8 Audit Deliverables Every CISO Needs Before Their Management Body Signs Off on NIS2 Article 20
When a competent authority audits an essential entity’s Article 20 compliance, the first question is not directed at the CISO. It goes to the board. Article 20 of the NIS2 Directive (EU) 2022/2555 places three obligations on the management body — approval of cybersecurity measures, oversight of their implementation, and personal liability for infringements — and none of these can be delegated to a security team [1]. The CISO’s role under this framework is structural and specific: to prepare the evidence, documentation, and reporting that make meaningful management oversight possible. That is a different task from bearing the liability.
This guide covers the structural distinction between the CISO and the management body under NIS2, explains what non-delegable liability means in practice, and sets out the eight deliverables every CISO needs before the management body sign-off that Article 20 requires.
Where the CISO Sits in the NIS2 Governance Structure
NIS2 does not define the term management body. Article 20(1) uses it without specifying composition, seniority, remit, or reporting line — the definition is left to member states’ national legal frameworks [1]. In practice, nearly every EU member state has aligned the management body with the entity’s board of directors or, in two-tier structures common in Germany and Austria, the executive board [2]. This matters for one straightforward reason: the CISO is almost never a board member.
In most organisations, the CISO is an operational executive — responsible for running the cybersecurity function, reporting to the C-suite or to the board’s audit or risk committee, and implementing the measures that the management body approves. The CISO advises, prepares, and executes. The management body decides, approves, and is held accountable.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
This creates a structural distinction that Article 20 makes legally enforceable. Ireland’s William Fry summarises the governance provision precisely: there is little scope for directors to delegate these obligations given their fiduciary duties to mitigate risk [4]. The obligations that cannot be delegated are three: formal approval of cybersecurity risk-management measures under Article 21, active oversight of their implementation, and the personal liability that attaches to infringements of Article 21.
The practical consequence is that the person signing off on the cybersecurity programme must be a management body member — not the CISO, not a risk committee, not a technical team, even when the CISO leads all of the underlying work [2][4]. This is the single most commonly misunderstood element of Article 20 governance. For a detailed breakdown of what Article 20 requires from the management body directly, see our Article 20 management liability guide.
The Delegation Asymmetry — What the CISO Can and Cannot Own
Article 20(1) contains an asymmetry that shapes the entire CISO–management body relationship. Management bodies must approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements [1]. Every verb in that sentence — approve, oversee, be held liable — belongs to the management body. The Directive does not create an equivalent liability pathway for the CISO.
Operational execution is different. Managing the security operations function, running vulnerability assessments, negotiating supplier security clauses, responding to incidents — all of this can be, and typically is, assigned to the CISO and the security team. Germany’s national implementation through the BSIG (BSI Act) captures the principle: operational tasks may be assigned, but the overarching responsibility for key security-related decisions remains, in principle, with the management body [3].
Article 20(2) reinforces this asymmetry. Member states must ensure that management body members are required to follow training to gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices [1]. This requirement sits with the management body — not with the CISO — because the board cannot meaningfully approve measures it does not understand. The CISO arranging training is a support function. Management body completing and documenting that training is a compliance obligation.
The enforcement implication is direct. Where a competent authority identifies Article 21 infringements, it is management body members who face personal consequences. Article 32 of the Directive enables supervisory authorities, where enforcement measures against essential entities have failed, to seek a temporary prohibition on individuals at CEO or legal representative level from exercising managerial functions in the entity [5]. That power does not target the CISO. It targets the people Article 20 holds liable.
8 Audit-Facing Deliverables Every CISO Must Prepare
The CISO’s practical role under NIS2 Article 20 is to produce the evidence that makes genuine management oversight possible — and that survives an audit. National implementations, including Germany’s BSIG and the guidance of law firms advising on Article 20, converge on a consistent set of documented artefacts [3][4][6]. The eight below represent the deliverables that audit trails consistently examine. They are not exhaustive, but they cover the gaps that enforcement actions most frequently expose.
1. Art.21 Measure Approval Record
A policy document is not approved by existing. The management body must formally approve each Article 21 cybersecurity measure, and that approval must be documented with version number, approval date, and the name of the approving body or individual. A general cybersecurity noted agenda item in board minutes does not meet this threshold — auditors expect substantive documented consideration of specific measures [3][6]. In practice, this means a version-controlled policy register, each policy cross-referenced to the Article 21(2)(a)–(j) measure it addresses, with approval minutes or a signed board resolution for each version. When a policy is revised, the approval record follows the revision.
2. Residual Risk Acceptance Document
Article 21(1) requires cybersecurity measures to be proportionate to the risks. Commission Implementing Regulation (EU) 2024/2690 goes further for the entities it covers: the risk treatment process must include documented justification of residual risk accepted in a comprehensible manner, and documented management authority for that acceptance. This means the CISO’s risk register is not complete until a management body member has formally signed off on which residual risks the entity accepts and why. A risk register that stops at threat identification without a formal management acceptance record fails this test regardless of how thorough the underlying analysis is.
3. Management Body Training Evidence
Article 20(2) mandates training for management body members. Germany’s BSIG sets a minimum of every three years with detailed record-keeping requirements — organisations must retain records showing not just who attended training but the date, content, provider, and duration. Attendance certificates are explicitly insufficient [3]. The CISO’s role is to source or commission appropriate training and maintain the training log. The obligation to complete it sits with each management body member individually, which makes the tracking function essential.
4. Quarterly Cybersecurity Reporting Dashboard
The phrase oversee its implementation in Article 20(1) describes an active, ongoing obligation — not a one-time approval [1]. A single annual board presentation does not constitute oversight. Competent authorities expect evidence that the management body received and reviewed regular cybersecurity reporting on a cadence that allowed genuine decision-making [6][7]. In practice, quarterly board or audit committee reporting on cybersecurity posture, key risk indicators, and incident status represents the minimum pattern that satisfies this requirement. The CISO prepares this dashboard. The management body must demonstrably receive, review, and act on it — and those responses must be captured in board minutes.
5. Board Resolution on Cybersecurity Measures
Distinct from individual policy approvals, a board resolution captures the management body’s formal decision to adopt the overall cybersecurity programme — including the scope of Article 21 measures, the risk appetite applied, and the organisational structure for oversight. This document provides the foundational governance record: the point at which the management body first exercised its Article 20(1) approval function for the programme as a whole. On material programme updates — a significant service change, a post-incident restructure — a fresh resolution documents the management body’s re-engagement with the programme scope.
6. CISO-to-Management Escalation Protocol
Since the CISO operates at the delegatee level and the management body retains liability, there must be a documented protocol defining when and how the CISO escalates issues upward. Auditors examine whether a clear escalation pathway exists — including defined thresholds (what incident severity triggers mandatory management notification), named escalation contacts, and maximum response time expectations [7]. This document serves two purposes: it demonstrates to auditors that active oversight was structurally possible, and it demonstrates to the management body that the reporting line was followed if a failure occurred after proper escalation.
7. Post-Incident Management Review Record
Article 23 incident reporting places the notification obligation on the entity, but Article 20’s oversight obligation means management body members must demonstrably review significant incidents — not merely receive notification that one occurred. A post-incident management review record documents that the management body was briefed on the incident, reviewed the root cause analysis, and either approved or directed the corrective action plan. This record is distinct from the Article 23 notification itself and satisfies a separate oversight evidence requirement that auditors examine when assessing whether management body oversight was genuinely active.
8. Annual Art.21 Proportionality Review with Management Sign-Off
Article 21(1) establishes that measures must be proportionate to the risks facing the entity, taking into account the state of the art, implementation costs, and the likelihood and severity of incidents. This is not a static determination — it requires review as threats evolve, services change, and the entity’s risk profile shifts. An annual proportionality review, documented and signed off by the management body, demonstrates that oversight is ongoing rather than historical [3][4].
Germany’s BSIG explicitly requires organisations to demonstrate decisions, risk analyses, the implementation of measures, and their effectiveness in a comprehensible manner [3]. The annual review is the mechanism for that demonstration. Where risks change materially between scheduled reviews — a significant acquisition, a new service, a major incident — an interim review should be triggered and documented rather than deferred to the next annual cycle.
What Article 32 Enforcement Actually Looks Like for Management
When an essential entity fails to comply with Article 21 requirements, Article 32 determines what follows. The supervisory powers available to competent authorities include on-site inspections, targeted security audits, ad hoc audits following significant incidents, security scans, and demands for documentation and evidence of policy implementation [5]. These are exercised against the entity as a whole.
What changes the picture is the personal dimension. Article 32 enables supervisory authorities, where enforcement measures against essential entities have failed, to seek a temporary prohibition on individuals at CEO or legal representative level from exercising managerial functions in the entity [5]. This power does not apply to public administration entities. It flows directly from the Article 20(1) accountability provision and targets the management body members who hold the approval and oversight functions — not the CISO who implemented the controls.
The Article 34 fine maxima for Article 20 governance infringements follow the same structure as Article 21 violations: up to €10 million or 2% of global annual turnover for essential entities (whichever is higher), and up to €7 million or 1.4% for important entities [5]. Critically, Article 20 governance failures are independently enforceable. A competent authority can fine for the absence of proper approval documentation even when the underlying technical security controls are sound — the governance breach and the technical breach are separate enforcement vectors.
This means the 8 deliverables described above protect the management body from this exposure — but only if they demonstrate genuine oversight, not its appearance. Auditors examining Article 20 compliance look at whether board minutes contain substantive cybersecurity discussion, whether training records reflect real engagement over time, and whether the reporting dashboard was reviewed and acted on [3][6]. A policy binder assembled under audit pressure without evidence of ongoing management engagement fails the test even if the policies themselves are well-written.
Building a Governance-Ready CISO Function — The Annual Rhythm
The 8 deliverables above are most sustainable when structured into a repeating annual cycle rather than assembled reactively ahead of an audit. The following rhythm produces them as a natural output of an active governance function.
| Cadence | CISO activity | Deliverable produced |
|---|---|---|
| Monthly | Update cybersecurity KPIs, log incident escalations and management responses, flag policy review dates | Dashboard data, escalation log |
| Quarterly | Prepare and present Art.20 reporting dashboard; document management body receipt and any decisions made | Deliverable 4 (dashboard), board minutes |
| Annually | Conduct Art.21 proportionality review; update policy register; obtain fresh management sign-off; run management training session | Deliverables 1, 3, 5, 8 |
| Post-significant incident | Conduct management review of the incident; document root cause briefing and corrective action decisions | Deliverable 7 (post-incident review record) |
| On risk acceptance change | Present updated residual risk position for formal management sign-off | Deliverable 2 (residual risk acceptance) |
This rhythm means that when a competent authority requests evidence of Article 20 compliance, the documentation exists as a by-product of routine governance activity — not as a document created in response to the request.
In organisations without a formal CISO role, the same deliverables apply. Where the security function is led by an IT Director, Head of IT, or an outsourced MSSP security lead, the responsible party should be clearly named in the entity’s governance documentation with an explicit mandate covering preparation of materials for management body review. The Article 20 obligations do not disappear because the CISO title does not exist — and the management body’s liability does not diminish either.
Frequently Asked Questions
Is the CISO considered part of the management body under NIS2?
In most organisational structures, no. NIS2 does not define management body — member states align it with the board of directors or executive board under their company law. CISOs typically hold operational rather than board-level positions [2]. A CISO who is also a board director holds both roles simultaneously, but the Article 20 compliance obligations attach to their position as a board member, not as CISO. In that dual-role scenario, the same individual carries both the operational accountability of the CISO and the personal liability of a management body member.
Can the CISO be held personally liable under NIS2?
Article 20 places liability with the management body, not with the CISO. The enforcement mechanism that targets individual executives in Article 32 applies to the CEO or legal representative — again, management body functions, not the security leadership function [5]. National company law and employment law may create separate liability paths for negligent employees; NIS2 itself does not establish CISO personal liability under the Directive. The CISO’s exposure under NIS2 is reputational and professional, not direct regulatory liability under Article 20.
How often does management body training need to happen?
Article 20(2) requires training on a regular basis without specifying intervals [1]. Germany’s BSIG sets a minimum of every three years with detailed record-keeping [3]. The practical benchmark is sufficient frequency to maintain genuine capability to assess cybersecurity risks — a single one-time training session that becomes stale as the threat landscape evolves is unlikely to satisfy an active audit. Most practitioners recommend annual or biennial training, supplemented by targeted briefings when significant regulatory or threat developments occur.
What if no formal CISO role exists in the organisation?
The Article 20 governance obligations remain regardless of whether a CISO exists. Where the security function is distributed across IT leadership or managed externally, the organisation should document clearly in its governance structure who holds the mandate to prepare materials for management body review, at what seniority, and with what escalation authority. The management body’s responsibility to approve, oversee, and receive training is unchanged — as is its liability for infringements of Article 21 [1][4].
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- European Union. “Article 20 — Governance.” Directive (EU) 2022/2555 (NIS2 Directive). nis2resources.eu/directive-2022-2555-nis2/article-20/
- DLA Piper. “NIS2 Directive Explained: Part 2 — Management Bodies Rules.” November 2025. dlapiper.com
- Greenberg Traurig LLP. “NIS2 in Germany: The New BSI Act Makes Cybersecurity a Board-Level Issue.” December 2025. gtlaw.com
- William Fry. “NIS2: A Game-Changer for Senior Management and Boards.” williamfry.com
- European Union. “Article 32 — Supervisory and Enforcement Measures for Essential Entities.” Directive (EU) 2022/2555 (NIS2 Directive). nis-2-directive.com
- Policy Confirm. “NIS2 Article 20: Personal Liability and Evidence for Management.” policyconfirm.com
- Bastion. “NIS2 Management Liability: What Leaders Need to Know.” bastion.tech
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
