Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
All posts
Pavel Láska

NIS2 makes management accountable. Here’s what that actually means.

Article 20 gives the board three verbs — approve, oversee, be personally liable — plus a training duty that gets overlooked. The calm version, and the paper trail that answers all of it.

  • nis2
  • governance
  • article-20

Somewhere in the past year, NIS2 stopped being your IT manager's problem. Maybe it arrived as a board paper, maybe as a customer questionnaire, maybe as a memo from your lawyer with your name in it. However it arrived, the part that concerns you personally is one short article — Article 20 — and it fits on a page.

This post is that page, unpacked for the person who runs the company. No acronym soup; where a technical term is unavoidable, it gets explained.

The three verbs in Article 20

NIS2 — the EU directive on cybersecurity for essential and important entities, now transposed into national law across most of the EU — spends most of its length on what companies must do. Article 20 is about what leadership must do, and it comes down to three verbs:

"Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article."

Approve is not "was informed about." It means the management body — the board, the executive directors, in many mid-market companies simply you — formally signs off the cybersecurity measures the company takes. If nobody can point to the meeting where that happened, it didn't happen.

Oversee is ongoing, not annual. It implies leadership receives regular, readable reporting on where the measures stand — and can show it acted on what the reporting said.

Held liable means what it says: when the company falls short of its Article 21 obligations, responsibility can reach the management body personally. The exact mechanics vary by country, because each member state wrote its own transposition law — but the direction of travel is uniform. "The IT department handles security" is no longer a governance answer.

The obligation almost everyone misses: training

Article 20 has a second paragraph, and it is quietly the most concrete duty in the whole article. Members of the management bodies of essential and important entities are required to follow cybersecurity training — required, not encouraged. The encouragement applies to offering similar training to employees; for leadership itself, the training is an obligation. The stated goal: enough knowledge and skills to identify risks and assess how cybersecurity measures affect the services the company provides.

Practically, this is the cheapest item on the entire NIS2 list. A half-day session, pitched at non-technical executives, once a year, with attendance recorded. Yet when a supervisory authority asks for management training records, a surprising number of otherwise well-run companies have nothing on file — because nobody told the leadership team the obligation was theirs, personally.

What "liable" actually reaches

Here is the calm version of the enforcement picture, because this topic attracts more scaremongering than any other clause in the directive.

The fines sit at entity level: for essential entities, up to €10 million or 2% of total worldwide annual turnover, whichever is higher; for important entities, up to €7 million or 1.4%. Those are the maximums national law must allow for, not the expected outcome of an inspection.

For essential entities there is a further step, and it is worth knowing precisely because it is so often misquoted. If an authority has already issued warnings and binding instructions and the entity still doesn't remediate, the authority can temporarily suspend certifications or authorisations for the relevant services — and can ask a court to temporarily bar the person at chief-executive or legal-representative level from exercising managerial functions in that entity, until the deficiency is fixed. That power exists as leverage against refusal to act. It is an escalation at the end of a documented process, not an ambush at the start of one.

The realistic exposure for most owners is quieter than either of those: a supervisory inquiry the company answers badly, remediation under a deadline you didn't choose, and uncomfortable conversations with the customers who ask what happened. Expensive, distracting, and — with a paper trail in place — largely avoidable.

Governance obligations are evidence obligations

Every verb in Article 20 turns into a document when someone checks. Four artefacts cover the ground:

  • A minuted approval. The board (or you, as owner-director) formally approved the company's cybersecurity risk-management measures, on a date, recorded in minutes.
  • A recurring management paper. A few readable pages, monthly or quarterly: current posture, movement in the supplier portfolio, open exposures, decisions taken. This is what "oversee" looks like on paper.
  • Training records for the management body. Date, content, attendees. Half a day a year.
  • A decision trace for the judgment calls. Who accepted which risk, when, and on what basis. Written at decision time — not reconstructed at audit time.
Decision trace ready for the regulatorAuditor question answered by a signed, hash-anchored decision trace with five entries from risk tier through final approval.?Auditor question"How did you assess Cirrus Edge Networks for NIS2 21(2)(d)?"Decision traceEdge ingress · REV-2026-014Risk tier set: Tier 2 / HighApr 12 · You8/8 questionsISO 27001 + SoA approvedApr 18 · Yousha256:f1c…Sub-processor list v2 approvedApr 22 · Yousha256:7d2…Privileged access review approvedApr 22 · Yousha256:b8e…Approved · valid until Oct 26, 2026Apr 26 · YousealedEvery entry timestamped, signed, hash-anchored.Hand it over. Walk away.

None of this requires a security background. It requires the same governance habit you already apply to financial risk: decisions made visibly, recorded, and revisited on a cadence.

Why the supplier part is the hardest to oversee

Most of the Article 21 measures are internal — backup, incident handling, access control, training. Overseeing them means asking your own team and reading your own systems. One obligation is structurally different: supply chain security, Article 21(2)(d), which covers the relationships between your company and its direct suppliers and service providers.

The evidence for that one lives with external parties. It arrives in a dozen formats. It expires unevenly. And a board cannot oversee what nobody in the company can reconstruct. If you want one question that cuts through every reassuring slide at your next management meeting, ask this: "If our most critical supplier reported a breach tomorrow morning, how long until I know whether we're exposed?" If the honest answer is a shrug — or "a few days" — that is the gap, named.

What to do this quarter

1. Find out what you are. Essential entity, important entity, or out of scope — the classification depends on your sector and size under your country's transposition law, and a handful of entity types are in scope regardless of size. Don't guess from headcount alone; get a definitive answer from counsel or your national authority's guidance.

2. Put the measures in front of the board — and minute the approval. If the measures aren't written down yet, that's the first finding; commissioning them is itself a defensible, documented act of oversight.

3. Book the training. It is the fastest obligation to discharge and the first record an inspector can ask for by name.

4. Ask for the recurring paper. If nobody in the company can produce a readable monthly or quarterly summary of cybersecurity posture, you've learned something important about your oversight machinery — before a regulator does.

If there's no one to write that paper

Plenty of mid-market companies have exactly this shape: a capable IT lead, no dedicated security manager, and a board that needs a credible voice on its papers. That's the gap the NIS2 Qualified Manager retainer exists to close — a named practitioner on a monthly cadence, writing the board paper Article 20 assumes someone is writing.

And if you want a written, defensible picture of where the company stands before you put anything in front of the board, the NIS2 Supplier Exposure Assessment produces exactly that. Two to three weeks. Fixed price. The deliverable is the report.

Follow on LinkedIn

Release announcements on LinkedIn.

Follow the company page for pilot dates, product milestones, and the work as it ships. Public, low-volume, no inbox to clutter.

Follow Shards Cybersecurity