NIS2 Programme Governance: All 12 Governance Actions Point at the Board — and the 4 a Steering Committee Can Never Carry
Article 20(1) of NIS2 is a single sentence, and it names exactly one body: the management body. It does not name a steering committee, a security council, a programme board or a CISO. Those are structures you invent to discharge a duty the directive parks somewhere else — and that gap is where most NIS2 programme governance quietly fails. A committee gets a plausible roster and a monthly slot, and nobody checks whether the decisions it takes are decisions it is permitted to take.
Ireland’s National Cyber Security Centre is one of the few competent authorities to publish the governance measure as a discrete, numbered list. Its draft risk-management guidance sets out twelve actions under RMM002 — and every one of them is addressed to the management board [3]. Read the verbs in that list and the design rule for your committee falls out of the text.
NIS2 names one accountable body — and it is not your steering committee
In plain terms: the board approves and oversees, everyone else prepares and executes, and no committee structure changes who carries the liability.
Article 20(1) requires Member States to ensure that “the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article” [1]. Three verbs, one owner. Article 20(2) adds a fourth duty that attaches to individuals rather than the entity: members of the management body “are required to follow training” [1].
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
What the directive never does is tell you who the management body is. DLA Piper’s analysis puts it bluntly: “NIS2 is notably vague about what constitutes a ‘management body’. There is no unified definition regarding its composition, seniority, remit, or position,” and the near-universal practice so far has been to align it with the existing board of directors or equivalent [5]. Our guide to what Article 20 actually requires your board to sign works through that identification question in detail.
The Irish NCSC’s board guidance borrows the cleanest available distinction from Belgium’s CyFun framework: “Governance is about setting strategy, oversight, risk appetite (board and executive level)” while “Management is about implementing policies, processes, and controls (operational level)” — and overlap exists because “some actions (e.g. policy approval, role assignment) are both governance-driven and management-executed” [4]. That overlap is the seam. A steering committee is the joint that holds those two layers together, which is precisely why its charter has to be explicit about which layer each decision belongs to.
One scope note before the detail. Article 20 binds every essential and important entity. Commission Implementing Regulation (EU) 2024/2690, which supplies the specific governance mechanics quoted throughout this article, is binding only on the eleven digital-infrastructure categories named in its Article 1 — DNS providers, TLD registries, cloud, data centre and CDN providers, managed service and managed security service providers, online marketplaces, search engines, social networking platforms and trust service providers [2]. For everyone else it is the most detailed benchmark available of what a supervisor considers adequate, not law. Our guide to the Implementing Regulation covers that scope boundary.
The verb test: the four governance acts a committee can never carry
Group the Irish NCSC’s twelve RMM002 actions by the verb the regulator chose, and they separate cleanly into two piles. Four are things the board does itself. Eight are things the board must ensure happen — which is a duty you can discharge through a structure.
| Regulator’s verb | RMM002 actions | Can a steering committee carry it? |
|---|---|---|
| Undertake (training) | FA01 — board training, documented and repeated | No. Article 20(2) attaches training to the individual members of the management body [1] |
| Approve | FA02 — the Article 21 measures; FA05 — the policy suite, security objectives and risk-acceptance criteria | No. Article 20(1) assigns approval to the management bodies; CIR point 1.1.1(k) requires the policy to carry the date of their formal approval [1][2] |
| Commit (resources) | FA03 — commit the resources to implement, operate and maintain the approved measures | No. CIR point 1.1.1(e) puts the resourcing commitment inside the policy document the board dates [2] |
| Ensure | FA04 (an effective governance structure is in place) plus SA01–SA07 — eight actions covering policy application, communication, risk recording, escalation of significant risks, implementation, progress review and continual improvement | Yes, in execution. The board still answers for the outcome, but “ensure” is a duty a standing body can discharge on its behalf |
The verb split is our reading of the NCSC’s wording, not a classification the NCSC publishes — and the guidance itself is draft, issued while Ireland’s transposing legislation was still pending. But it is a more defensible allocation rule than the alternative on offer, which is a committee roster copied from a consultancy deck. It also matches how the NCSC frames the foundation tier: Foundation Actions are “the minimum required to meet the legislative obligations of the Directive”, while Supporting Actions are “further controls [that] may be required, depending on specific risks” [3].
Stated as a design rule: a NIS2 steering committee is the machine that discharges eight “ensure” duties and delivers four decisions to the people who must personally make them. Every clause in its charter should serve one of those two jobs. Anything that serves neither is meeting overhead.
The RACI where the “A” column is already filled in
In an ordinary programme RACI you choose all four columns. In a NIS2 programme you choose three, because the regulation has pre-assigned accountability for a defined set of decisions. Design the other three columns freely; treat the “A” column as a lookup.
| Decision | Responsible | Accountable | Consulted | Source of the “A” |
|---|---|---|---|---|
| Approve the Article 21 measures | CISO drafts and presents | Management body | Legal, Finance | Art 20(1) [1] |
| Approve the policy suite and risk-acceptance criteria | CISO | Management body | Legal, Compliance | Art 20(1); CIR 1.1.1(k), 1.1.2 [1][2] |
| Commit programme resources | CISO with Finance | Management body | Finance, business units | CIR 1.1.1(e); RMM002.FA03 [2][3] |
| Accept a residual risk | Named risk owner | Management body or a delegated person with authority, conditional on reporting | CISO, Risk | CIR 2.1.1 [2] |
| Assign roles and authorities | CISO with HR | Management body (communicated to, and reviews) | Legal, HR | CIR 1.2.1, 1.2.6 [2] |
| Implement a control | IT / Operations owner | CISO | Architecture, business units | Freely delegable |
| Verify effectiveness | Internal Audit or an independent reviewer | Management body (receives the result) | CISO, Compliance | CIR 2.3.2, 2.3.3 [2] |
The most common defect in a NIS2 RACI is an “A” against the CISO for measure approval or risk acceptance. Put that in writing and your own governance document tells a supervisor the approval sat one level below where Article 20 puts it — a matrix built to demonstrate control becomes evidence of a control gap.
What makes the mistake feel safe is a genuine asymmetry in the CIR that almost every commentary flattens. Point 2.1.1 does allow residual risks to be “accepted by management bodies or, where applicable, by persons who are accountable and have the authority to manage risks, provided that the relevant entities ensure adequate reporting to the management bodies” [2]. Delegated risk acceptance is therefore a conditional permission with a reporting condition attached. Approval of the measures themselves, and of the policy that carries the approval date, carries no equivalent clause. The two duties are not interchangeable, and a charter that delegates both because it delegated one has over-read the text.
Two roles that get mis-assigned in practice. The DPO is a consulted party here, not a programme owner — as we set out in our analysis of why NIS2 does not assign DPO responsibility by default, the directive gives the role no standing under Article 21. And outsourcing operations to a managed provider moves execution only; the Article 20 liability travels with the entity, so an MSSP never appears in the “A” column.
The steering committee charter: six clauses that decide whether it works
Neither the directive nor the CIR prescribes a charter, so the clauses below are an implementation pattern rather than a legal requirement. Each one exists to close a failure the regulation would otherwise expose.
| Clause | What to write | Effort |
|---|---|---|
| 1. Membership | One member of the management body (the approver), the CISO or equivalent as the person who “reports directly to the management bodies” under CIR 1.2.3, Legal or Compliance, the IT/operations delivery lead, Finance, and a standing non-voting invitee from Internal Audit | Low |
| 2. Quorum | Approval-class items require the management-body member to be present; without them the item is discussion-only and rolls to the next meeting | Low |
| 3. Decision rights and thresholds | State what the committee settles itself and what it must escalate — residual risk above the board’s own acceptance criteria, any scope change touching entity classification, any deferral that leaves a known gap open | Medium |
| 4. Cadence | Your committee rhythm is yours to choose; two clocks are not. CIR 1.1.2 requires management-body review of the policy at least annually, and again after significant incidents or significant changes to operations or risks | Low |
| 5. Escalation trigger and response time | Define what forces an out-of-cycle item to the management body, and how quickly. RMM002.SA04 asks the board to ensure significant risks are presented to it, and attaches no meeting cycle to that | Medium |
| 6. Minute contents | For each decision: what was decided, which clause it satisfies, who approved it, the date, and any dissent | Medium |
Clause 2 is the one most charters get silently wrong. A committee whose quorum can be met without anyone holding approval authority will eventually approve something — and the minute will record an approval that Article 20 does not recognise. Tying quorum to decision class costs one sentence and removes the failure mode entirely.
Clause 4 deserves a calibration most templates skip. Monthly is a widely used convention, not a legal cadence; it earns its place because it is the shortest interval at which an overdue item still surfaces before an annual clock expires. Our board governance framework covers the oversight-model and minute-structure question at the board’s own level, and the NIS2 project plan shows where the committee sits against the delivery workstreams.
The independence rule most charters break
Put the verifier in the room, but never in the delivery line.
CIR point 2.3.2 is unusually specific for an annex written in outcome language. Independent reviews must be “carried out by individuals with appropriate audit competence”, and where the reviewer is a staff member, “the persons conducting the reviews shall not be in the line of authority of the personnel of the area under review” [2]. Point 1.2.5 reinforces it: “conflicting duties and conflicting areas of responsibility shall be segregated, where applicable” [2].
For committee design that has one hard consequence. Whoever holds the verification seat cannot own delivery of a workstream they will later review, which rules out the common shortcut of making the CISO both implementer and assurance provider. The Irish NCSC sets out a notional three-lines model behind this: business-unit managers are “responsible and accountable” for their own risks, Risk and Compliance provide “independent oversight and challenge”, and Internal Audit “provides independent assurance to the Board” while reporting directly to the chair of the audit committee [4].
Smaller entities are not exempt, but they are not trapped either. Where size makes separation of line of authority impossible, the CIR requires “alternative measures to guarantee the impartiality of the reviews” [2] — in practice an external reviewer, a peer review from an unrelated business unit, or a review commissioned directly by a management-body member. The obligation is impartiality, not headcount.
What each meeting has to leave behind
A steering committee that produces no artefacts has not discharged an “ensure” duty; it has held a conversation about one. The table below maps the recurring evidence to the clause that demands it.
| Artefact | Clause | Whose signature | When |
|---|---|---|---|
| Policy carrying a formal approval date | CIR 1.1.1(k) | Management body | At approval and after each review |
| Resource commitment written into that policy | CIR 1.1.1(e) | Management body | Same document, same date |
| Record of residual risks accepted | CIR 2.1.1 | Management body, or delegated authority plus report to the board | At each acceptance |
| Regular status report on security posture | CIR 2.2.1 | The person reporting directly to the board under 1.2.3 | Per charter cadence |
| Roles and authorities register, with review date | CIR 1.2.1, 1.2.6 | Management body | At planned intervals and after significant change |
| Independent review report and corrective actions | CIR 2.3.3, 2.3.4 | Reviewer, reported to management body | At planned intervals and after significant incidents |
| Board training records | Art 20(2); RMM002.FA01 | Individual board members | Documented and repeated as needed |
One clause changes what a “no” costs you. CIR Article 2(2) provides that where the Annex qualifies a requirement with “where appropriate”, “where applicable” or “to the extent feasible”, an entity that judges the requirement unsuitable must document the reasoning [2]. Proportionality is a real defence under Article 21(1), which requires measures “appropriate and proportionate” to the risk [1] — but for entities inside the CIR’s scope it is a defence that only exists in writing. A steering committee is the natural place to record it, because it is the only forum where the decision, the reasoning and the approver are in the same room.
What to do this quarter, by role
- CISO or programme lead: open your RACI and find every “A” that sits below the management body for approval, policy or resource decisions. Move them, and confirm you are formally named as the person who reports directly to the board under CIR 1.2.3.
- Compliance officer or Legal: add the quorum clause and the minute-content clause to the charter, then check the last six months of minutes for approvals recorded without an approver present.
- Management body member: ask the four strategic questions the Irish NCSC tells boards to ask and document the answers — whether cyber risk is formally acknowledged as strategic, what the risk appetite is, how security is embedded into procurement and technology decisions, and what resources are allocated [4]. Then confirm your Article 20(2) training is recorded.
- Internal Audit: confirm your seat is non-voting and that you own no workstream you will later review, then schedule the first independent review against CIR 2.3.4’s trigger conditions.
Frequently Asked Questions
Does NIS2 require a cybersecurity steering committee?
No. No provision of Directive (EU) 2022/2555 or Implementing Regulation 2024/2690 assigns cybersecurity duties to a steering committee — they run to the management bodies and to the entity itself. What the directive requires is that the management body approves the Article 21 measures and oversees implementation [1]. Ireland’s NCSC comes closest to an expectation with RMM002.FA04, which asks the management board to “ensure that an effective governance structure is in place” [3] — the structure is your design choice, the accountability is not.
Can the CISO approve the Article 21 measures on the board’s behalf?
No. Article 20(1) assigns approval to the management bodies, and CIR point 1.1.1(k) requires the policy to carry the date of their formal approval [1][2]. The CISO drafts, presents and implements. The narrow exception elsewhere in the CIR is residual-risk acceptance, which point 2.1.1 permits by a person with the relevant authority provided the entity ensures adequate reporting to the management bodies [2] — a different decision under a different clause.
How often should a NIS2 steering committee meet?
Neither instrument sets a committee cadence, so choose one and justify it. Two clocks are fixed for entities inside the CIR’s scope: management-body review of the policy at least annually, and a further review after significant incidents or significant changes to operations or risks (point 1.1.2), with independent reviews on the same trigger pattern under point 2.3.4 [2]. Monthly is a common working convention because it surfaces overdue items before those annual deadlines arrive. Our guide to NIS2 board reporting metrics covers what belongs in each cycle.
Can a group parent run one steering committee for all its subsidiaries?
It can run one committee, but not one approval. Each in-scope legal entity has its own management body carrying its own Article 20 duty, and DLA Piper notes that group structures tend to delegate cybersecurity decision-making to a central body “while retaining ultimate accountability” locally [5]. In practice that means a shared committee producing entity-specific approval records and minutes. Our guides to subsidiary compliance and large-enterprise group structures work through the entity boundary; groups documenting several entities in parallel can license the full template library for up to five legal entities under the enterprise compliance licence.
What happens if the committee approves something outside its authority?
In practice the decision is not void, but it does not by itself discharge the Article 20 obligation — and the minute recording it evidences an approval taken at the wrong level. The fix is procedural rather than dramatic: re-table the item at the next management-body meeting, approve it properly, and date the record. Our analysis of Article 20 personal liability mechanics covers the exposure that follows a missing approval trail.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Directive (EU) 2022/2555 (NIS2), Articles 20 and 21 — official consolidated text on EUR-Lex.
- Commission Implementing Regulation (EU) 2024/2690, Article 2 and Annex points 1.1.1, 1.1.2, 1.2, 2.1.1, 2.2.1 and 2.3 — official text on EUR-Lex.
- National Cyber Security Centre (Ireland), Draft Risk Management Measures Guidance, RMM002 — Governance: Management board commitment and accountability (draft guidance).
- National Cyber Security Centre (Ireland), Guidance on Cyber Governance for Management Board Members in NIS2 entities, sections 3.1 to 3.2 and Annex III.
- DLA Piper, "NIS2 directive explained: Part 2 — Management bodies rules" (dlapiper.com).
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
