NIS2Cyber Governance5-minute read·Marcin Pajdzik·October 2025

NIS2 Makes Cybersecurity a Leadership Duty

NIS2 requires the management bodies of in-scope entities to approve the cybersecurity risk-management measures, oversee their implementation and follow training. The duties apply through national law, so leadership first needs to establish which law applies, when it takes effect and which body carries the duty in each entity.

Leadership should then be able to demonstrate what it approved, how implementation was monitored and how material shortcomings were addressed. That record depends on decisions taken with adequate information and on reporting that shows whether the measures work.

Establish who carries the duty

Article 20 of NIS2 sets out the management body's duties, and each Member State gives effect to it through national law. The applicable law determines which body counts as the management body and from when the duties apply. Depending on that law and on the entity's corporate form, the management body may be the board of directors or a body of executive managers.

In a group with several entities in scope, each entity's management body needs to be able to show its own decisions. Records can be organised centrally, provided they show the approval and oversight for each entity.

Approval, oversight and training

Receiving a presentation does not, by itself, demonstrate approval, effective oversight or completion of suitable training.

Approval
The management body approves the measures the entity takes to manage cybersecurity risk. Informed approval rests on an understanding of the main risks, the resources the measures require and the gaps that remain. A minuted decision on a defined set of measures is one practical way to record it.
Oversight
The management body oversees implementation. Periodic reporting on whether the measures are working, where material gaps exist, which incidents have occurred and how the risk picture has changed gives it the basis to intervene. The frequency and depth of that reporting should be proportionate to the entity's risk exposure.
Training
Members must follow training that enables them to identify risks and assess risk-management practices and their impact on the services the entity provides. Individual training records are a practical way to show that each member has done so.

Liability and enforcement

NIS2 provides that management bodies can be held liable for infringements of the risk-management obligations, subject to national rules on the liability of public institutions and officials.

For essential entities, enforcement can escalate further. Where earlier enforcement measures have proved ineffective and the entity misses a deadline to remedy the deficiencies, the competent authority may ask the relevant bodies, courts or tribunals under national law to temporarily prohibit a person at chief executive or legal representative level from exercising managerial functions. The prohibition lasts until the required action is taken, and it does not apply to public administration entities.

Questions for the next leadership discussion

These questions help leadership assess whether it has the decisions and evidence needed to demonstrate informed approval and effective oversight.

Responsibility
Which body and members carry the applicable duties for each entity?
Approval
What measures require a decision, and what risks, resources and gaps should inform it?
Oversight
What evidence demonstrates implementation, and which delays or failures require intervention?
Training
What learning do members need to assess the organisation's risks and challenge management effectively?

How this affects your organisation

For directors and executives of entities in NIS2 scope, the duties attach to the management body defined by national law. Establishing which body that is, and from when, comes before any assessment of whether the duties are met.

Leadership that can show what it approved, how it monitored implementation and how it addressed shortcomings can account for its oversight. Approval and oversight should be part of the organisation's regular governance, with decisions, follow-up actions and reviews recorded as they occur.

If your leadership team is establishing how the NIS2 governance duties apply to it, I can help set up the approval, oversight and training arrangements.

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.

NIS2 Frameworks

If this briefing is relevant to your organisation, these frameworks set out how to act on it, with a structured starting point and a programme approach designed to deliver sustained compliance.

NIS2 Diagnostic FrameworkHow to Run a NIS2 Programme