Article 20 NIS2: Why CEO Liability Cannot Be Delegated to Your CISO — and What Regulators Require in Writing
Most CEOs hire a CISO and assume the cybersecurity governance problem is solved. Under Directive (EU) 2022/2555 — the NIS2 Directive — that assumption carries a direct line to personal financial liability.
Article 20 places three obligations on management bodies that cannot be transferred to any other function: approval of cybersecurity measures, oversight of their implementation, and personal completion of cybersecurity training. Your CISO can deliver a world-class security programme. What they cannot do is carry your Article 20(1) liability.
The October 2024 transposition deadline has passed. As of 2026, 22 of 27 EU member states have completed national implementation, and supervisory authorities in Germany, the Netherlands, and France have opened enforcement proceedings. The question is not whether your organisation is subject to Article 20 — it is whether your management body’s evidence file would survive a regulatory inspection today.
This guide covers what Article 20 requires, what evidence regulators examine, and when enforcement action targets you personally rather than the organisation.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
What Article 20 Actually Requires
Article 20(1) of Directive (EU) 2022/2555 states verbatim: “Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article.”
Article 20(2) adds: “Member States shall ensure that the members of the management bodies of essential and important entities are required to follow training…in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity.”
Three non-delegable obligations sit inside those two paragraphs.
| Obligation | Article reference | Who it applies to |
|---|---|---|
| Approve Article 21 cybersecurity risk-management measures | Article 20(1) | Management body collectively |
| Oversee implementation of those measures | Article 20(1) | Management body collectively |
| Follow cybersecurity training | Article 20(2) | Individual management body members |
The phrase “management bodies” does not name a specific role. In a sole-director company, the CEO is the management body. In a board structure, every director — executive and non-executive — carries the obligation. The directive draws no distinction based on portfolio, technical expertise, or operational involvement in security.
The text does not say management bodies shall ensure that cybersecurity measures are approved. It says management bodies shall approve them — directly, not through a delegate. That choice of language is deliberate, and it is what gives Article 20 its enforcement teeth. For an overview of what board director obligations look like across the full Article 20 framework, see the dedicated guide.
The Non-Delegable Core — Where Your Liability Ends and the CISO’s Begins
Two types of activity operate under NIS2: operational execution (what gets done) and governance accountability (who answers for it). Delegating the first does not transfer the second.
Your CISO can design and implement the Article 21 technical and organisational measures. Your IT team can run vulnerability scanning, patch management, and access controls. Your legal team can draft the policies. All of that is operational work, and delegating it is not only permissible — it is how compliance functions at scale. The management body is not expected to write firewall rules.
What the CISO cannot accept on your behalf is the Article 20(1) approval obligation. DLA Piper’s analysis of NIS2 management body rules is direct: “delegation of tasks does not equal delegation of liability.” When a supervisory authority examines whether your cybersecurity measures were appropriate and properly approved, the examination begins with the management body, not with whoever implemented the controls.
| Task | Can be delegated to CISO / IT | Cannot be delegated |
|---|---|---|
| Implementing Article 21 technical controls | ✓ | — |
| Maintaining the policy library | ✓ | — |
| Running daily security operations | ✓ | — |
| Formal approval of Article 21 measures | — | Management body (Article 20(1)) |
| Oversight of implementation at governance level | — | Management body (Article 20(1)) |
| Completing cybersecurity training | — | Individual management body members (Article 20(2)) |
| Liability for Article 21 infringements | — | Management body (Article 20(1)) |
This split has a practical implication: if your CISO is terminated following a cybersecurity incident, the liability question does not leave with them. The management body’s approval records, oversight documentation, and training completion remain the primary evidence for or against personal liability under Article 20.
What “Approval” Means When Regulators Are Watching
If approval were a board member saying “yes, we are doing cybersecurity,” Article 20(1) would carry no weight. The word “approve” in the directive carries an evidentiary standard: there must be documentation demonstrating that the management body reviewed specific measures and formally agreed to them.
Regulators examining an Article 20 compliance file look for four things.
Named approver. Not “the board,” not “senior management.” A specific named individual — the chair, the CEO, the relevant director — tied to the approval record. In a sole-director company this is straightforward. In a multi-member board, the resolution should name participants or record that no member withheld approval.
Specific date. Board minutes or a formal resolution capturing the exact date. A general reference to “ongoing governance processes” does not satisfy this. Verbal approval in a meeting — even if others were present — is weak evidence without a contemporaneous written record.
Version-specific approval. If your information security policy was approved in March 2024 and substantially revised in November 2024, the March record does not cover the November version. Regulators tie approval to document versions. Each material revision requires a new approval record.
Retrievable evidence. A document management system, formal board minute, or signed resolution that exists independently of any single person’s control. An email thread from the CEO to the CISO does not carry the same evidential weight as a formal board minute held in the company’s governance record.
PolicyConfirm’s analysis of Article 20 documentation requirements puts it directly: “verbal approval and ‘standard practice’ references are rejected as insufficient.” The approver’s name, the policy version, and the date must be on the record — without reconstruction after the fact.
Documented dissent has evidential value. If a management body member raises concerns about a measure but the board proceeds anyway, recording that dissent alongside the final decision provides a cleaner audit trail. It demonstrates active engagement rather than rubber-stamping, and it preserves the dissenting member’s position should the decision later come under scrutiny.
The Oversight Obligation in Practice
Approval is a point-in-time event. Article 20(1) also requires the management body to “oversee its implementation” — an ongoing obligation that a single annual board agenda item does not satisfy.
Defensible oversight at management body level has four components.
Regular cadence. Cybersecurity appears on the board agenda as a standing item, not as an exception triggered only by incidents. Most national guidance converges on quarterly as the minimum frequency for formal governance engagement with the cybersecurity programme.
Attributed engagement. Board minutes record who asked what, not merely that “cybersecurity was discussed.” A minute noting “the CISO presented the Q1 threat report” without attributing questions, challenges, or decisions to named individuals provides thin evidence of oversight. Minutes recording that the CEO queried the unresolved critical patch backlog and set a 30-day remediation deadline are evidentially much stronger.
Escalation paths that reach the board. Incident escalation protocols that define when the CEO or board chair is personally notified — not just when the security operations team logs an event internally. If the management body learns about a significant incident through the press, the absence of a working escalation path is itself an Article 20(1) oversight failure.
Documented response to findings. When the CISO or internal audit presents a material gap, the board’s response — the action assigned, the owner named, and the timeline set — belongs in the governance record. Boards that receive security briefings without documented responses have oversight gaps even where the information flow was adequate.
Training — What Article 20(2) Actually Demands
Article 20(2) is frequently the least-implemented element of management body compliance. Most entities train their IT and security teams regularly. Fewer can produce individual training records for their board members.
The requirement is precise about its goal: management body members must gain “sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity.” This is a competency standard, not a completion certificate. The directive is asking whether the management body can make meaningful governance decisions about cybersecurity — not whether it has sat through a presentation.
In practice, training should enable a board member to understand what the Article 21 measures the entity has adopted are intended to address, ask substantive questions about the entity’s risk profile, form an independent view on whether the CISO’s proposed measures are proportionate to assessed risk, and recognise which categories of incident should be escalated to board level.
The directive does not mandate a frequency or minimum duration. The test is whether the management body maintains sufficient competency as the entity’s risk environment evolves. A board that completed a single cybersecurity awareness session before a major cloud migration or acquisition faces a credible argument that it no longer meets the Article 20(2) standard. For a detailed breakdown of what NIS2 training requirements look like in practice, including the competency framework and evidence structures, see the dedicated guide.
The evidence that survives an audit consists of individual records — named member, date, content covered, and duration — not an aggregate organisation-level log. A record stating “J. Smith, CEO, completed Board-Level Cybersecurity Governance training, 2025-09-15, 3 hours” is the format that demonstrates compliance. A single entry noting “Company X completed NIS2 awareness training” is insufficient.
When You Are Personally Fined — and When the Organisation Pays
The distinction between entity-level and personal enforcement is where Article 20’s consequences show most clearly — and where entity classification creates a material difference in personal exposure. If you are not yet certain whether your entity is classified as essential or important, see the essential vs important entity guide before reading this section, as the distinction determines which personal enforcement mechanisms apply.
Entity-level fines apply to both essential and important entities. Essential entities face sanctions of up to €10 million or 2% of total global annual turnover under the directive’s penalty framework. Important entities face the equivalent of up to €7 million or 1.4% of global turnover. These are institutional sanctions — levied on the legal entity, not on individual management body members. For the full breakdown of how penalties are calculated and applied across member states, see the NIS2 penalties guide.
Article 32(6) personal liability applies to natural persons “responsible” for essential entities. The directive states they must ensure the entity’s compliance with NIS2 and “can be held liable for breach of their duties.” This personal liability mechanism sits in Article 32, which governs supervisory and enforcement measures for essential entities. The equivalent provision for important entities in Article 33 does not replicate the same personal liability language with the same specificity.
The temporary management ban under Article 32(5)(b) is the most consequential personal sanction. A competent authority may apply to a court or equivalent body for a temporary prohibition on a named natural person — at CEO or legal representative level — from exercising management functions until the entity remedies its deficiencies. This is not a fine payable in cash. It is removal from your role, subject to fair trial procedural safeguards. This mechanism applies to essential entities only.
Germany’s national transposition provides a specific benchmark: personal administrative fines for management body members of essential entities who negligently fail their Article 20 obligations, with reported penalties reaching up to €500,000 per infringement under the national implementing legislation. Germany’s BSI began active enforcement in Q4 2025, issuing 47 formal notices to entities primarily for failure to register and failure to designate a cybersecurity point of contact — the first enforcement wave before substantive Article 20 governance audits begin.
| Consequence | Essential entities | Important entities |
|---|---|---|
| Entity-level fine (up to €10M / 2% global turnover) | ✓ Article 32 | Equivalent limit: €7M / 1.4% (Article 33) |
| Management body personal liability | ✓ Article 32(6) | Not directly replicated in Article 33 |
| Temporary CEO / legal representative ban | ✓ Article 32(5)(b) | Not applicable |
| Personal fines under national transposition | In some member states (e.g. Germany) | Member state dependent |
The risk profile for a CEO of an essential entity is materially higher under Article 32 than for a CEO of an important entity. That asymmetry does not always appear clearly in general NIS2 summaries.
Building Your Article 20 Evidence File
An Article 20 audit trail cannot be constructed after a supervisory notice arrives. The documentation must exist in real time — and it must demonstrate all three pillars of Article 20(1): approval, oversight, and training.
| Evidence element | Format | Minimum frequency |
|---|---|---|
| Board resolution approving Article 21 measures | Signed minutes or formal resolution, naming each measure set and version date | On adoption and each material revision |
| Individual management body training records | Named log: member name, date, training content, duration | After each training session |
| Quarterly cybersecurity board report with recorded management response | Written report + board minute recording decisions and actions | Quarterly |
| Incident escalation records | Log of board-level notifications, with CEO / chair response recorded | Following each notifiable or significant incident |
| Policy version approval log | Document: policy name, version date, approver name, approval date | Each policy revision |
| Annual review of Article 21 measures | Board resolution or formal review minute with action assignments | Annually |
A critical distinction: operational evidence (CISO reports, penetration test results, patch logs) demonstrates that security work was done. Governance evidence demonstrates that the management body approved and oversaw that work. Regulators examining Article 20 compliance look specifically for the governance layer — the management body’s name, date, and version on the record, not just the security team’s outputs.
If you are still establishing whether your entity falls within NIS2 scope before building this evidence file, the NIS2 scope guide is the starting point.
Frequently Asked Questions
Does every director need to individually sign every cybersecurity policy?
Article 20(1) requires the management body to approve measures — not every individual director to sign each document. A board resolution is the appropriate approval vehicle. In a sole-director company, director sign-off on the resolution creates the equivalent record. The requirement is that a named management body member — not a delegated operational role — is tied to the approval record.
Can the CISO attend the supervisory authority inspection on behalf of the CEO?
The CISO can present technical evidence about the programme. An Article 20 audit examines the governance layer — whether the management body approved and oversaw the programme. The management body representative should be present to respond to questions about governance decisions, approval records, and oversight activity.
What if our entity recently moved from important to essential classification?
Article 20 obligations apply from the point of essential classification. Most supervisory authorities maintain a three-year investigative look-back period. If reclassification is recent, building the Article 20 documentation structure immediately — not retrospectively — is the priority.
Is there a minimum training frequency under Article 20(2)?
No specific frequency is mandated. The directive’s standard is competency: “sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices.” Annual training with individual attendance records, supplemented by sessions following material developments (significant incidents, new technology deployments, M&A activity), is the approach that most national guidance documents identify as defensible.
Does Article 20 apply to the supervisory board in a two-tier governance structure?
The directive uses “management body” without specifying one-tier or two-tier structures. Most member state transpositions apply Article 20 obligations to the management body that holds formal governance responsibility for the entity’s operations — typically the management board in a two-tier structure. Where the supervisory board formally approves governance frameworks (as in some German and Dutch corporate structures), Article 20 obligations may extend to it. Legal advice specific to the jurisdiction and corporate structure is required here.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS2 Directive). EUR-Lex CELEX 32022L2555.
- “Article 20, Governance — NIS2 Directive (EU) 2022/2555.” nis2resources.eu.
- “Article 32, Supervisory and enforcement measures relating to essential entities.” nis-2-directive.com.
- “NIS2 directive explained: Part 2 – Management bodies rules.” DLA Piper.
- “NIS2 Article 20: Personal Liability and Evidence for Management.” PolicyConfirm.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
