Glossary · NIS2

Management Body

The board of directors, executive committee, or equivalent governing body of an organisation.

Explained in depth: NIS2 penalties and management liability

NIS2 places obligations directly on the management body rather than on the organisation in the abstract. Under Article 20, the management body must approve the cybersecurity risk-management measures, oversee their implementation, and undergo cybersecurity training. Members can be held personally liable for the entity's infringements of Article 21. What constitutes the management body depends on corporate form and national law: for a Swedish aktiebolag it is typically the board of directors (styrelsen), and depending on national transposition, senior executives can also fall within scope. For essential entities, some national laws allow authorities to request a temporary prohibition on individuals exercising managerial functions.

Why it matters

Cybersecurity governance evidence now needs to exist at board level: approved policies, board minutes covering risk decisions, and training certificates for directors. "We delegated it to IT" is no longer a defence.

Used in

See also

← All glossary terms