NIS2 Article 20: The Personal Fine Mechanics That D&O Insurance May Not Cover — What Boards Need to Know
The management bodies of essential and important entities across the EU are learning that NIS2 Article 20 works differently from most compliance obligations they have encountered. When the organisation fails to implement the right security measures, it faces fines — up to €10 million or 2% of global annual turnover under Article 34. When the board fails to govern those measures adequately, individual directors face personal accountability — through a separate legal mechanism that D&O insurance may not cover.
These are two distinct consequences, and most NIS2 board briefings address only the first. This article focuses on the mechanics of the second: how personal director liability works under Articles 20 and 32, what triggers the temporary management ban that competent authorities can seek, why administrative fines are almost universally uninsurable across the EU, and what documented governance behaviour constitutes a defence against a finding of gross negligence.
This article is specifically for boards, general counsel, and compliance officers who need to understand the personal liability exposure and insurance gap. If you need an overview of what management bodies must do under NIS2, see our articles on board directors’ obligations and NIS2 training requirements.
What Article 20 Requires — and What “Approve” Actually Means
Article 20(1) of the NIS2 Directive (EU) 2022/2555 states that management bodies of essential and important entities must “approve the cybersecurity risk-management measures” taken under Article 21 and “oversee its implementation.” On the surface, this looks like a standard board approval obligation. In practice, it creates a continuous active governance requirement that many boards have not yet translated into their operating rhythm.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The approval function under Article 20 is not a one-time exercise. Oversight of implementation — the second obligation in Art.20(1) — requires the board to receive structured reporting on how measures are performing, evidence that gaps are being addressed, and briefings on material changes in the organisation’s risk posture. A board that approved an information security policy two years ago and has received no structured cybersecurity reporting since has not fulfilled the oversight obligation Article 20 creates, regardless of how mature the organisation’s technical controls are.
Article 20(2) adds a further, individually-directed obligation: member states must ensure that management body members “follow training” on cybersecurity. This training is intended to equip directors to identify risks and evaluate whether cybersecurity risk-management practices are effective and proportionate. Generic IT awareness training does not satisfy this requirement. The intent is substantive competency — the ability to interrogate a risk briefing rather than simply receive one.
The non-delegation principle implicit in Article 20 is where many boards encounter their first compliance gap. The organisation can appoint a CISO, retain external auditors, and implement a mature ISMS — none of which transfers the board’s governance obligation. A board actively engaging with structured cybersecurity reporting from competent specialists has fulfilled Article 20. A board that has outsourced its awareness of cybersecurity to those same specialists has not.
How Personal Liability Works Under NIS2 — Art.20, Art.32, and Art.34
The most important thing to understand about NIS2 personal director liability is where it does not live: Article 34. The headline fine figures — €10 million or 2% of global annual turnover for essential entities; €7 million or 1.4% for important entities — are levied on the entity, not on the individuals who govern it. Article 34 creates organisational financial exposure. The mechanism for individual accountability is structurally separate.
Individual director liability flows through Article 32(6), which requires member states to ensure that “any natural person responsible for or acting as a legal representative of an essential entity who has the power to ensure its compliance, may be held liable for breach of their duties to ensure compliance with this Directive.” This is an enabling provision, not a fine schedule. It mandates that member states create personal accountability pathways in their national transposition laws — but the precise consequence, the triggering threshold, and the fine amounts for individuals are set at national level, not by the Directive.
The structure that results is a three-layer system. Article 20 establishes what the board must do. Article 32(6) mandates that member states ensure natural persons can be held personally liable for failing to do it. National transposition law — company law, administrative law, civil law — determines what “held liable” actually means in each jurisdiction. A director of a German entity and a director of an Irish entity face structurally different personal exposure, even though both operate under the same Directive.
This matters for the entire basis of compliance planning. The correct question for a board is not “what does NIS2 do to me personally?” but “what does the national transposition law in each jurisdiction where my entities are established do to me personally?” The Directive sets the floor. Each member state builds on it.
The Art.32(5) Temporary Management Ban — What Triggers It and Who It Reaches
Article 32(5) gives competent authorities the power to request “that the relevant bodies, courts or tribunals prohibit temporarily any natural person who is responsible for discharging managerial responsibilities at chief executive officer or legal representative level…from exercising managerial functions in that entity.” Three features of this mechanism are consistently misrepresented in NIS2 commentary.
The ban is a compliance tool, not a punishment. Article 32(5) specifies that a prohibition operates only “until the entity concerned takes the necessary action to remedy the deficiencies.” The mechanism is designed to remove the obstacle to compliance. A CEO facing a temporary prohibition has a strong personal incentive to ensure the entity remediates its failures promptly — the ban lifts when compliance is restored. This is structurally different from a fine or a criminal sanction: the duration is entirely within the entity’s control.
The target is narrow and senior. The provision specifically reaches “chief executive officer or legal representative level” — it does not automatically extend to all board members, all C-suite executives, or non-executive directors. CFOs, CISOs, and general counsel may face consequences under national law separately, but they are not the primary target of Art.32(5). The prohibition connects to the person who leads the entity’s executive management or acts as its legal representative.
It is not a unilateral regulatory act. The competent authority must request that a court or relevant tribunal issue the prohibition. Procedural safeguards apply. This is not an administrative order issued directly by the regulator — it is a judicial or quasi-judicial process that the regulator initiates.
The Art.32(5) ban is also not triggered by a first compliance failure. It follows a finding that initial enforcement measures have been ineffective. The typical enforcement sequence is: competent authority identifies a compliance gap → issues a binding corrective order → entity fails to remedy adequately → authority then seeks the management prohibition. A board that responds promptly to regulatory directions is unlikely to reach this stage. The provision targets persistent non-remediation, not initial non-compliance.
Italy’s national transposition illustrates how member states have operationalised this mechanism. Italian law allows the competent authority to impose “the accessory administrative sanction of incapacity to perform managerial functions” — applicable to directors, CEOs, and legal representatives. Reinstatement requires the individual to demonstrate that the deficiencies have been addressed. Unlike the Directive’s primary framing, Italy applies this sanction to both essential and important entities.
Why D&O Insurance May Not Cover NIS2 Board Liability
The instinctive board response to personal liability is to review the Directors & Officers insurance policy. For NIS2, that review produces an uncomfortable result in most EU jurisdictions.
NIS2 administrative fines are almost universally uninsurable across the EU. France, Germany, the Netherlands, and Italy — four of the largest EU economies and active NIS2 enforcement jurisdictions — explicitly prohibit the contractual indemnification of administrative penalties. The prohibition is not a policy drafting quirk; it reflects deliberate regulatory philosophy. If organisations can transfer fines to an insurer, the deterrent effect disappears. Regulators have structured the penalty regime so that fines must be paid from the entity’s own resources, not covered by an insurer paying on the organisation’s behalf.
Standard D&O policy language contains three mechanisms that NIS2 liability tends to activate:
- “Administrative fines not covered” — the most direct exclusion. Where national law bars indemnity for administrative penalties, the policy cannot pay the fine regardless of other coverage language.
- “If insurable by law” — the most dangerous for multinational boards. A policy that appears to offer coverage conditions it on local insurability. For an entity operating across multiple EU jurisdictions, this can mean coverage in one country and no coverage in several others — discovered only after a claim is filed.
- Gross negligence and intentional misconduct exclusions — the clauses that create the most acute personal risk under NIS2. A board that approved policies without reviewing implementation evidence, failed to receive structured cybersecurity reporting, or has no individual training logs for its members is precisely the governance profile that a competent authority would characterise as gross negligence. If a regulator makes that finding, insurers invoke these exclusions and deny claims in full.
What D&O policies do cover is narrower but genuinely valuable: legal defence costs when a director is personally investigated, forensic investigation costs, crisis communications, and regulatory response expenses — provided there is no finding of wilful misconduct or gross negligence. These costs can be substantial in a major NIS2 enforcement action, and the coverage is real for directors who can demonstrate active governance engagement.
The practical gap is this: the governance behaviours that constitute gross negligence under NIS2 — approving policies without questioning the evidence, signing off on risk reports without documented engagement, missing mandatory training — are exactly the behaviours that void D&O coverage. Directors who maintain a proper record of active governance engagement are protected where policies respond. Directors who do not are exposed where policies do not.
The required action for boards is specific: obtain written, jurisdiction-specific confirmation from the insurer or broker of what NIS2-related liability is and is not covered — not a product summary or verbal assurance, but a written legal opinion covering each country of operation. That document itself becomes compliance evidence. Regulators increasingly expect that the board has assessed its insurance coverage gaps as part of its governance responsibilities under Article 20.
National Implementations That Extend the Art.20 Baseline
Article 20 sets a minimum standard across the EU. Several national transpositions have gone further — in ways that materially affect the personal exposure of directors operating in those jurisdictions.
Germany is the most significant example. Germany’s NIS2 implementation — the Cybersicherheitsstärkungsgesetz, amending the BSI Act — introduces personal liability through Section 38. Under §38(1), directors must “implement the necessary risk management measures and monitor their implementation.” Under §38(2), directors face civil liability for damages when those duties are breached.
The language gap matters. Article 20(1) of the Directive says management bodies must “approve” cybersecurity measures. Germany’s §38(1) says directors must “implement” them — a standard that appears to exceed the Directive’s baseline by requiring active implementation involvement rather than governance-level approval and oversight. The gap may reflect an error in legislative drafting, but until corrected, German directors operate under a more demanding standard.
This matters in combination with pre-existing German corporate law. Section 43 of the GmbHG creates personal civil liability with private assets for GmbH directors who breach their duties of care. Section 93 of the AktG creates an equivalent standard for Aktiengesellschaft directors — with a reverse burden of proof: the director must demonstrate they acted with appropriate diligence, not the regulator. As one German law firm has observed: “NIS2 makes the management duty explicit; §43/§93 makes it personal.”
A German director facing a NIS2 investigation does not encounter only regulatory exposure. They face the prospect of civil claims from the company or its shareholders under existing corporate law, triggered by the same governance failure that attracted regulatory attention. And under AktG, the burden of proof is theirs to displace.
One important scope distinction in Germany: the BSI Act’s personal liability framework targets executive functions. In a two-tier governance structure, this means the Vorstand (executive management board), not the Aufsichtsrat (supervisory board). Supervisory board members exercise oversight rather than executive management and are not the primary personal liability target under §38.
The broader EU pattern is of member states using Article 32(6) as an enabling provision to layer national corporate, administrative, and civil law onto the Directive’s baseline. Directors operating across multiple member states should treat Article 20 compliance as the minimum floor — and obtain jurisdiction-specific legal advice on what personal liability looks like in each country where their entities are established.
Art.20(4) — The Public Sector Carve-Out and What It Does Not Exempt
Article 20(4) provides that the personal liability provisions are “without prejudice to national law as regards the liability rules applicable to public institutions, as well as the liability of public servants and elected or appointed officials.” This carve-out is sometimes cited as protecting public sector leaders from NIS2 personal liability. The reality is more limited.
What Art.20(4) does is preserve each member state’s existing framework for governing civil servant accountability. A Director-General of a government agency in scope under NIS2 Annex I faces the same governance obligations under Article 20 as a private-sector CEO. What changes is the consequence of failing those obligations: it follows civil service law rather than the company-law personal liability standard. Civil service liability frameworks vary significantly across member states — some provide strong protections for public officials, others impose meaningful personal accountability that approaches the corporate law standard. Art.20(4) is a reference to national law, not a universal safe harbour.
Article 34(7) operates in parallel, permitting member states to decide whether and to what extent administrative fines can be imposed on public administration entities. Some member states have taken up this option; others apply the full fine regime. The result is substantial jurisdictional variation in whether public agencies face organisational fines under NIS2 and at what scale.
One limit of the Art.20(4) carve-out is critical: it covers liability rules only. Public administration entities retain full exposure under Article 32’s supervisory toolkit — on-site inspections, security audits, binding corrective orders, public disclosure of compliance violations, and external audits at the entity’s cost. What the carve-out prevents, in most implementations, is the management prohibition under Art.32(5) being applied to public officials. The supervisory pressure is real; the personal ban and fine mechanics route through national law.
The Governance Evidence That Constitutes a Defence
Under Article 20, what separates a director facing a gross negligence finding from one who is not is almost entirely a matter of documented evidence. Competent authorities investigating a governance failure seek to answer four questions: Was the board briefed on the organisation’s risk posture? Did the board formally approve the cybersecurity measures in place? Did the board receive ongoing reporting that would have revealed compliance gaps? Did individual directors engage substantively, with named attribution in the record?
Collective board attestations provide weak protection. A board minute that says “the board approved the Information Security Policy” is a less defensible record than one that identifies which directors attended, which version of the policy was approved, what questions were raised and by whom, and who signed the resolution. The Directive does not require perfect cybersecurity — it requires documented, informed governance of cybersecurity measures.
Four specific artefacts form the core of a defensible Article 20 record:
- Named policy approvals — a signed board resolution or meeting minute referencing the specific policy version, the approval date, and the directors approving it, not just a generic board reference
- Individual training completion logs — timestamped records per director, not aggregate attendance data; each director’s completion must be individually traceable per Art.20(2)
- Board briefing records — documenting what risk posture information the board received, when, and in what form, to demonstrate that oversight under Art.20(1) was exercised between formal approvals
- Oversight evidence — KPI reports, management updates, or security review outputs showing the board was kept informed of implementation progress
The behavioural standard underlying these artefacts is as important as the documents themselves. Regulators consistently treat board silence as the marker of gross negligence. A director who attends every meeting but has no attributed engagement in the record — no questions, no challenge, no documented concern — has not fulfilled the oversight obligation Article 20 creates. Active, recorded engagement is both the ethical standard and the strongest available legal defence against a finding of gross negligence.
For boards putting these structures in place now, the Art.20(2) training requirement provides an immediate starting point. Ensuring each director completes individually-logged cybersecurity training creates one of the four core artefacts and generates the substantive competency that makes structured challenge at board level possible. See also our NIS2 penalties overview for the full picture of organisational and supervisory enforcement consequences.
Frequently Asked Questions
Does NIS2 create direct fines against individual directors?
No. Article 34 fines apply to the entity — €10M or 2% of global turnover for essential entities; €7M or 1.4% for important entities. Individual director liability operates through Article 32(6), which requires member states to create personal accountability pathways in national law. What those pathways cost individuals depends on each member state’s transposition and existing corporate law, not on the Directive itself.
Who can be subject to the Art.32(5) temporary management ban?
The ban targets individuals “responsible for discharging managerial responsibilities at chief executive officer or legal representative level.” It must be requested by the competent authority and granted by a court or tribunal — it is not a unilateral regulatory act. Non-executive directors and other C-suite roles are not the primary target of Art.32(5), though they may face separate consequences under national corporate or administrative law.
Does the public sector carve-out in Art.20(4) eliminate personal liability for civil servants?
No. It routes personal liability through civil service law rather than company law. Public sector entities in NIS2 scope face identical governance obligations under Art.20 and identical supervisory measures under Art.32 — including binding corrective orders and public disclosure of violations. The carve-out affects the liability framework, not the compliance obligations.
What if a D&O policy says it covers “regulatory investigations”?
Coverage for regulatory investigation costs — legal defence, regulatory response, forensics — is different from coverage for the administrative fine itself. The former is commonly covered; the latter is almost universally excluded by law in France, Germany, the Netherlands, and Italy. Directors should obtain written, jurisdiction-specific confirmation of both, and treat that document as compliance evidence.
Can completing NIS2 cybersecurity training eliminate personal liability?
Training (required by Art.20(2)) is a necessary element of demonstrating governance engagement but not sufficient alone. Directors also need documented evidence that training translated into informed board conduct: structured review of risk reports, recorded questions and challenge in board meetings, formal approval records with individual attribution. Training demonstrates competency; the governance record demonstrates it was exercised.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS2 Directive Article 20 — nis-2-directive.com
- NIS2 Directive Article 32 — nis-2-directive.com
- NIS2 Directive Article 34 — nis-2-directive.com
- Evolution of D&O Liability: NIS2 Example — Noerr
- NIS2 Directors’ Personal Liability — DLA Piper
- Director Liability Under §43 GmbHG and NIS-2 — Sectepe
- Can Insurance Cover NIS2 Fines? — ISMS.online
- How Article 20 Makes Boardroom Cyber Liability Personal and Auditable — ISMS.online
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
