NIS2 Legal Obligations: The Privilege Trap Compliance Counsel Must Avoid When Documenting Article 20 and 21 Compliance
Most NIS2 compliance guidance is written for the CISO or the board. It tells them what Article 21 requires and what Article 20 exposes them to. It rarely stops to ask the three questions in-house legal actually needs answered: does the risk assessment I just told the CISO to write down become a weapon against us in an inspection? Does Article 20’s liability language reach me, personally, as the person who signed off on the compliance programme? And at what point does this stop being something I can handle from my own desk?
This guide answers those three questions directly. It does not re-walk the full Article 20 approve-oversee-liable mechanic or the Article 32/33 enforcement powers menu in detail — both are covered thoroughly elsewhere on this site, and are linked below. Instead, it starts where those guides stop: at the point where a compliance document becomes evidence, and where evidence becomes a legal risk that needs a specific person to own it.
This article provides general information only and does not constitute legal advice. NIS2 implementation, professional secrecy rules, and privilege doctrine vary by member state and profession — always verify requirements against your national transposition law, your national bar rules, and applicable competent authority guidance.
Who This Applies To: Scope at a Glance for Legal Counsel
Article 20 and the privilege questions below apply once your organisation is in scope as an essential or important entity under NIS2 Annexes I and II. If scope hasn’t been confirmed yet, that determination comes first — everything in this article assumes it has been.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
| Entity type | Art. 20 governance duties | Supervisory posture | Max fine (Art. 34) |
|---|---|---|---|
| Essential entities (Annex I) | Approve, oversee, liable | Ex ante (Art. 32) — proactive, no trigger needed | €10M or 2% global turnover, whichever higher |
| Important entities (Annex II) | Approve, oversee, liable | Ex post (Art. 33) — reactive, evidence-triggered | €7M or 1.4% global turnover, whichever higher |
| Public administration bodies | Training duty applies; entity liability applies | Per national transposition | Per national transposition |
Note: Supervisory posture and fine ceilings are set at directive level under Articles 32–34 of Directive (EU) 2022/2555 [1][3][4][5]; national transposition laws implement these with member-state-specific procedure. Confirm the exact regime with your national competent authority.
The Article 20 Liability Chain — Where It Starts
Article 20(1) requires management bodies of essential and important entities to approve the cybersecurity risk-management measures adopted under Article 21, oversee their implementation, and accept that they “can be held liable for infringements” of that article [1]. Article 20(2) adds a non-delegable training duty for management body members personally [1]. Three verbs — approve, oversee, be liable — and none of them is satisfied by a single annual sign-off; regulators expect documented, dated, recurring evidence of active board engagement, not a policy binder nobody has opened since it was approved.
What counts as a “management body” and how far its liability actually extends — to a sole director, to non-executive board members, to a group parent’s subsidiary boards — is covered in detail in our Article 20 management liability guide, and the CEO-specific non-delegation question in CEO responsibilities under NIS2. Our legal counsel’s action guide covers a companion set of operational duties — the Article 21(2)(d) contractual cascade into supplier agreements, Article 26 jurisdiction determination, and coordinating parallel GDPR/NIS2 notification clocks. None of those three guides addresses what happens once a document exists: whether it can be withheld from an inspector, and who should have created it in the first place. That is where this guide starts.
Where the Chain Stops: Does Article 20 Reach General Counsel Personally?
Directly: usually not, and it’s worth being precise about why. Article 20(1) attaches liability to the “management body” — the board of directors or equivalent governance structure — not to advisors who brief it [1]. An in-house General Counsel who is not a formal board member sits outside that definition in most member-state transpositions, in the same way the CISO does. Ireland’s implementing approach, among the more detailed available, frames the management body as the group “vested with the authority and responsibility for oversight, direction and control” — a description built around decision-making authority, not advisory function.
That said, three scenarios narrow the gap between advising the board and standing inside Article 20’s reach:
General Counsel who also holds a board seat. Where GC sits on the board as an executive director — common in smaller essential/important entities — Article 20 liability attaches in that capacity, indistinguishable from any other director’s exposure.
Secondary and professional-negligence exposure. Article 20 doesn’t need to name counsel directly for counsel to face consequences. A director sanctioned under Article 32(5) for an unapproved compliance programme has a natural next question: who advised that the programme was adequate? That question can surface as a professional negligence claim against in-house or external counsel, running on ordinary civil liability principles rather than NIS2 itself.
Jurisdictions still finalising transposition. Some national implementing laws leave “management body” deliberately undefined, and a handful extend duties to “persons discharging managerial responsibilities” more broadly than the EU text strictly requires. Confirm the exact wording in your jurisdiction — this is precisely the kind of detail generic EU-level commentary glosses over and national counsel should confirm directly.
The practical takeaway: General Counsel’s exposure under Article 20 is usually indirect — professional and reputational rather than statutory — which is exactly why the documentation questions in the next three sections matter more to counsel than the liability chain itself.
Enforcement Mechanics: What an NCA Investigation Actually Looks Like
The distinction that matters procedurally isn’t how large the fine could be — it’s how the file gets opened. Essential entities face Article 32’s ex ante supervision: on-site inspections, off-site checks, security audits, and information requests that a competent authority can initiate without any triggering incident or complaint [3]. Important entities sit under Article 33’s ex post regime instead — the same inspection and audit toolkit, but action only follows “evidence, indication or information” of a suspected infringement [4]. That single distinction changes counsel’s posture entirely: for an essential entity, the file can already be open before anything has gone wrong; for an important entity, something — an incident, a complaint, a tip from another authority — already triggered it, which means there is already a known fact pattern to manage before the first information request lands.
Germany’s BSI illustrates the same split in practice: entities classified as “particularly important” face direct, proactive supervision and inspections without cause, while “important” entities are engaged only once indications of a violation exist [6]. Once a file opens, both regimes converge on the same escalation ladder: information requests and document access first, then on-site inspection or audit, then binding instructions with a remediation deadline, then — if unresolved — public disclosure orders, managerial-function suspension, or fines under Article 34 [3][4]. Essential entities face fines up to €10M or 2% of global turnover; important entities up to €7M or 1.4%, whichever figure is higher in each case, with the amount shaped by the specific circumstances of the case rather than a fixed tariff [5].
The operational point for counsel: the information-request stage is where the file gets built, and it arrives well before any fine is on the table. What gets produced at that stage — and how it was created — determines almost everything that follows. That is the question the rest of this article is about.
The Privilege Question: Is Your Article 21 Risk Assessment Discoverable?
Start with what NIS2 itself says, which is nothing. Neither Article 32 nor Article 33 carves out any exception for legally privileged material when listing a competent authority’s power to “access data, documents and information necessary to carry out their supervisory tasks” [3][4]. The directive was not drafted with privilege in mind — it was drafted to guarantee inspectors can see the real state of your security programme. That has a direct consequence: documents Article 21 exists to produce — the risk analysis, the incident log, the effectiveness assessment — are not privileged simply because a compliance team wrote them. They were created to demonstrate compliance, and an inspector is entitled to read them for exactly that purpose.
The harder question is what happens to material adjacent to that record — a candid gap analysis your team commissioned, an internal memo flagging that a control doesn’t actually meet the Article 21(2) standard, or post-incident legal exposure analysis. Here the closest developed body of law is EU legal professional privilege doctrine, and it points somewhere specific. Since AM&S Europe v Commission (1982), EU-level privilege has required that a communication serve the client’s rights of defence and come from a lawyer who is “independent” — explicitly, one “not bound to the client by a relationship of employment” [7]. The European Court of Justice applied that test directly to in-house counsel in Akzo Nobel v Commission (2010), holding that an employed lawyer’s communications are not privileged in EU Commission investigations, because the employment relationship itself compromises the independence the doctrine requires [7][8]. That exclusion of in-house counsel has not been disturbed since.
Here is the nuance that matters for NIS2 specifically, and that generic privilege commentary misses: that entire line of case law governs European Commission investigations under EU competition law. Where an investigation is run by a national authority under national law — which describes every NIS2 supervisory action, since NCAs like BSI, ANSSI, or your national equivalent act under domestic transposition law, not EU Commission competition powers — national privilege and professional-secrecy rules apply instead, and those vary sharply by member state [7]. Some jurisdictions extend a form of confidentiality to registered in-house counsel domestically even though EU Commission investigations would not recognise it; others track the EU position closely. The one point that survives across every version of this doctrine: privilege protection is strongest, and most reliably recognised, for documents created for the specific purpose of seeking independent external legal advice — not for material generated as part of the ordinary operational compliance record [7][8].
The Two-Track Documentation Model
The practical framework that follows from this is a separation most compliance programmes never make explicit: keep your statutory compliance record and your legal risk analysis on two distinct tracks, created differently and stored differently, because they serve different purposes and carry different exposure.
| Track 1 — Compliance evidence | Track 2 — Legal risk analysis | |
|---|---|---|
| Purpose | Demonstrates Article 20/21 compliance | Assesses gaps, exposure, and strategy |
| Examples | Risk assessment register, board resolutions, incident logs, audit checklists | Gap-analysis memo flagging a control shortfall, incident root-cause legal exposure note, D&O coverage analysis |
| Who should create it | Compliance/security team, with board sign-off | Requested by and addressed to counsel specifically, for the purpose of legal advice |
| Privilege posture | Not privileged — and shouldn’t be treated as such; it exists to be inspected | Best-supported privilege claim when created for and by independent legal advice, kept separate from the operational file |
| Where it should live | Standard compliance repository, referenced in board minutes | Marked as privileged/confidential at creation, circulated on a need-to-know basis, not folded into the general compliance folder |
The mistake this framework is designed to prevent is a common one: labelling a document “privileged and confidential” after the fact does not create privilege, and burying a candid legal risk assessment inside the same shared drive as the Article 21 risk register does not protect it — it just makes the privileged document easier for an inspector to find sitting next to the ones they’re entitled to see anyway.
In-House or External? A Decision Framework for Engaging Outside Counsel
In-house counsel knows the organisation’s risk tolerance, existing vendor relationships, and internal politics better than anyone external ever will — and for the routine work of running a compliance programme, that knowledge is the more valuable asset. The calculation changes at specific, identifiable trigger points, not as a general matter of seniority or budget.
| Trigger | Why it shifts the calculus |
|---|---|
| An NCA information request or inspection notice has arrived | The file is open; responses become part of the supervisory record, and privilege posture for anything created from this point forward is under scrutiny |
| An incident meets the Article 23 significance threshold | The 24-hour early warning, 72-hour notification, and one-month final report sequence creates a fast-moving evidentiary trail counsel should be shaping from the first hour, not reviewing after the fact |
| A gap analysis will identify a genuine, undisclosed non-compliance | This is the document with the strongest case for privilege protection — and the weakest case for it if drafted by the same in-house team that owns the compliance programme |
| The question spans multiple group entities or jurisdictions | Each subsidiary may be its own essential or important entity under a different national transposition; scoping this correctly is rarely a one-jurisdiction exercise |
| A director is facing personal exposure (Art. 32(5) suspension risk, D&O coverage dispute) | Individual and entity interests can diverge quickly once personal liability is on the table, which is a conflict in-house counsel is not well positioned to manage alone |
None of this means outside counsel should run the compliance programme day to day — that would be neither efficient nor necessary. It means the trigger points above are exactly the moments where routing the specific piece of work through independent external counsel, rather than the in-house team, is what gives a later privilege claim its best chance of holding up, for the reasons the previous section set out.
Compliance Counsel’s Action Checklist
- Confirm scope status is current. Essential/important classification determines whether you sit under Article 32 (ex ante) or Article 33 (ex post) supervision — see the NIS2 scope test if this hasn’t been revisited recently.
- Separate the two documentation tracks now, not during an inspection. Retrofitting privilege claims onto an existing shared compliance folder rarely holds up.
- Confirm who, specifically, sits inside your local “management body” definition — and whether GC is a member of it or purely an advisor.
- Pre-identify external counsel before you need them. An engagement negotiated calmly, before an inspection notice arrives, moves faster and preserves privilege more reliably than one arranged under deadline pressure.
- Confirm your national competent authority’s specific inspection procedure — timelines, appeal rights, and the right to be heard vary by member state even though the Article 32–34 framework is EU-wide.
- Brief the board on its own evidence gap, not just the security programme’s — Article 20 approval and oversight need their own documented trail, distinct from the CISO’s technical file.
Frequently Asked Questions
Does attorney-client privilege automatically protect our NIS2 compliance documents?
No. Neither Article 32 nor Article 33 recognises a privilege exception, and documents created to demonstrate Article 21 compliance are not privileged simply because they were prepared by or reviewed by counsel [3][4]. Privilege attaches to communications made for the purpose of seeking independent legal advice — not to the underlying compliance record.
Is in-house counsel’s advice ever privileged in an NIS2 investigation?
This depends entirely on national law, since NIS2 supervisory actions are run by national competent authorities, not the European Commission. The EU-level doctrine excluding in-house counsel (Akzo Nobel, 2010) applies specifically to Commission competition investigations [7][8]; it does not automatically extend to or exclude NIS2 supervisory files. Confirm the position under your specific national procedural and professional-secrecy rules.
Can General Counsel be held personally liable under Article 20?
Only if GC is formally a member of the management body (for example, an executive director). Where GC is purely an advisor, exposure is more likely to arise indirectly — through professional negligence claims following a director’s sanction — than directly under Article 20 itself [1].
What’s the difference between ex ante and ex post supervision?
Ex ante (Article 32, essential entities) allows a competent authority to inspect or audit without any triggering incident. Ex post (Article 33, important entities) requires evidence or indication of a suspected infringement before supervisory action begins [3][4].
When should we bring in outside counsel rather than handling something internally?
The clearest triggers are: an inspection notice has arrived, an incident meets the Article 23 significance threshold, a gap analysis is likely to surface genuine undisclosed non-compliance, the matter spans multiple jurisdictions, or an individual director faces personal exposure.
Where This Leaves Compliance Counsel
The Article 20 liability chain, the Article 32/33 enforcement toolkit, and the Article 34 fine ceilings are all well documented elsewhere. What’s less discussed — and what actually shapes counsel’s day-to-day judgment calls — is that the compliance record NIS2 requires you to keep is, by design, not protected, while the legal risk analysis sitting next to it might be, if it was created the right way, by the right person, and kept on its own track from the start. Getting that separation right before an inspection notice arrives is the single highest-leverage thing compliance counsel can do that no board template or penalty table addresses directly.
For legal teams coordinating this across more than one group entity or jurisdiction, the Enterprise Compliance License extends the Complete Toolkit’s evidentiary templates across up to five legal entities under a single licence — worth a scoping conversation if your compliance documentation currently has to be rebuilt, rather than reused, across subsidiaries.
Sources
- Directive (EU) 2022/2555, Article 20 — Governance
- Directive (EU) 2022/2555, Article 21 — Cybersecurity risk-management measures
- Directive (EU) 2022/2555, Article 32 — Supervisory and enforcement measures for essential entities
- Directive (EU) 2022/2555, Article 33 — Supervisory and enforcement measures for important entities
- Directive (EU) 2022/2555, Article 34 — Administrative fines
- BSI (Germany) — NIS-2-Pflichten (national competent authority obligations and supervisory procedure)
- WilmerHale — No Legal Privilege in EU Competition Law Investigations for In-House Lawyers: The ECJ’s Akzo Nobel Judgment
- Baker McKenzie — Global Attorney-Client Privilege Guide: European Union Competition Investigations
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
