Directive (EU) 2022/2555

What NIS2 management accountability requires

Move management approval and training from a signature to an evidenced oversight cycle.

Written and reviewed by Fredrik Surtell ยท

What is the management body expected to do under NIS2?

Management bodies approve the cybersecurity risk-management measures, oversee implementation, and can be held liable under national law. Members must follow training, while entities offer relevant training to employees.

Operating sequence

  1. 01

    Identify the management body for each in-scope legal entity.

  2. 02

    Schedule decisions on scope, risk measures, residual risk, incidents, resources, testing, and remediation.

  3. 03

    Record attendance, challenge, decisions, owners, deadlines, and follow-up evidence.

Failure modes to avoid

  • Delegating approval entirely to the security function.
  • Using generic awareness training as management-body training.
  • Recording a policy approval without tracking implementation or exceptions.

The source remains the authority.

NIS2 Directive Article 20 โ€” EUR-Lex