The NIS2 Directive moves part of the responsibility for cybersecurity onto the management body, and it does so personally. Article 20 requires the board to approve the risk management measures, oversee their implementation and be capable of being held liable for infringements. For essential entities, Article 32(5)(b) goes further: it lets a competent authority ask a court to temporarily bar a chief executive or legal representative from exercising managerial functions until the deficiencies are remedied.
This is not a rhetorical threat. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose NIS2, with a request for fines. Supervisory machinery is already activating in the countries that did transpose. This article is not about technical controls. It is about what a board must do, approve and document so that this accountability does not turn into a personal sanction.
At a glance
- NIS2 makes the management body accountable for three specific things: approving the measures, overseeing implementation, and answering for infringements (Article 20(1)).
- The accountability is personal and educational: board members are required to undergo dedicated training (Article 20(2)).
- A temporary management ban exists for essential entities (Article 32(5)(b)); it does not apply to important entities.
- Fines reach EUR 10 million or 2% of worldwide turnover for essential entities, and EUR 7 million or 1.4% for important ones (Article 34).
- A board does not evidence compliance with an approval minute — it evidences it with continuous oversight and dated proof.
From delegation to accountability
For years, cybersecurity was something the board delegated to the IT function and reviewed, if at all, only when an incident occurred. NIS2 breaks that pattern. Article 20 rests on a principle that is easy to state and demanding to satisfy: operational execution can be delegated, governance responsibility cannot.
The practical consequence is that a board cannot confine itself to signing a policy once a year. Article 20(1) assigns three duties that operate continuously: approving the risk management measures with enough understanding to decide on risk appetite and resource allocation; overseeing implementation through regular, meaningful reporting; and accepting that it will answer for infringements if it fails to exercise that oversight.
That structure connects to Article 21, which defines the substance: an all-hazards approach with ten minimum categories of measures, from risk analysis and incident handling to supply chain security, cryptography and multi-factor authentication. Article 21 is not a technical checklist but a standard of care — an organisation can suffer a sophisticated incident and remain compliant if it can show that governance, risk analysis and appropriate measures were in place beforehand. What is judged is the quality of governance, not the isolated existence of controls.
What “director accountability” actually means
It helps to separate three distinct consequences that often get merged into a single boardroom conversation, because their scope and their targets are not the same.
Fines on the entity
Article 34 sets the ceilings. For essential entities, fines of a maximum of at least EUR 10 million or 2% of total worldwide turnover for the preceding financial year, whichever is higher. For important entities, EUR 7 million or 1.4%. The regime deliberately mirrors the GDPR logic of a percentage of turnover, and pursues the same deterrent effect.
Temporary ban on directors
This is the measure that most deserves a board's attention, and the most misread. Article 32(5)(b) applies only to essential entities, not important ones, and it is not automatic. It operates as a last resort: the authority first issues binding instructions and sets a deadline; only if that deadline is missed can it ask a court to temporarily bar a chief executive or legal representative from managerial functions. The ban lasts until the deficiencies are remedied and is subject to procedural safeguards. It is not a criminal penalty — it is a coercive measure to force remediation.
Personal liability for breach of duty
Article 32(6) allows the natural person representing an essential entity to be held liable for failing in their duty to ensure compliance. This does not replace national regimes governing directors' liability; it adds to them. A director who already answers for the duty of care under company law now faces a specific, verifiable duty in cybersecurity.
The question a board must be able to answer is not “do we have a SOC?” but “can we demonstrate, with minutes and dated evidence, that we approved, oversaw and reviewed the measures before anything happened?”
The oversight duty, translated into practice
The part of Article 20 that causes the most discomfort is not approval, it is oversight. Approval is settled with a minute. Oversight demands a living mechanism. In operational terms, a board wanting to evidence effective oversight needs several elements in place.
- A dashboard with indicators the board understands and can challenge: external exposure, time to remediate critical vulnerabilities, backup coverage with tested restoration, incidents and how they were handled. The logic of a board-level cyber resilience dashboard is exactly this.
- A defined, recorded reporting cadence — not ad hoc meetings when something goes wrong. The frequency and content of reporting are themselves evidence of oversight.
- An escalation procedure that brings material deficiencies and audit findings to the board, with a documented decision on prioritisation and remediation.
- Independent assurance: internal audit, external assessments or red team exercises that let the board test what executive management tells it.
That last point deserves emphasis. The value of a penetration exercise or an independent audit to the board is not only technical: it is a source of assurance that does not depend on the team that built the controls grading its own work. Without independent assurance, board oversight rests solely on the word of those doing the execution.
Board training is a requirement, not a recommendation
Article 20(2) requires members of the management body to undergo training that lets them identify risks and assess risk management practices. It is one of the few NIS2 requirements evidenced by a single document — an attendance and content record — and one almost no organisation has ready.
The aim is not to turn a director into a technician. It is to let them exercise informed judgement: to understand the implications of a risk decision, challenge executive management where appropriate, and integrate cyber risk into overall governance. After Article 20, not knowing stops being an excuse and becomes, in itself, a governance failing.
Why this binds already, even without a national law
Several member states have not yet published their implementing law. It would be a mistake to conclude that the board's duties do not exist yet. They arrive through two channels that do not wait for the national legislator.
The first is contractual. An essential entity in a transposed country passes down to its suppliers, by contract, requirements that reproduce NIS2 — including the demand for demonstrable security governance. The supplier's board inherits those duties even where the legal basis is a contract rather than a statute. That is where third-party risk management becomes the first real point of contact with NIS2.
The second is the European supervisory calendar itself. Germany, which transposed, set registration with its authority for 6 March 2026; by the end of May roughly 18,500 of approximately 29,000 in-scope entities had registered, per BSI figures. When a national law publishes, the registration window will be short and the board will have to demonstrate governance from day one, not start building it.
What a board can approve and document today
Everything resting on Article 21, which is already published and is not drafted by the national legislator, is stable work. A board can formally record the following without waiting for the definitive text.
- Formal approval, minuted, of the cybersecurity risk management framework, with express reference to the Article 21 categories and the risk appetite adopted.
- Documented determination of whether the organisation is an essential entity, an important entity or neither, with the reasoning by sector and size. When the law arrives you revise it; you do not start over.
- A management body training plan with an attendance and content record.
- Definition of the cadence and content of security reporting to the board, and of the escalation procedure for material deficiencies.
- A standing engagement for periodic independent assurance: audit, external assessment or red team exercise, with conclusions raised to the board.
Consolidating with frameworks the organisation already holds — a well-implemented ISO 27001 covers a good share of Article 21 — avoids duplicating effort. It is where a compliance platform such as NormexAI reduces the work of keeping evidence live and traceable. In financial services, the same governance logic connects to the digital operational resilience that DORA requires.
Where a security provider fits, and where it does not
It is worth being honest about the split. A managed SOC with adequate retention, a rehearsed incident response procedure and red team exercises resolve the executable part of the Article 21 measures and give the board the independent assurance it needs to oversee with judgement.
What no provider can take on is the governance duty. Approving the framework, adopting the risk appetite, training the board and bearing the Article 20 accountability are non-transferable. Any consultancy suggesting that buying a service “puts you in compliance” with NIS2 is describing the law wrongly: services generate the evidence, but governance is exercised by the board. That distinction, properly understood, is what separates a file that survives an inspection from one that collapses at the first question about oversight.
In short
NIS2 turns cybersecurity into a board matter, with names attached. The sanctioning regime — Article 34 fines, the Article 32(5)(b) temporary ban for essential entities — exists to force the Article 20 accountability to be genuinely exercised. The encouraging part is that almost everything protecting the board can be built today, regardless of when a national law publishes: approve with understanding, oversee with evidence, train, and test through independent assurance. A board that can demonstrate those four things sits in a very different position from one that can only produce a service invoice.
You can find more detail on scope and obligations on our NIS2 page and in our analysis of cyber crisis communication in the first 24 hours, where the board's role is again decisive.