Establish who carries the duty
Article 20 of NIS2 sets out the management body's duties, and each Member State gives effect to it through national law. The applicable law determines which body counts as the management body and from when the duties apply. Depending on that law and on the entity's corporate form, the management body may be the board of directors or a body of executive managers.
In a group with several entities in scope, each entity's management body needs to be able to show its own decisions. Records can be organised centrally, provided they show the approval and oversight for each entity.
Approval, oversight and training
Receiving a presentation does not, by itself, demonstrate approval, effective oversight or completion of suitable training.
- Approval
- The management body approves the measures the entity takes to manage cybersecurity risk. Informed approval rests on an understanding of the main risks, the resources the measures require and the gaps that remain. A minuted decision on a defined set of measures is one practical way to record it.
- Oversight
- The management body oversees implementation. Periodic reporting on whether the measures are working, where material gaps exist, which incidents have occurred and how the risk picture has changed gives it the basis to intervene. The frequency and depth of that reporting should be proportionate to the entity's risk exposure.
- Training
- Members must follow training that enables them to identify risks and assess risk-management practices and their impact on the services the entity provides. Individual training records are a practical way to show that each member has done so.
Liability and enforcement
NIS2 provides that management bodies can be held liable for infringements of the risk-management obligations, subject to national rules on the liability of public institutions and officials.
For essential entities, enforcement can escalate further. Where earlier enforcement measures have proved ineffective and the entity misses a deadline to remedy the deficiencies, the competent authority may ask the relevant bodies, courts or tribunals under national law to temporarily prohibit a person at chief executive or legal representative level from exercising managerial functions. The prohibition lasts until the required action is taken, and it does not apply to public administration entities.
Questions for the next leadership discussion
These questions help leadership assess whether it has the decisions and evidence needed to demonstrate informed approval and effective oversight.
- Responsibility
- Which body and members carry the applicable duties for each entity?
- Approval
- What measures require a decision, and what risks, resources and gaps should inform it?
- Oversight
- What evidence demonstrates implementation, and which delays or failures require intervention?
- Training
- What learning do members need to assess the organisation's risks and challenge management effectively?