What is the management body expected to do under NIS2?
Management bodies approve the cybersecurity risk-management measures, oversee implementation, and can be held liable under national law. Members must follow training, while entities offer relevant training to employees.
Operating sequence
- 01
Identify the management body for each in-scope legal entity.
- 02
Schedule decisions on scope, risk measures, residual risk, incidents, resources, testing, and remediation.
- 03
Record attendance, challenge, decisions, owners, deadlines, and follow-up evidence.
Failure modes to avoid
- Delegating approval entirely to the security function.
- Using generic awareness training as management-body training.
- Recording a policy approval without tracking implementation or exceptions.
The source remains the authority.
NIS2 Directive Article 20 โ EUR-Lex