Get Demo
↑

NIS2 Management Liability: Board Accountability and Training (Article 20)

Article 20 of Directive (EU).

Published: September 2026 Compliance · NIS2 8–12 min read

Article 20 is why NIS2 shows up in board packs. Management bodies must approve cybersecurity risk-management measures, oversee implementation, and can be held liable for infringements under national rules implementing the Directive.

Related: NIS2 hub · Article 21 · Fines.

Board themes under Article 20: approve and oversee cybersecurity risk-management measures; follow training sufficient to identify risks and assess risk-management practices; expect national law to attach personal consequences for serious failures.

What Boards Need to Show

Training Expectations

Article 20 emphasises that members of management bodies follow training to identify risks and assess cybersecurity risk-management practices — tabletop briefings and one-slide “awareness” decks rarely meet that bar.

Practical Cadence

How CyberSilo Helps

Give Directors Evidence, Not Slides Alone

CSA management dashboards and ThreatHawk incident metrics support Article 20 oversight.

Frequently Asked Questions

Does Article 20 create personal liability automatically?

The Directive requires Member States to ensure management bodies can be held liable for infringements of Article 21 duties. Exact personal sanctions depend on national transposition — confirm national law.

Can the CISO replace board training?

No. Management-body members themselves need appropriate training under Article 20 themes.

What evidence helps in a supervisory review?

Board minutes approving measures, training attendance records, and recurring oversight reports mapped to Article 21 status.

NIS2 hub · Checklist · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!