Skip to content
NISDESK

Who is liable under NIS2? (management liability)

Under NIS2 Article 20, the management body of an essential or important entity must approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements. Its members must follow cybersecurity training. For essential entities, authorities can also seek a temporary ban on managers at CEO or legal-representative level.

Last updated: 2026-09-30

What the management body must do

  • ▸Approve the Article 21 cybersecurity risk-management measures
  • ▸Oversee their implementation — not just delegate them
  • ▸Follow cybersecurity training, and encourage similar training for employees

How liability is enforced

The directive requires member states to make management bodies accountable for infringements; how personal liability works in practice (civil, administrative or other) is defined by each national law. For essential entities, Article 32 lets authorities request a temporary prohibition on exercising managerial functions if other enforcement measures fail.

Depends on national law: The form and extent of personal liability for managers is set by national law.

Related question

Can managers delegate NIS2 responsibility to the IT team?

They can delegate the work, but not the accountability. Article 20 requires the management body itself to approve the measures and oversee their implementation, and it is the management body that can be held liable.

Next steps

For decision-support purposes only, not legal advice. Exact obligations depend on national transposition — use our free scope checker for a personalised assessment.