NIS2 Article 20 makes cybersecurity risk management a management-body responsibility. For essential and important entities, the management body must approve the measures used to comply with Article 21, oversee their implementation and follow training. National law determines how liability applies in practice.
This is more than receiving an annual cybersecurity presentation. Management needs enough current information to understand the services at risk, challenge whether the measures are proportionate, decide how gaps will be treated and follow whether agreed actions are actually completed.
01
What does NIS2 Article 20 require?
Article 20 of Directive (EU) 2022/2555 establishes three connected duties for the management bodies of essential and important entities:
- Approve the cybersecurity risk-management measures. These are the technical, operational and organisational measures taken to comply with Article 21.
- Oversee implementation. Approval is not the end of the responsibility. Management must remain able to see whether the agreed measures operate and whether material gaps are being addressed.
- Follow training. Members need sufficient knowledge and skills to identify risks and assess cybersecurity practices and their effect on the services the entity provides.
Article 20 also requires Member States to ensure that management bodies can be held liable for infringements of Article 21. The applicable liability rules, competent authority and enforcement route come from national implementation. Organisations operating in several Member States should therefore keep a shared governance model with clear country-specific overlays.
02
Which cybersecurity measures must management approve?
Article 20 points directly to Article 21. This means management is not approving a narrow security policy. It is approving an appropriate and proportionate system of measures across the organisation.
- risk analysis and information-system security policies;
- incident handling;
- business continuity, backup, disaster recovery and crisis management;
- supply-chain security and direct supplier relationships;
- secure acquisition, development and maintenance, including vulnerability handling;
- assessment of whether cybersecurity measures are effective;
- cyber hygiene and cybersecurity training;
- cryptography and encryption where appropriate;
- human-resources security, access control and asset management; and
- multi-factor or continuous authentication, secured communications and secured emergency communications where appropriate.
The measures must use an all-hazards approach and be proportionate to the risks. The Directive points to factors such as exposure, size, likelihood, severity and the potential societal and economic impact of incidents. Management does not need to approve every technical configuration. It does need to approve the risk basis, the organised set of measures and the treatment of material exceptions.
03
What does meaningful management oversight look like?
Operational teams remain responsible for running systems, responding to incidents and maintaining controls. Article 20 places a different responsibility on management: approve, challenge, monitor and decide.
A useful oversight view should let the management body answer questions such as:
- Scope: Which legal entities and services are covered, and which national rules apply?
- Service impact: What would customers, citizens or other services experience if a critical dependency failed?
- Risk: Which scenarios could materially disrupt the service, and how has their likelihood and impact changed?
- Measures: Which safeguards address those scenarios, who owns them and how is effectiveness assessed?
- Gaps: Which findings, exceptions or overdue actions require acceptance, funding or escalation?
- Dependencies: Which suppliers, assets and people create concentrations or single points of failure?
- Incidents: What happened, what was reported, what remains uncertain and which measures must change?
These answers rarely live in one system. They are usually spread across meetings, email, policies, supplier files, risk registers, tickets and incident records. Oversight becomes fragile when every management meeting requires a new reconstruction of the same story.
04
Which evidence makes Article 20 oversight visible?
The Directive does not prescribe a single board-pack format or a fixed Article 20 evidence list. The following is a practical evidence model: it helps show that approval, challenge, training and follow-up occurred and were connected to the entity’s real services and risks.
- a dated approval record for the cybersecurity risk-management framework and material updates;
- the scope and service map used to support the decision;
- meeting papers and minutes that preserve questions, challenge, decisions and requested actions;
- a measure register linking risks, measures, owners, effectiveness checks, evidence and review dates;
- documented risk acceptances and exceptions, including rationale, authority and expiry;
- management training content, attendance and follow-up needs;
- incident escalation and reporting decisions, with the facts available at the time;
- tracked remediation actions showing ownership, deadlines, status and closure evidence; and
- records showing how supplier, continuity and asset information affected the management view.
Volume is not the goal. A short record that connects the decision to current risks and follow-up can be stronger than a large pack of policies with no visible ownership or challenge.
05
What must management-body training achieve?
Article 20 does not describe training as a generic awareness exercise. Its purpose is to give management sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided.
Training should therefore reflect the organisation’s own operating reality. Useful topics include the entity’s important services, plausible disruption scenarios, the reporting and escalation model, supply-chain exposure, the meaning of key risk and control indicators, and the decisions management may need to take before every technical fact is known.
ENISA’s guidance on cybersecurity roles and skills can help organisations map the professional capabilities needed to put NIS2 measures into practice. It does not define the training that a management body must follow. National requirements and guidance remain the final reference for training frequency, content or evidence in a particular Member State.
06
How do liability and enforcement affect management?
Article 20 says management bodies can be held liable for an entity’s infringement of Article 21, but the practical liability rules depend on national law. The legal analysis should therefore identify the applicable entity, Member State, management structure and national transposition instead of treating “the board” as the same body in every organisation.
For essential entities, Article 32 also provides serious last-resort enforcement powers. If specified enforcement measures have been ineffective and the entity has not remedied deficiencies by the authority’s deadline, the competent authority can ask the relevant body, court or tribunal to impose a temporary prohibition on exercising managerial functions at chief executive or legal-representative level. The route depends on national law, and the prohibition lasts only until the entity takes the required action. This is not an automatic consequence of every control gap, but it underlines why approval without effective follow-up is not enough.
Financial entities should also check the formal boundary with DORA. The Commission’s guidance on NIS2 Article 4 explains when a sector-specific Union legal act applies to cybersecurity risk-management and reporting requirements.
07
A practical Article 20 governance cycle
A repeatable cycle is more useful than a one-time approval exercise:
- Establish the boundary. Confirm the legal entities, services, classification and national implementation routes.
- Prepare the decision. Present the main service risks, Article 21 measures, effectiveness evidence, open gaps and proposed treatment.
- Record approval and challenge. Preserve what was approved, which questions were raised, which exceptions were accepted and which actions were requested.
- Monitor implementation. Follow material risks, incidents, effectiveness results, supplier changes and overdue remediation on an agreed cadence.
- Escalate change. Return to management when the service, threat, supplier landscape or risk acceptance changes materially.
- Learn from incidents and tests. Connect lessons to measures, owners, resources and the next management decision.
The cadence should fit the entity’s risks and national requirements. The important point is continuity: management should be able to follow the same responsibilities from approval through implementation, exception, incident and improvement.
08
Where should an organisation start?
Start by assembling one management view from information the organisation already holds:
- confirm scope and the responsible management body;
- name the services whose security and availability matter;
- map the most material risks to the Article 21 measures;
- identify gaps, owners, decisions and deadlines;
- schedule management training around the entity’s actual risk scenarios; and
- set a recurring oversight and escalation cadence.
The European NIS2 guide connects this management responsibility to scope, national implementation, incident reporting, supply-chain security and the wider operating record. Ariadnah helps organisations connect the knowledge behind those responsibilities so that decisions, ownership and evidence remain usable between meetings and assessments.
Book a Discovery Call to discuss the NIS2 responsibility that is still spread across teams, systems and documents.
09
Primary sources
- Directive (EU) 2022/2555, Article 20: management approval, oversight, liability and training.
- Directive (EU) 2022/2555, Article 21: appropriate and proportionate cybersecurity risk-management measures.
- Directive (EU) 2022/2555, Article 32: supervision and enforcement for essential entities.
- ENISA: Cybersecurity roles and skills for NIS2 essential and important entities.
- European Commission guidance on NIS2 Article 4: the boundary with sector-specific Union legal acts.
This article is an operating overview, not legal advice. Scope, management responsibility, liability and enforcement depend on the entity and the national law implementing NIS2.