[{"data":1,"prerenderedAt":10},["ShallowReactive",2],{"article:en:nis2-article-20-for-the-board-what-the-management-body-must-approve-oversee-and-learn-the-twelve-places-the-implementing-regulation-names-it-and-what-liability-means":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"body":9},"en","nis2-article-20-for-the-board-what-the-management-body-must-approve-oversee-and-learn-the-twelve-places-the-implementing-regulation-names-it-and-what-liability-means","NIS2 Article 20 for the board: what the management body must approve, oversee and learn, the twelve places the Implementing Regulation names it, and what liability means","Article 20 of NIS2 makes the management body of an essential or important entity approve the cybersecurity risk-management measures, oversee their implementation, be liable for the entity's infringements of Article 21, and follow training. Implementing Regulation 2024\u002F2690 then names the management body in twelve places of its Annex: a dated approval of the policy, an annual review, a direct reporting line, acceptance of residual risk, compliance reporting, an awareness programme. Each of the twelve as a record, the ISO 27001 clause that already produces it, and what Article 32 and Article 34 say liability looks like.","2026-09-12","\nEvery article about NIS2 and boards says that management is liable. Fewer say what the management body is actually required to do, which is the question a director asks first, because liability attaches to duties. The duties are short and in one article of the Directive, and for the entities the Implementing Regulation covers they are then written out as twelve specific records. This article is those duties and those records, with the ISO 27001 clause that already produces each, and what the Directive says about liability, read from the text.\n\n## Article 20, in two paragraphs\n\nArticle 20(1) of Directive (EU) 2022\u002F2555: member states \"shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article\". Three verbs: approve, oversee, be liable. The measures are [the ten of Article 21(2)](\u002Farticles\u002Fthe-ten-measures-of-nis2-article-21-2-as-a-checklist-each-point-quoted-the-regulation-sections-behind-it-and-the-iso-27001-controls-that-already-produce-it), and the liability is for the entity's infringements of that article, not for every incident.\n\nArticle 20(2): member states \"shall ensure that the members of the management bodies of essential and important entities are required to follow training\", and \"shall encourage\" the entities to offer similar training to their employees on a regular basis, so that they \"gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity\". The asymmetry is deliberate: for members of the management body the training is required; for employees it is encouraged. The Directive does not say how long, how often or by whom; national law and the sector's supervisor fill that in, and the Implementing Regulation adds the awareness programme below.\n\nThe duties are the same for essential and important entities, and for every sector. What differs is enforcement, which is the last section.\n\n## The twelve places the Implementing Regulation names the management body\n\nFor the sectors Implementing Regulation (EU) 2024\u002F2690 covers, cloud providers, managed service providers, data centres, online marketplaces and the rest of its Article 1, Article 20's \"approve\" and \"oversee\" stop being abstract. The Annex names the management bodies in twelve places, and each one is a record a supervisor can ask for. The ISO 27001 clause in the last column is our reading of what already produces it; the mapping is ours, not ENISA's.\n\n| Annex point | What the management body does | The record | ISO\u002FIEC 27001:2022 |\n| --- | --- | --- | --- |\n| 1.1.1(k) | The security policy shall \"indicate the date of the formal approval by the management bodies\" | A policy with an approval date and the body that approved it | 5.2 |\n| 1.1.2 | The policy is \"reviewed and, where appropriate, updated by management bodies at least annually\", and after significant incidents or changes; \"the result of the reviews shall be documented\" | A dated review record, at least yearly | 9.3 |\n| 1.2.1 | Responsibilities and authorities for security are assigned to roles and \"communicated to the management bodies\" | The roles document, and the communication | 5.3 |\n| 1.2.3 | \"At least one person shall report directly to the management bodies on matters of network and information system security\" | A named person with a direct reporting line | 5.3 |\n| 1.2.6 | Roles, responsibilities and authorities are \"reviewed and, where appropriate, updated by management bodies at planned intervals\" | A review of the roles, on a schedule | 9.3 |\n| 2.1.1 | \"Risk assessment results and residual risks shall be accepted by management bodies\", or by accountable persons with adequate reporting to the management bodies | The risk assessment with its acceptance, signed | 6.1.2, 6.1.3 |\n| 2.2.1 | The management bodies \"shall be informed of the status of network and information security on the basis of the compliance reviews by means of regular reporting\" | Compliance reports, on a cadence | 9.1 |\n| 2.2.2 | A compliance reporting system \"capable to provide to the management bodies an informed view of the current state\" of risk management | The reporting system itself | 9.1 |\n| 2.3.3 | The results of independent reviews, including compliance monitoring and measurement, \"shall be reported to the management bodies\" | Internal audit results reaching the body | 9.2, 9.3 |\n| 8.1.1 | Employees \"including members of management bodies\" are aware of risks and apply cyber hygiene | Awareness evidence for the members | 7.3 |\n| 8.1.2 | An awareness-raising programme offered to employees \"including members of management bodies\", scheduled over time and repeated | The programme, its schedule, attendance | 7.2, 7.3 |\n| 10.1.2(c) | \"Mechanisms to ensure that members of management bodies understand and act in accordance with their role, responsibilities and authorities\" | Role acknowledgements for the members | 5.3, 7.3 |\n\nTwo of the twelve carry most of the weight. The approval date in 1.1.1(k) is the record of \"approve\" in Article 20(1): a policy without a dated approval by the management body fails the first duty on its face. The reporting line in 1.2.3 and the reports in 2.2.1 and 2.3.3 are the record of \"oversee\": a body that receives no security reporting cannot show it oversaw anything. An ISO 27001 management system already produces every row: the policy approval under clause 5.2, the roles under 5.3, the risk acceptance under 6.1.3, the reporting under 9.1 and 9.2, the yearly management review under 9.3, the competence and awareness records under 7.2 and 7.3. What it does not do by itself is put the members of the management body into the awareness programme, which the Regulation does twice, in 8.1.1 and 8.1.2.\n\nFor entities outside the Implementing Regulation's sectors, [the national transposition](\u002Farticles\u002Fnis2-transposition-state-by-state-what-the-commissions-register-shows) carries Article 20 and may add its own detail; the twelve records above are still the natural evidence of the two verbs.\n\n## What liability looks like\n\nArticle 20(1) says the management body \"can be held liable\"; it does not say how. Two other provisions do.\n\nFor essential entities, Article 32(5) gives the competent authority, where the enforcement measures of Article 32(4) have been ineffective and a deadline to remedy has passed, the power to request that the courts or relevant bodies \"prohibit temporarily any natural person who is responsible for discharging managerial responsibilities at chief executive officer or legal representative level in the essential entity from exercising managerial functions in that entity\", applied only until the entity remedies the deficiencies, with procedural safeguards. Article 32(6): member states ensure that any natural person responsible for or acting as a legal representative of an essential entity \"has the power to ensure its compliance\" and that \"it is possible to hold such natural persons liable for breach of their duties to ensure compliance\". The temporary prohibition does not apply to public administration entities.\n\nFor important entities, Article 33 has no equivalent of Article 32(5) or (6); the liability of Article 20(1) is what national law makes of it.\n\nFor both, Article 34 sets the fines for infringing Article 21 or 23: for essential entities a maximum of at least EUR 10 000 000 or 2 % of total worldwide annual turnover of the undertaking, whichever is higher (Article 34(4)); for important entities a maximum of at least EUR 7 000 000 or 1.4 % (Article 34(5)). The fines are on the entity; \"maximum of at least\" means member states set the ceiling no lower.\n\nRecital 137 says why: the Directive \"should aim to ensure a high level of responsibility for the cybersecurity risk-management measures and reporting obligations at the level of the essential and important entities\", which is why \"the management bodies of the essential and important entities should approve the cybersecurity risk-management measures and oversee their implementation\".\n\n## What to put in front of the board\n\nRead as a list of records, Article 20 for a company in the Implementing Regulation's sectors is one meeting a year plus a standing item: the policy approved with a date and re-approved yearly (1.1.1(k), 1.1.2); the roles reviewed and the named person who reports directly (1.2.1, 1.2.3, 1.2.6); the risk assessment and its residual risks accepted in the minutes (2.1.1); compliance and audit results on the agenda at a set cadence (2.2.1, 2.2.2, 2.3.3); and the members' own awareness training scheduled and recorded (8.1.1, 8.1.2, 10.1.2(c)). [Whether your company is essential or important](\u002Farticles\u002Fessential-or-important-under-nis2-the-size-rule-the-size-blind-rules-and-the-seven-ways-to-be-essential), and whether the Implementing Regulation applies to it, is the [free determination](\u002Fnis2\u002Fscope); [the mapping of the Regulation's thirteen sections to ISO 27001](\u002Fnis2\u002Fiso-27001-mapping) has the rest of the Annex.\n\n## Sources\n\n- Directive (EU) 2022\u002F2555 (NIS2), Article 20, Article 21(2), Article 32(4) to (6), Article 33, Article 34(4) and (5), recital 137.\n- Commission Implementing Regulation (EU) 2024\u002F2690, Annex, points 1.1.1(k), 1.1.2, 1.2.1, 1.2.3, 1.2.6, 2.1.1, 2.2.1, 2.2.2, 2.3.3, 8.1.1, 8.1.2 and 10.1.2(c).\n- ISO\u002FIEC 27001:2022, clauses 5.2, 5.3, 6.1.2, 6.1.3, 7.2, 7.3, 9.1, 9.2 and 9.3, cited by number; the mapping is ours.\n\nThis is not legal advice. Article 20 is transposed by each member state, and the liability rules for a specific board are the national ones; the text to read is the Directive's and your state's act.\n",1789383983537]