Abstract network of glowing blue nodes representing NIS2 board-level cybersecurity governance

NIS2 Board Presentation Template: 8 Slides Built From the Regulator’s Own 10 Questions — and Why Slide 8 Asks for Approval, Not Budget

A NIS2 board deck that ends on “please approve €340,000” has asked for the wrong thing. Article 20(1) does not hand the management body a budget to sign off. It hands them cybersecurity risk-management measures to approve, an implementation to oversee, and personal liability attached to both. The money is a consequence of that approval, not its subject — and decks that invert the order get deferred, because the board is being asked to spend before it has been asked to decide.

This is the slide structure built backwards from that fact: eight slides that answer the ten questions a national competent authority tells board members to ask, and that leave behind the four records a supervisor can later demand to see.

What your board is actually doing when it approves the deck

In plain terms: the board is not receiving a briefing. It is performing a legal act, and the deck is the evidence of what it knew when it performed it.

Article 20(1) of Directive (EU) 2022/2555 requires Member States to ensure that management bodies of essential and important entities “approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article” [1].

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Three obligations sit in that one sentence, and they behave differently. Approval is a point event — it happens in a meeting, on a date, against a named document. Oversight is continuous and cannot be discharged by the same meeting. Liability attaches to the members personally. A single deck can complete the first obligation and only start the second, which is why the cadence slide (slide 7 below) is not optional padding.

The liability tail differs by entity type. For essential entities, Article 32(5) lets a competent authority, after earlier enforcement has failed, temporarily prohibit “any natural person who is responsible for discharging managerial responsibilities at chief executive officer or legal representative level” from exercising managerial functions [3]. Article 33(5) imports only Article 32(6), (7) and (8) into the important-entity regime [4] — so that specific prohibition does not reach important-entity directors, even though Article 20 liability does. If you are unsure which side of that line you sit on, settle it before the meeting: see essential entity and important entity classification, and the detail in our guide to Article 20 management liability.

One more thing shapes how you write the slides: under Article 20(2), members of management bodies are required to follow training so they can “identify risks and assess cybersecurity risk-management practices” [1]. You are presenting to an audience the directive obliges to be trained. Pitch accordingly — a deck that over-explains what a firewall is signals that you have not read the room or the Article 20(2) training obligation.

The four records your slides have to produce

Work out what the meeting must leave behind, and the slide list stops being a matter of taste. Commission Implementing Regulation (EU) 2024/2690 sets technical and methodological requirements for Article 21(2) measures, and ENISA’s technical implementation guidance reproduces its Annex with the evidence each point expects [5]. Four of those points describe outputs only a board meeting can create.

Record the meeting must produce What creates it Annex point
A dated formal approval of the top-level security policy The board approves a named document version; the date goes into the policy itself 1.1.1(k)
Approval of risk-assessment results and acceptance of residual risks The board sees the residual risks and accepts them, or refuses and sends them back 2.1.1
A regular report on compliance status, including policy exceptions The reporting format and cadence the board signs up to receive 2.2.1
A documented result of the policy review Review at least annually, and on significant incidents or significant changes to operations or risks 1.1.2

Point 2.1.1 is explicit that “risk assessment results and residual risks shall be accepted by management bodies or, where applicable, by persons who are accountable and have the authority to manage risks, provided that the relevant entities ensure adequate reporting to the management bodies”, and it lists a “record of approval of residual risks” as evidence [5]. That single line is why slide 4 exists and why it is the slide that decides your budget.

Scope caveat: CIR 2024/2690 binds the entity types listed in its own Article 1 — DNS providers, cloud and data-centre providers, managed service providers and the other digital categories — not every NIS2 entity. If you sit outside that list, the Annex is not a rule you must meet; it is the clearest published statement of what a European regulator thinks “approve and oversee” produces on paper, and building to it is a defensible reading of Article 21(2)(a). Either way, these four artefacts belong in your evidence chain.

The ten questions your slides have to answer

Ireland’s National Cyber Security Centre — a national competent authority, not a vendor — published Guidance on Cyber Governance for Management Board Members in NIS2 entities, and it instructs boards to “address the following questions and document decisions” [7]. Ten questions, split into four strategic and six governance:

Type Question the board is told to ask Slide that answers it
Strategic Has the board formally acknowledged that cyber risk is a strategic risk? 1, 8
Strategic What is the board’s cyber risk appetite and tolerance for incidents impacting services? 4
Strategic How will cyber security be embedded into business-as-usual, technology decisions and procurement? 5
Strategic What resources will be allocated to cyber security governance and implementation? 6
Governance What are our critical assets and systems? 1
Governance What cyber risks could disrupt our services? 2
Governance How are we managing our third-party and supply chain risks? 3
Governance How do we benchmark our cyber posture? 3
Governance When was our last cyber exercise or test? 2
Governance How prepared are we to detect and respond to an incident? 3

Read strategic question four again. The resource question is one the guidance tells the board to put to you. Answering it on slide 6 is not a request for money; it is a response to a question the board has been instructed to ask — and if the deck is silent on it, the gap is a governance failure recorded against the board, not a modest ask you politely left out.

The eight slides

Each slide has one job, answers named questions, and feeds a record. Effort is the realistic preparation cost for a mid-sized entity that has already done a gap analysis.

# Slide and what goes on it Feeds Prep effort
1 Standing and scope. Entity type, the route into scope, registration status, the services and assets in scope. No threat content yet. Record 1 Low
2 Exposure. The two or three scenarios that stop your services, dated evidence of the last exercise or test, and what it found. Sector-specific, never a generic threat-landscape slide. Record 2 Medium
3 Current posture against Article 21(2)(a)–(j). Ten rows, one rating each, plus supply chain and detection called out. Nothing below the ten measures. Record 3 Medium
4 The residual risks you are asking them to accept. Named, owned, quantified where you honestly can. This is the slide that carries their signature. Record 2 High
5 The measures proposed. The actual object of approval — a named policy document, version and date, plus the risk treatment plan it sits on. Record 1 Medium
6 Resources the measures require. Staff, financial resources, tools and technologies, phased against the treatment plan. Record 1 Medium
7 Oversight cadence. What comes back, in what format, how often, and what triggers an out-of-cycle review. Records 3, 4 Low
8 The resolution. The wording you want minuted, on screen, so the secretary can capture it verbatim. All four Low

Slide 4 is where boards wake up, and it is the one most CISOs soften. Resist that. A residual-risk slide that says “we accept a 40-hour recovery time for the billing platform because closing that gap costs €180,000 and sits outside this cycle” gives directors something they can actually decide. A slide that says “residual risk: moderate” gives them nothing to accept, and under Annex point 2.1.1 there is then no record of acceptance to produce later.

Why the ask is “approve the measures”, not “approve the budget”

The resource commitment is not a separate agenda item you bolt on. Annex point 1.1.1 lists what the top-level policy must contain, and sub-point (e) requires it to “include a commitment to provide the appropriate resources needed for its implementation, including the necessary staff, financial resources, processes, tools and technologies” [5].

Read that against sub-point (k), which requires the policy to “indicate the date of the formal approval by the management bodies” [5]. The resourcing commitment is written into the document the board dates and approves. A board that approves the policy and then declines the resources has approved a document that contradicts itself on its face — and the contradiction is in writing, with a date on it. That is a far more uncomfortable position for a director than saying no to a budget line, which is exactly why slide 5 must come before slide 6.

Benchmark the number honestly. Figures of “10–15% of the IT budget” circulate widely in compliance commentary, usually without a source. ENISA’s NIS Investments 2025 study, drawing on 1,080 professionals across EU entities in sectors of high criticality, measured cybersecurity budgets at 9% of total IT budgets, a median cybersecurity spend of €1.5 million, and cybersecurity staff at 10.6% of total IT FTEs — the lowest proportion the series has recorded [6]. Those are measurements of what peers spend, not targets, and any CFO who has seen the report will know the difference. Putting an unsourced 15% on a slide invites the one question you cannot answer.

Then anchor the figure to the legal test rather than the benchmark. Article 21(1) requires measures that are “appropriate and proportionate”, assessed against “the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact” [2]. Show the number falling out of those three factors and you have made the budget slide part of the proportionality file a supervisor will ask for. If you need the underlying arithmetic, our NIS2 ROI model and the real cost of non-compliance cover the scenarios in full.

The resolution, and what the minute has to capture

Put the resolution on screen. Secretaries minute what they can see, and a paraphrase is where evidence quietly degrades. As a drafting starting point — adapt it to your own constitution and national transposition:

“The Board, having considered the cybersecurity risk assessment dated [date] and the residual risks set out therein, approves the Information Security Policy version [x.y] as the entity’s cybersecurity risk-management measures for the purposes of Article 20(1); accepts the residual risks listed at items [n]–[n]; commits the resources set out in section [x] of the policy; and will receive [quarterly] reporting on implementation, with an out-of-cycle review on any significant incident or significant change to operations or risks.”

That sentence produces all four records at once. The minute should also carry the document version approved, the approval date that goes back into the policy under 1.1.1(k), any dissent, and any item the board deferred — deferrals matter, because ENISA’s guidance on Annex point 2.2.1 lists “compliance status, including policy exceptions” among the elements a report to the management bodies should carry [5].

Annex point 1.2.3 also requires that at least one person report directly to the management bodies on network and information system security, and lists as evidence both “minutes from meetings with the management” and “evidence of business decisions made (e.g. investments in cybersecurity)” [5]. Your minute is that evidence. For the meeting mechanics and minute structure, see our Article 20 board governance framework; for the recurring reporting that follows this meeting, the CISO board reporting cadence.

Who does what with this deck

Role What this deck asks of you
CISO / IT security manager Own slides 2–4 and 6. Bring the risk register and the treatment plan into the room, not just their summaries — a director who asks “what is behind the amber on 21(2)(d)?” should get the row, not a promise to follow up.
Compliance officer / legal Own slides 5, 7 and 8. Check the policy version number matches what is on screen, that the resolution reflects national transposition wording, and that the approval date is written back into the policy afterwards.
CFO / finance Test slide 6 against the proportionality factors, not against a peer percentage. Phasing the spend against the treatment plan is legitimate; deferring it without recording a residual risk is not.
Board member You are approving named measures and accepting named residual risks. Ask for both by name. Approving “the cyber programme” creates no defensible record of what you approved.

Three failure modes that get a deck deferred

No approvable object. If no slide names a document, a version and a date, there is nothing for the board to approve and nothing for 1.1.1(k) to record. Boards sense this even when they cannot articulate it, and the meeting ends with “come back with a proposal”.

An all-green posture slide. A clean board pack feels like good news and is a liability trap for the directors receiving it: their approval was obtained on incomplete information. Annex point 2.2.1 requires that the management bodies be informed of the status of network and information security on the basis of compliance reviews, and ENISA’s guidance on that point puts policy exceptions among the elements the report should surface [5]. ENISA’s data suggests a fully green pack is rarely honest anyway — 30% of surveyed organisations had not run a cybersecurity assessment in the previous twelve months, and 28% take more than three months to patch critical vulnerabilities [6]. If your amber and red rows have vanished between the working draft and the board pack, someone has edited the evidence.

Approval without cadence. Article 20(1) has two verbs, and a deck with no slide 7 answers only the first [1]. The policy must in any case be reviewed and, where appropriate, updated by the management bodies at least annually and when significant incidents or significant changes to operations or risks occur, with the result documented [5]. Book the next review date in the same meeting, or the annual obligation becomes someone’s calendar problem eleven months from now. Our implementation roadmap sets out where this meeting sits in the wider sequence.

Frequently Asked Questions

How long should a NIS2 board presentation be?

As a practical guideline, eight slides and 20 to 30 minutes of airtime, with the risk register, treatment plan and policy available as annexes. The directive sets no format. The constraint is not attention span but evidence: in a later supervisory review, the pack attached to the minutes is what shows the board was informed, so anything material to the approval belongs in it even if you never present it aloud.

Does the board have to approve every security policy?

No. ENISA’s guidance is explicit that the top-level policy on the security of network and information systems should be approved by the management bodies, while topic-specific policies are approved “by an appropriate level of management” [5]. Bring one document to the board and delegate the rest — a deck that asks directors to approve fourteen policies will approve none of them properly.

What if the board approves the measures but cuts the budget?

Record it precisely: which measures move out of the cycle, which residual risks that creates, and that those risks were accepted. That record is what protects everyone, including the directors. Article 21(4) separately requires entities that are not complying to take corrective measures without undue delay [2], so a deferral that leaves a known gap unmanaged does not become safe simply because it was minuted.

Do group entities each need their own board approval?

Article 20(1) attaches to the management bodies of essential and important entities, so each in-scope legal entity ordinarily needs its own approval record, even where a group runs one security function. In practice that means one set of measures and a per-entity residual-risk and resourcing slide, with each board dating its own approval. Confirm the position under your national transposition before consolidating.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Directive (EU) 2022/2555 (NIS2), Article 20 — Governance. Linked above.
  2. Directive (EU) 2022/2555 (NIS2), Article 21 — Cybersecurity risk-management measures.
  3. Directive (EU) 2022/2555 (NIS2), Article 32 — Supervisory and enforcement measures in relation to essential entities.
  4. Directive (EU) 2022/2555 (NIS2), Article 33 — Supervisory and enforcement measures in relation to important entities.
  5. ENISA, Technical Implementation Guidance on cybersecurity risk-management measures, version 1.0, June 2025 — reproducing the Annex to Commission Implementing Regulation (EU) 2024/2690. Linked above.
  6. ENISA, NIS Investments 2025, December 2025. Linked above.
  7. National Cyber Security Centre Ireland, Guidance on Cyber Governance for Management Board Members in NIS2 entities. Linked above.
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: