← Back to the cybersecurity blog

NIS2 and the board: the accountability directors cannot delegate

By Adrián González · CEO · Published: 22 July 2026 · Updated: 22 July 2026
NIS2 and the board: the accountability directors

The NIS2 Directive moves part of the responsibility for cybersecurity onto the management body, and it does so personally. Article 20 requires the board to approve the risk management measures, oversee their implementation and be capable of being held liable for infringements. For essential entities, Article 32(5)(b) goes further: it lets a competent authority ask a court to temporarily bar a chief executive or legal representative from exercising managerial functions until the deficiencies are remedied.

This is not a rhetorical threat. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose NIS2, with a request for fines. Supervisory machinery is already activating in the countries that did transpose. This article is not about technical controls. It is about what a board must do, approve and document so that this accountability does not turn into a personal sanction.

At a glance

  • NIS2 makes the management body accountable for three specific things: approving the measures, overseeing implementation, and answering for infringements (Article 20(1)).
  • The accountability is personal and educational: board members are required to undergo dedicated training (Article 20(2)).
  • A temporary management ban exists for essential entities (Article 32(5)(b)); it does not apply to important entities.
  • Fines reach EUR 10 million or 2% of worldwide turnover for essential entities, and EUR 7 million or 1.4% for important ones (Article 34).
  • A board does not evidence compliance with an approval minute — it evidences it with continuous oversight and dated proof.

From delegation to accountability

For years, cybersecurity was something the board delegated to the IT function and reviewed, if at all, only when an incident occurred. NIS2 breaks that pattern. Article 20 rests on a principle that is easy to state and demanding to satisfy: operational execution can be delegated, governance responsibility cannot.

The practical consequence is that a board cannot confine itself to signing a policy once a year. Article 20(1) assigns three duties that operate continuously: approving the risk management measures with enough understanding to decide on risk appetite and resource allocation; overseeing implementation through regular, meaningful reporting; and accepting that it will answer for infringements if it fails to exercise that oversight.

That structure connects to Article 21, which defines the substance: an all-hazards approach with ten minimum categories of measures, from risk analysis and incident handling to supply chain security, cryptography and multi-factor authentication. Article 21 is not a technical checklist but a standard of care — an organisation can suffer a sophisticated incident and remain compliant if it can show that governance, risk analysis and appropriate measures were in place beforehand. What is judged is the quality of governance, not the isolated existence of controls.

What “director accountability” actually means

It helps to separate three distinct consequences that often get merged into a single boardroom conversation, because their scope and their targets are not the same.

Fines on the entity

Article 34 sets the ceilings. For essential entities, fines of a maximum of at least EUR 10 million or 2% of total worldwide turnover for the preceding financial year, whichever is higher. For important entities, EUR 7 million or 1.4%. The regime deliberately mirrors the GDPR logic of a percentage of turnover, and pursues the same deterrent effect.

Temporary ban on directors

This is the measure that most deserves a board's attention, and the most misread. Article 32(5)(b) applies only to essential entities, not important ones, and it is not automatic. It operates as a last resort: the authority first issues binding instructions and sets a deadline; only if that deadline is missed can it ask a court to temporarily bar a chief executive or legal representative from managerial functions. The ban lasts until the deficiencies are remedied and is subject to procedural safeguards. It is not a criminal penalty — it is a coercive measure to force remediation.

Personal liability for breach of duty

Article 32(6) allows the natural person representing an essential entity to be held liable for failing in their duty to ensure compliance. This does not replace national regimes governing directors' liability; it adds to them. A director who already answers for the duty of care under company law now faces a specific, verifiable duty in cybersecurity.

The question a board must be able to answer is not “do we have a SOC?” but “can we demonstrate, with minutes and dated evidence, that we approved, oversaw and reviewed the measures before anything happened?”

The oversight duty, translated into practice

The part of Article 20 that causes the most discomfort is not approval, it is oversight. Approval is settled with a minute. Oversight demands a living mechanism. In operational terms, a board wanting to evidence effective oversight needs several elements in place.

  • A dashboard with indicators the board understands and can challenge: external exposure, time to remediate critical vulnerabilities, backup coverage with tested restoration, incidents and how they were handled. The logic of a board-level cyber resilience dashboard is exactly this.
  • A defined, recorded reporting cadence — not ad hoc meetings when something goes wrong. The frequency and content of reporting are themselves evidence of oversight.
  • An escalation procedure that brings material deficiencies and audit findings to the board, with a documented decision on prioritisation and remediation.
  • Independent assurance: internal audit, external assessments or red team exercises that let the board test what executive management tells it.

That last point deserves emphasis. The value of a penetration exercise or an independent audit to the board is not only technical: it is a source of assurance that does not depend on the team that built the controls grading its own work. Without independent assurance, board oversight rests solely on the word of those doing the execution.

Board training is a requirement, not a recommendation

Article 20(2) requires members of the management body to undergo training that lets them identify risks and assess risk management practices. It is one of the few NIS2 requirements evidenced by a single document — an attendance and content record — and one almost no organisation has ready.

The aim is not to turn a director into a technician. It is to let them exercise informed judgement: to understand the implications of a risk decision, challenge executive management where appropriate, and integrate cyber risk into overall governance. After Article 20, not knowing stops being an excuse and becomes, in itself, a governance failing.

Why this binds already, even without a national law

Several member states have not yet published their implementing law. It would be a mistake to conclude that the board's duties do not exist yet. They arrive through two channels that do not wait for the national legislator.

The first is contractual. An essential entity in a transposed country passes down to its suppliers, by contract, requirements that reproduce NIS2 — including the demand for demonstrable security governance. The supplier's board inherits those duties even where the legal basis is a contract rather than a statute. That is where third-party risk management becomes the first real point of contact with NIS2.

The second is the European supervisory calendar itself. Germany, which transposed, set registration with its authority for 6 March 2026; by the end of May roughly 18,500 of approximately 29,000 in-scope entities had registered, per BSI figures. When a national law publishes, the registration window will be short and the board will have to demonstrate governance from day one, not start building it.

What a board can approve and document today

Everything resting on Article 21, which is already published and is not drafted by the national legislator, is stable work. A board can formally record the following without waiting for the definitive text.

  1. Formal approval, minuted, of the cybersecurity risk management framework, with express reference to the Article 21 categories and the risk appetite adopted.
  2. Documented determination of whether the organisation is an essential entity, an important entity or neither, with the reasoning by sector and size. When the law arrives you revise it; you do not start over.
  3. A management body training plan with an attendance and content record.
  4. Definition of the cadence and content of security reporting to the board, and of the escalation procedure for material deficiencies.
  5. A standing engagement for periodic independent assurance: audit, external assessment or red team exercise, with conclusions raised to the board.

Consolidating with frameworks the organisation already holds — a well-implemented ISO 27001 covers a good share of Article 21 — avoids duplicating effort. It is where a compliance platform such as NormexAI reduces the work of keeping evidence live and traceable. In financial services, the same governance logic connects to the digital operational resilience that DORA requires.

Where a security provider fits, and where it does not

It is worth being honest about the split. A managed SOC with adequate retention, a rehearsed incident response procedure and red team exercises resolve the executable part of the Article 21 measures and give the board the independent assurance it needs to oversee with judgement.

What no provider can take on is the governance duty. Approving the framework, adopting the risk appetite, training the board and bearing the Article 20 accountability are non-transferable. Any consultancy suggesting that buying a service “puts you in compliance” with NIS2 is describing the law wrongly: services generate the evidence, but governance is exercised by the board. That distinction, properly understood, is what separates a file that survives an inspection from one that collapses at the first question about oversight.

In short

NIS2 turns cybersecurity into a board matter, with names attached. The sanctioning regime — Article 34 fines, the Article 32(5)(b) temporary ban for essential entities — exists to force the Article 20 accountability to be genuinely exercised. The encouraging part is that almost everything protecting the board can be built today, regardless of when a national law publishes: approve with understanding, oversee with evidence, train, and test through independent assurance. A board that can demonstrate those four things sits in a very different position from one that can only produce a service invoice.

You can find more detail on scope and obligations on our NIS2 page and in our analysis of cyber crisis communication in the first 24 hours, where the board's role is again decisive.

Frequently asked questions

What exactly does NIS2 require of the board of directors?

Article 20(1) of the Directive imposes three duties on the management body of essential and important entities: to approve the cybersecurity risk management measures, oversee their implementation, and answer for infringements. Article 20(2) adds a duty for board members to undergo dedicated training. It is not a delegable duty: operational execution can be delegated, but governance responsibility cannot.

Can a director be personally banned for NIS2 non-compliance?

For essential entities, yes, but as a last resort and temporarily. Article 32(5)(b) allows that, if the entity fails to remedy deficiencies within the deadline set after binding instructions, the authority may ask a court to temporarily bar a chief executive or legal representative from managerial functions until they are remedied. It does not apply to important entities or to public administration entities, and it is subject to procedural safeguards.

What are the maximum fines under NIS2?

Article 34 sets, for essential entities, fines of a maximum of at least EUR 10 million or 2% of total worldwide turnover for the preceding financial year, whichever is higher. For important entities, the maximum is EUR 7 million or 1.4% of worldwide turnover. Fines are imposed in addition to other enforcement measures, not instead of them.

How do essential and important entities differ for liability?

Both categories are subject to the Article 20 governance duty and the Article 34 fine regime, though with different ceilings. The relevant difference for directors sits in the enforcement measures: the temporary management ban in Article 32(5)(b) is provided only for essential entities. Important entities fall under Article 33, which does not include that measure and operates through reactive supervision.

Is approving a security policy enough to satisfy Article 20?

No. Approval is only one of the three duties, and the easiest to evidence. Article 20 also demands continuous oversight, which is not shown by a single minute but by a living mechanism: a dashboard with indicators the board understands, a defined reporting cadence, documented escalation of deficiencies, and independent assurance. Approving without overseeing leaves the board exposed.

Do these board duties apply where the national law is unpublished?

Formally, an untransposed directive does not create obligations directly enforceable by a national authority. In practice, the duties arrive through contracts with customers in transposed countries, who pass down requirements that reproduce NIS2, including demonstrable security governance. In addition, when the law publishes the registration window will be short and the board will have to evidence governance from day one.

What training does the board need under NIS2?

Article 20(2) requires members of the management body to undergo training that lets them identify risks and assess risk management practices and their impact on services. The aim is not to turn a director into a technician, but to enable informed judgement and the ability to challenge executive management. It is evidenced by an attendance and content record, so it is worth planning and documenting deliberately.

Can a SOC or managed provider put the board in compliance?

Not on its own. A managed SOC, incident response and red team exercises resolve the executable part of the Article 21 measures and give the board independent assurance. But approving the framework, setting the risk appetite, training and the Article 20 accountability are non-transferable. Services generate the evidence; governance is exercised by the board.