Glossary · NIS2
Article 20
The NIS2 provision requiring management bodies to approve, oversee, and be trained on cybersecurity risk measures.
Explained in depth: NIS2 penalties and management liability
Article 20 makes cybersecurity a board-level responsibility. Management bodies of essential and important entities must approve the cybersecurity risk-management measures the organisation takes under Article 21, oversee their implementation, and can be held liable for infringements. Members of management bodies are also required to follow cybersecurity training, and entities are encouraged to offer similar training to all employees on a regular basis. This is one of the most consequential changes from the original NIS Directive: accountability can no longer be delegated entirely to the IT department or the CISO. National transposition laws define what liability looks like in practice, and in some member states this includes temporary bans on exercising managerial functions for essential entities.
Why it matters
Boards that treat NIS2 as an IT project expose themselves personally. Documented board approval of the risk-management measures, meeting minutes, and completed training records are among the first things a competent authority will ask for.
