What management bodies must personally do: approve the risk-management measures, oversee implementation, carry liability for infringements, and follow (and offer staff) cybersecurity training.
Article 20 of Directive (EU) 2022/2555 (NIS2) sets governance requirements that Member States must impose on essential and important entities. The Article assigns three duties to the management body of each in-scope entity: approving cybersecurity risk-management measures, overseeing their implementation, and liability exposure for infringements — with a further training requirement in Article 20(2) 32022L2555 Article 20@2022-12-27.
Member States must ensure that the management body of every essential and important entity approves the cybersecurity risk-management measures taken by that entity in order to comply with Article 21 32022L2555 Article 20@2022-12-27. The duty to approve sits directly with the management body.
The same bodies must oversee implementation of those measures 32022L2555 Article 20@2022-12-27. Approval and oversight are stated as distinct requirements: approving a measure does not exhaust the management body's obligation.
Member States must ensure that management bodies can be held liable for infringements by those entities of Article 21 32022L2555 Article 20@2022-12-27. The formulation is permissive: the Directive requires Member States to create a framework under which such liability can attach to the management body; it does not impose liability automatically upon every infringement. The Directive specifies no additional condition — such as a traceable governance failure — beyond the occurrence of an infringement of Article 21 itself.
This provision carries an explicit qualification for public-sector actors. Its application is without prejudice to national law as regards the liability rules applicable to public institutions, as well as the liability of public servants and elected or appointed officials 32022L2555 Article 20@2022-12-27.
Article 20(2) addresses training in two related but structurally distinct ways 32022L2555 Article 20@2022-12-27.
Management body members. Member States must ensure that members of the management body are required to follow training 32022L2555 Article 20@2022-12-27. The stated purpose is that they gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity 32022L2555 Article 20@2022-12-27. Article 20(2) does not attach a frequency qualifier to management body member training.
Employees. Member States must encourage essential and important entities to offer similar training to their employees on a regular basis 32022L2555 Article 20@2022-12-27. Two features distinguish this from the management body requirement: the Member State obligation is one of encouragement rather than mandatory enforcement, and the phrase "regular basis" qualifies employee training — it is not used in Article 20(2) in relation to management body member training 32022L2555 Article 20@2022-12-27.
The training objective in Article 20(2) — to enable individuals to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity — is set out as a single integrated competence goal, not two separable objectives 32022L2555 Article 20@2022-12-27.
This block connects to your organisation's own information-security policies (ISMS). In the full product it shows, cited to your policy set, how YOUR organisation implements the obligation above — private to your organisation. (Demo placeholder.)
The entries below are labeled illustrative context, not regulation.
No recent cases are cached for this topic.
1. Which three duties does Article 20 of NIS2 assign to the management body of an in-scope entity?
Article 20 expressly lists approval, oversight of implementation, and liability exposure as the three distinct management body duties — training is a separate requirement under Article 20(2), not one of the three. 32022L2555 Article 20@2022-12-27
2. What is the relationship between a management body's duty to approve risk-management measures and its duty to oversee their implementation?
The lesson states that approval and oversight are stated as distinct requirements, making clear that approving a measure does not satisfy the oversight obligation. 32022L2555 Article 20@2022-12-27
3. How does Article 20 frame management body liability for infringements of Article 21?
The Directive's formulation is permissive — it requires Member States to enable such liability, not to impose it automatically, and it specifies no additional condition beyond the infringement itself. 32022L2555 Article 20@2022-12-27
4. For which category of actors does Article 20 explicitly state that its liability provision applies without prejudice to national law?
The lesson notes an explicit qualification: the liability provision is without prejudice to national law as regards public institutions and the liability of public servants and elected or appointed officials. 32022L2555 Article 20@2022-12-27
5. How does Article 20(2) differ in its training requirements for management body members compared to employees?
Article 20(2) imposes a must-follow obligation on management body members without a frequency qualifier, while using encourage and the phrase "regular basis" exclusively for employees. 32022L2555 Article 20@2022-12-27