Ariadnah
Platform
DORA Understand the responsibilities, common operating gaps, and the path from shared knowledge to evidence. AML & KYC Customer due diligence with the ownership look-through resolved as data. Risk & Control One control catalogue, read through every framework it answers to. Governance & Policies Policies drafted, mapped to requirements clause by clause, and approved in the platform.

Platform

  • Platform overview
  • AI assistant
  • Security & trust
  • Impact & access

Domains and services

  • Register of Information
  • Suppliers & Contracts
  • Asset Management
  • Risk & Control
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • Governance & Policies
  • Incident Management
  • All solutions →

By sector

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services
  • All sectors →
About Pricing Insights Resources Contact
Book a Discovery Call
Home About Platform Solutions Sectors Pricing Insights Resources DORA Guide NIS2 Guide Contact
Book a Discovery Call
Insights

NIS2 Article 20: Management Body Responsibilities

Menno Schaap NIS2 10 Jul 2026 7 min read

NIS2 Article 20 requires management bodies to approve cybersecurity risk-management measures, oversee implementation and follow training. What does credible oversight look like in practice?

NIS2 Article 20 makes cybersecurity risk management a management-body responsibility. For essential and important entities, the management body must approve the measures used to comply with Article 21, oversee their implementation and follow training. National law determines how liability applies in practice.

This is more than receiving an annual cybersecurity presentation. Management needs enough current information to understand the services at risk, challenge whether the measures are proportionate, decide how gaps will be treated and follow whether agreed actions are actually completed.

01

What does NIS2 Article 20 require?

Article 20 of Directive (EU) 2022/2555 establishes three connected duties for the management bodies of essential and important entities:

  1. Approve the cybersecurity risk-management measures. These are the technical, operational and organisational measures taken to comply with Article 21.
  2. Oversee implementation. Approval is not the end of the responsibility. Management must remain able to see whether the agreed measures operate and whether material gaps are being addressed.
  3. Follow training. Members need sufficient knowledge and skills to identify risks and assess cybersecurity practices and their effect on the services the entity provides.

Article 20 also requires Member States to ensure that management bodies can be held liable for infringements of Article 21. The applicable liability rules, competent authority and enforcement route come from national implementation. Organisations operating in several Member States should therefore keep a shared governance model with clear country-specific overlays.

02

Which cybersecurity measures must management approve?

Article 20 points directly to Article 21. This means management is not approving a narrow security policy. It is approving an appropriate and proportionate system of measures across the organisation.

  • risk analysis and information-system security policies;
  • incident handling;
  • business continuity, backup, disaster recovery and crisis management;
  • supply-chain security and direct supplier relationships;
  • secure acquisition, development and maintenance, including vulnerability handling;
  • assessment of whether cybersecurity measures are effective;
  • cyber hygiene and cybersecurity training;
  • cryptography and encryption where appropriate;
  • human-resources security, access control and asset management; and
  • multi-factor or continuous authentication, secured communications and secured emergency communications where appropriate.

The measures must use an all-hazards approach and be proportionate to the risks. The Directive points to factors such as exposure, size, likelihood, severity and the potential societal and economic impact of incidents. Management does not need to approve every technical configuration. It does need to approve the risk basis, the organised set of measures and the treatment of material exceptions.

03

What does meaningful management oversight look like?

Operational teams remain responsible for running systems, responding to incidents and maintaining controls. Article 20 places a different responsibility on management: approve, challenge, monitor and decide.

A useful oversight view should let the management body answer questions such as:

  • Scope: Which legal entities and services are covered, and which national rules apply?
  • Service impact: What would customers, citizens or other services experience if a critical dependency failed?
  • Risk: Which scenarios could materially disrupt the service, and how has their likelihood and impact changed?
  • Measures: Which safeguards address those scenarios, who owns them and how is effectiveness assessed?
  • Gaps: Which findings, exceptions or overdue actions require acceptance, funding or escalation?
  • Dependencies: Which suppliers, assets and people create concentrations or single points of failure?
  • Incidents: What happened, what was reported, what remains uncertain and which measures must change?

These answers rarely live in one system. They are usually spread across meetings, email, policies, supplier files, risk registers, tickets and incident records. Oversight becomes fragile when every management meeting requires a new reconstruction of the same story.

04

Which evidence makes Article 20 oversight visible?

The Directive does not prescribe a single board-pack format or a fixed Article 20 evidence list. The following is a practical evidence model: it helps show that approval, challenge, training and follow-up occurred and were connected to the entity’s real services and risks.

  • a dated approval record for the cybersecurity risk-management framework and material updates;
  • the scope and service map used to support the decision;
  • meeting papers and minutes that preserve questions, challenge, decisions and requested actions;
  • a measure register linking risks, measures, owners, effectiveness checks, evidence and review dates;
  • documented risk acceptances and exceptions, including rationale, authority and expiry;
  • management training content, attendance and follow-up needs;
  • incident escalation and reporting decisions, with the facts available at the time;
  • tracked remediation actions showing ownership, deadlines, status and closure evidence; and
  • records showing how supplier, continuity and asset information affected the management view.

Volume is not the goal. A short record that connects the decision to current risks and follow-up can be stronger than a large pack of policies with no visible ownership or challenge.

05

What must management-body training achieve?

Article 20 does not describe training as a generic awareness exercise. Its purpose is to give management sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided.

Training should therefore reflect the organisation’s own operating reality. Useful topics include the entity’s important services, plausible disruption scenarios, the reporting and escalation model, supply-chain exposure, the meaning of key risk and control indicators, and the decisions management may need to take before every technical fact is known.

ENISA’s guidance on cybersecurity roles and skills can help organisations map the professional capabilities needed to put NIS2 measures into practice. It does not define the training that a management body must follow. National requirements and guidance remain the final reference for training frequency, content or evidence in a particular Member State.

06

How do liability and enforcement affect management?

Article 20 says management bodies can be held liable for an entity’s infringement of Article 21, but the practical liability rules depend on national law. The legal analysis should therefore identify the applicable entity, Member State, management structure and national transposition instead of treating “the board” as the same body in every organisation.

For essential entities, Article 32 also provides serious last-resort enforcement powers. If specified enforcement measures have been ineffective and the entity has not remedied deficiencies by the authority’s deadline, the competent authority can ask the relevant body, court or tribunal to impose a temporary prohibition on exercising managerial functions at chief executive or legal-representative level. The route depends on national law, and the prohibition lasts only until the entity takes the required action. This is not an automatic consequence of every control gap, but it underlines why approval without effective follow-up is not enough.

Financial entities should also check the formal boundary with DORA. The Commission’s guidance on NIS2 Article 4 explains when a sector-specific Union legal act applies to cybersecurity risk-management and reporting requirements.

07

A practical Article 20 governance cycle

A repeatable cycle is more useful than a one-time approval exercise:

  1. Establish the boundary. Confirm the legal entities, services, classification and national implementation routes.
  2. Prepare the decision. Present the main service risks, Article 21 measures, effectiveness evidence, open gaps and proposed treatment.
  3. Record approval and challenge. Preserve what was approved, which questions were raised, which exceptions were accepted and which actions were requested.
  4. Monitor implementation. Follow material risks, incidents, effectiveness results, supplier changes and overdue remediation on an agreed cadence.
  5. Escalate change. Return to management when the service, threat, supplier landscape or risk acceptance changes materially.
  6. Learn from incidents and tests. Connect lessons to measures, owners, resources and the next management decision.

The cadence should fit the entity’s risks and national requirements. The important point is continuity: management should be able to follow the same responsibilities from approval through implementation, exception, incident and improvement.

08

Where should an organisation start?

Start by assembling one management view from information the organisation already holds:

  • confirm scope and the responsible management body;
  • name the services whose security and availability matter;
  • map the most material risks to the Article 21 measures;
  • identify gaps, owners, decisions and deadlines;
  • schedule management training around the entity’s actual risk scenarios; and
  • set a recurring oversight and escalation cadence.

The European NIS2 guide connects this management responsibility to scope, national implementation, incident reporting, supply-chain security and the wider operating record. Ariadnah helps organisations connect the knowledge behind those responsibilities so that decisions, ownership and evidence remain usable between meetings and assessments.

Book a Discovery Call to discuss the NIS2 responsibility that is still spread across teams, systems and documents.

09

Primary sources

  • Directive (EU) 2022/2555, Article 20: management approval, oversight, liability and training.
  • Directive (EU) 2022/2555, Article 21: appropriate and proportionate cybersecurity risk-management measures.
  • Directive (EU) 2022/2555, Article 32: supervision and enforcement for essential entities.
  • ENISA: Cybersecurity roles and skills for NIS2 essential and important entities.
  • European Commission guidance on NIS2 Article 4: the boundary with sector-specific Union legal acts.

This article is an operating overview, not legal advice. Scope, management responsibility, liability and enforcement depend on the entity and the national law implementing NIS2.

Continue with NIS2

Put this question in context.

The European NIS2 guide connects management responsibility to scope, national implementation, risk measures, incident reporting and supply-chain security.

Recommended next Read the European NIS2 guide →
Explore the operating approach See the governance and policy approach
Manage Consent
We use cookies to keep this site reliable and to understand how it is used. You can accept, deny, or adjust your preferences at any time.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ariadnah

Compliance advisory & technology

Regulatory specialists and technology that help organisations simplify compliance, strengthen operational resilience, and build lasting trust.

ISO/IEC 27001 certified (DNV)

Platform

  • Platform Overview
  • DORA Guide
  • NIS2 Guide
  • Regulatory Library
  • Register of Information
  • Risk & Control
  • Governance & Policies
  • Incident Management
  • Asset Management
  • Suppliers & Contracts
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • AI
  • Security

Sectors

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services

Company

  • About Ariadnah
  • Pricing
  • Our Experts
  • Impact
  • FAQ
  • Insights
  • Contact

Legal

  • General Terms
  • Data & Privacy
  • Cookie Policy
  • Accessibility

© 2026 Ariadnah Solutions B.V.