Business

NIS2 Management Body Liability: Can Your CEO Be Held Personally Responsible?

The Kopik team7 min read

Yes, NIS2 creates personal exposure for senior management. Article 20 requires the management bodies of essential and important entities to approve the cybersecurity risk-management measures, oversee their implementation and be capable of being held liable for the entity's infringements of Article 21. Members of those bodies must follow cybersecurity training. For essential entities, authorities can, as a last resort, seek a temporary ban on the CEO or legal representative exercising managerial functions. And corporate fines must reach at least EUR 10 million or 2% of worldwide annual turnover of the undertaking the entity belongs to.

Article 20: three duties for the management body

Article 20(1) of Directive (EU) 2022/2555 is short and direct: Member States "shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article."

  1. Approve. The measures required by Article 21, which include risk analysis and security policies, incident handling, business continuity, supply chain security, secure development and vulnerability handling, effectiveness testing, cyber hygiene and training, cryptography, HR security and access control, and multi-factor authentication, need management-body sign-off.
  2. Oversee. Approval is not a one-time signature. The body must follow implementation.
  3. Answer for it. The body "can be held liable" for the entity's infringements of Article 21.

Recital 137 explains the aim: "a high level of responsibility for the cybersecurity risk-management measures and reporting obligations at the level of the essential and important entities." Article 20 is addressed to Member States, which must ensure this liability exists; how it works in practice depends on each national transposing law. The directive also preserves national rules on the liability of public institutions, public servants and elected or appointed officials.

What "oversight" looks like on paper

For cloud, data center, managed service and other digital providers, Implementing Regulation (EU) 2024/2690 is concrete: the security policy must record its formal approval by the management bodies and be reviewed by them at least annually; at least one person must report directly to the management bodies on security; and risk assessment results and residual risks must be accepted by the management bodies or by accountable persons with authority to manage risks.

Mandatory training: for directors, encouraged for staff

Article 20(2) distinguishes two audiences. Members of management bodies "are required to follow training". For employees, Member States "shall encourage" entities to offer similar training "on a regular basis". The stated purpose is for participants to "gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity."

Separately, Article 21(2)(g) makes "basic cyber hygiene practices and cybersecurity training" one of the minimum measures for the whole organization. The 2024 Implementing Regulation asks in-scope digital providers to run an awareness program for employees, "including members of management bodies". ENISA's June 2025 guidance suggests including management bodies in incident response tests where necessary, so they understand their role during an incident.

Personal liability and management bans

Beyond Article 20, Article 32(6) requires Member States to ensure that any natural person "responsible for or acting as a legal representative of an essential entity", on the basis of the power to represent it, take decisions for it or control it, "has the power to ensure its compliance", and that it is possible "to hold such natural persons liable for breach of their duties to ensure compliance." Article 33(5) applies this paragraph to important entities too.

The heaviest tool is reserved for essential entities. Under Article 32(5)(b), where earlier enforcement measures have proved ineffective and a deadline to remedy has passed, authorities can request that the relevant bodies or courts "prohibit temporarily any natural person who is responsible for discharging managerial responsibilities at chief executive officer or legal representative level" from exercising managerial functions in that entity. Recital 133 frames this as a last resort, applied only after other enforcement measures are exhausted and only until the entity remedies the deficiencies, with procedural safeguards including the presumption of innocence and the rights of the defense. It does not apply to public administration entities.

Corporate fines: essential vs. important entities

Article 34 minimum maximum fines for infringing Article 21 or 23

Essential entityImportant entity
Fixed amountMaximum of at least EUR 10,000,000Maximum of at least EUR 7,000,000
Turnover-basedMaximum of at least 2% of total worldwide annual turnoverMaximum of at least 1.4% of total worldwide annual turnover
RuleWhichever is higherWhichever is higher
Turnover basePreceding financial year, of the undertaking to which the entity belongsSame

Two words deserve attention. First, "at least": these are floors for the maximum that national law must allow, so national caps can be higher. Second, "the undertaking to which the essential entity belongs": the turnover base is not limited to the EU subsidiary. Worked example: a US group with EUR 2 billion in worldwide annual turnover owns an essential entity in the EU. 2% of EUR 2 billion is EUR 40 million, higher than EUR 10 million, so national law must allow a maximum of at least EUR 40 million. If the entity were important, 1.4% gives EUR 28 million, against the EUR 7 million floor.

Fines come on top of other measures: warnings, binding instructions, orders to comply with Articles 21 and 23, to implement audit recommendations or to make aspects of the infringement public, and, for essential entities, a monitoring officer (Articles 32(4) and 33(4)). Member States may also provide periodic penalty payments (Article 34(6)).

What raises or lowers the amount

Article 32(7), which also governs fines through Article 34(3), lists the factors. Serious infringements "in any event" include repeated violations, "a failure to notify or remedy significant incidents", failure to follow binding instructions, obstructing audits and "providing false or grossly inaccurate information". Authorities also weigh duration, prior infringements, damage, intent or negligence, mitigation, adherence to approved codes of conduct or certification, and cooperation.

Overlaps executives ask about

  • GDPR. If a GDPR supervisory authority fines the same conduct, the NIS2 authority does not impose an Article 34 fine for it, though other enforcement measures remain possible (Article 35(2)).
  • Criminal penalties. Article 36 leaves other penalties to Member States, and recital 132 says their nature, criminal or administrative, is determined by national law.
  • DORA. Where a sector-specific EU act such as DORA applies to financial entities, the Commission's 2023 guidelines state that Article 20 of NIS2 should not apply, since it is intrinsically linked to Article 21.

A board-level checklist

  1. Identify which group entities are essential or important, and in which Member States.
  2. Put the Article 21 measures on the board agenda for formal approval, and minute it.
  3. Set a reporting line: at least one person reporting directly to the management body on security (mandatory for in-scope digital providers).
  4. Schedule management-body training and keep attendance records; offer similar training to employees.
  5. Review the security policy at least annually and after significant incidents.
  6. Rehearse incident escalation with executives, including the 24-hour early warning decision.
  7. Ask counsel how each national transposing law implements Article 20 liability.

Transposition is uneven, which matters because liability is defined nationally. The Commission's tracker, consulted on 2 October 2026, reports reasoned opinions sent to 19 Member States on 7 May 2025 and the referral of Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026. The NIS2 knowledge base lets you check the directive's wording directly, for example by asking "Can our CEO personally be held liable if the company fails to comply with NIS2's cybersecurity measures?"

Brief your board with cited answers

The NIS2 knowledge base answers questions on management liability, training and fines with the exact passages from the directive and its implementing texts.

Source: Directive (EU) 2022/2555 on EUR-Lex. This article explains the EU framework; personal liability depends on national law and is not legal advice.

Frequently asked questions

Can a CEO be personally liable under NIS2?

The directive requires that management bodies can be held liable for the entity's infringements of Article 21 (Article 20(1)), and that natural persons representing or controlling an entity can be held liable for breach of their duties to ensure compliance (Article 32(6), applied to important entities by Article 33(5)). The form of liability is set by national law.

Is NIS2 training mandatory for board members?

Yes. Article 20(2) requires members of the management bodies of essential and important entities to follow training. Similar training for employees is encouraged, on a regular basis, but not mandated by that article.

What are the maximum NIS2 fines?

For infringements of Article 21 or 23, national law must allow a maximum of at least EUR 10 million or 2% of total worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities, whichever is higher (Article 34).

Can a manager be banned under NIS2?

For essential entities only, Article 32(5)(b) allows authorities, after other measures have failed and a deadline has passed, to request a temporary prohibition on a person at CEO or legal-representative level exercising managerial functions in that entity, until the deficiencies are remedied.

Is the NIS2 fine based on the subsidiary's or the group's turnover?

Article 34 refers to the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs.

Get the Kopik newsletter

New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.

By subscribing you agree to receive our newsletter. We never share your address.