Article 21 [1]. Three separate verbs, three separate duties — a board that approves a policy once and never checks on it again has satisfied the first duty and failed the second.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Article 20(2) adds a personal training obligation: members of the management body must themselves complete training sufficient to identify risks and assess cybersecurity practices [1]. One misreading worth correcting directly: the Directive’s “regular basis” language attaches to entities encouraging employee training, not to how often the board itself must train or re-approve — there is no fixed statutory cadence for board sign-off in the Directive’s own text. Germany’s BSI reflects the same structure nationally, requiring management bodies to complete training under §38(3) BSIG and stating that cybersecurity must be integrated into how the business and its risk management actually run, not bolted on as a side process [4]. For the full Article 20(2) training-evidence standard, see the board training requirements guide.
The Board Sign-Off Inventory: 9 Decisions Your CISO Can’t Sign for You
Every one of the items below can be drafted by a CISO, a consultant, or a compliance officer. None of them can be approved by one, because Article 20(1) puts the approval act itself with the management body [1].
| # | Decision | Who can prepare it | Why the board must personally sign |
|---|---|---|---|
| 1 | The Article 21 risk-management measure set (the core control programme) | CISO / security team | Named directly in Article 20(1) as requiring management-body approval [1] |
| 2 | Information Security Policy and material version updates | CISO / compliance | A policy without a dated approval resolution is, per practitioner guidance, indistinguishable from a draft [7] |
| 3 | Risk acceptance and risk-exception decisions | Risk owner proposes | Accepting residual risk is a governance judgement call, not a technical one [6] |
| 4 | Supply-chain risk framework and critical-supplier list | Procurement / CISO | Board-level sign-off is what regulators check for supplier risk exposure — see the full supply-chain security guide |
| 5 | Incident-severity criteria and notification sign-off authority | Incident response lead | Who decides an incident meets the Article 23 threshold has to be a board-ratified decision, not an ad hoc one — see Article 23 incident notification |
| 6 | Business continuity / disaster recovery plan | Operations / IT | Falls inside the Article 21 measure set the board must approve as a whole [1] |
| 7 | Cybersecurity budget tied to approved Article 21 measures | CISO / finance | Approving a measure without resourcing it is the “rubber-stamping” pattern practitioner guidance flags as failing oversight [7] |
| 8 | Risk register review (substantive, not received-and-noted) | Risk owner maintains | Oversight requires evidence of engagement with the register, not just its existence [6] |
| 9 | Individual director training completion | N/A — personal to each director | Article 20(2) makes this each director’s own obligation; nobody else can complete it for them [1][4] |
Evidence Sufficiency: Board Minutes vs. Email vs. System and DLP Logs
Assume every decision in the table above happened. The question a regulator actually asks is narrower and more uncomfortable: can you prove it, on one page, with a name, a date, and a document version attached? Practitioner compliance guidance frames the accepted evidence set explicitly as “a board minute, a signed approval record, or a system log showing who approved which policy version on which date” — and treats verbal approval, references to standard practice, or undated records as insufficient on their own [5]. Not every item on that list carries equal weight, and one of them proves something different from what people assume.
| Evidence type | What it proves | What it doesn’t prove | Verdict |
|---|---|---|---|
| Board minute / formal resolution (named votes, dated, versioned) | Genuine deliberation and a specific approval act tied to a named group of directors [8][9] | Nothing missing if drafted properly — this is the reference standard | Strong |
| Signed individual approval record on a specific document version | A named person approved a specific, identifiable version on a specific date [5] | Board-level oversight, if it substitutes for minutes entirely rather than supplementing them | Moderate–Strong |
| Email approval chain | That a message was sent and, sometimes, read | Formal deliberation; a named law firm’s own guidance states plainly that “emails, slide decks, or executive’s notes will not suffice” as a substitute for proper minutes, and that personal-account email use creates its own discovery and privilege risk in litigation [8][9] | Weak |
| System or DLP log (policy push confirmations, access-control enforcement records, monitoring timestamps) | That a technical control was actually enforced on the network at a given time — useful evidence for the Article 21 implementation side | That the board approved anything. A DLP log shows a rule fired; it says nothing about who authorised the policy behind it. Treat system logs as evidence of technical enforcement, not as a substitute for the governance sign-off Article 20 actually asks for — a distinction worth building into any evidence package deliberately, since the two are easy to conflate | Insufficient alone |
| Verbal approval / “this is how we’ve always done it” | Nothing a regulator can independently verify | Everything | Insufficient |
The underlying test, per the same practitioner guidance, is whether the answer to “prove this was approved” fits on one page without reconstruction — specific person, specific version, specific date, together [5]. If producing that answer means searching six inboxes and a Slack channel, the evidence has already failed regardless of whether the decision itself was sound.
Building a Sign-Off Package That Survives an Audit Request
| Step | Action | Effort |
|---|---|---|
| 1 | Run the 9-item inventory above against your own governance records — mark each Present, Weak, or Missing | Low |
| 2 | For each item, assign one accountable evidence owner and the required evidence type (minute, signed record, or supporting log) | Low |
| 3 | Close gaps by formal re-ratification at the next board meeting — record the rationale for why the approval is happening now rather than backdating anything, since regulators expect contemporaneous records, not retrofitted ones [7] | Medium |
| 4 | Move recurring approvals off personal email and onto a board portal or document-management system with version control — the same risk Baker Botts flags for litigation discovery applies equally to a regulator’s document request [8] | Medium |
| 5 | Set a review cadence for the Article 21 measure set — the three oversight-model comparison covers which cadence fits which entity size | Medium (first pass), Low (ongoing) |
| 6 | Run the one-page test on all 9 items before an audit, not during one | Low |
What Happens When the Sign-Off Trail Doesn’t Exist
Competent authorities don’t need a complaint to check essential entities — Article 32 lets them run security scans and order independent audits at their own initiative, with the audited entity paying the audit cost in most cases [2]. When findings point to a governance failure rather than a technical one, Article 32(5) allows escalated measures: temporary suspension of a certification, or a temporary ban on a named individual at CEO or legal-representative level from exercising managerial functions — lasting only until the deficiency is remedied, and subject to due-process safeguards [2]. Separately, Article 34 sets the fine ceiling for Article 21/23 infringements at €10,000,000 or 2% of worldwide annual turnover for essential entities, and €7,000,000 or 1.4% for important entities — whichever figure is higher in each case [3]. A missing sign-off trail doesn’t create a new fine category; it removes the one thing that would have shown the underlying Article 21 measures were properly governed, which is exactly what turns a technical gap into a personal one — and personal exposure is precisely where D&O insurance policies most often have gaps, covered separately in the D&O insurance mechanics guide. Full national fine variations are tracked in the penalties guide.
Who Owns What: Board, CISO, Compliance, and Legal
| Role | Owns |
|---|---|
| Management body (board / sole director) | Personal sign-off on all 9 inventory items, personal training completion, non-delegable liability under Article 20 — see CEO responsibilities under NIS2 |
| CISO / security lead | Drafts measures, presents them for approval, executes what’s approved, maintains the day-to-day audit trail — see the board-reporting KPI guide |
| Compliance / Legal | Builds and periodically tests the evidence package against the sufficiency standard above; flags any item resting on email or verbal approval alone |
| Founder / sole director (SME) | Holds all three roles at once — the sign-off duty doesn’t shrink because there’s no one to delegate it to |
Frequently Asked Questions
Can the CISO sign the Article 21 measure set on the board’s behalf? No. Article 20(1) places the approval act itself with the management body; a CISO’s sign-off, however senior, doesn’t satisfy the Directive’s requirement [1].
Does a Slack or Teams message count as board approval? No, for the same reason email doesn’t — it isn’t a formal deliberative record, and named legal guidance treats it as insufficient to substitute for minutes [9].
Do DLP or system logs prove NIS2 compliance on their own? They prove a technical control fired at a given time. They don’t prove the board approved the policy behind it — keep the two forms of evidence separate rather than assuming one covers the other.
How often must the board formally re-approve the measures? The Directive sets no fixed cadence in Article 20 itself; quarterly review is the practitioner norm for essential entities, discussed by oversight model in the governance framework guide [6][7].
What if we discover a sign-off gap on a measure that’s already been running for a year? Ratify it now, dated as of now, with a minute explaining that the measure was in effect from an earlier date and is being formally approved at this meeting. Don’t backdate the resolution itself — an honest “approved today, in effect since” record is defensible; a backdated one is not, and undermines every other minute in the same book if it’s ever challenged [7].
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Article 20, Directive (EU) 2022/2555 (NIS2) — nis-2-directive.com
- Article 32, Directive (EU) 2022/2555 — nis-2-directive.com
- Article 34, Directive (EU) 2022/2555 — nis-2-directive.com
- BSI (Germany) — NIS-2-Geschäftsleitungsschulung
- Policy Confirm — NIS2 Article 20: Personal Liability and Evidence for Management
- TTMS — NIS2 Compliance Documentation: Evidence Checklist
- Glocert International — NIS2 Governance & Management Accountability
- Baker Botts LLP — Corporate Governance Field Guide: Board Communications
- Cummings & Cummings Law — Legal Requirements for Corporate Recordkeeping of Board Minutes
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
