NIS2 Management Body Liability: What UK Directors of EU Entities Need to Know
Under NIS2, cyber security is a board matter by law. The management bodies of essential and important entities must approve the Article 21 risk-management measures, oversee their implementation and can be held liable for the entity's infringements (Article 20(1)). Their members must undertake training (Article 20(2)). Persons representing or controlling an entity can be held liable for failing to ensure compliance, and for essential entities a temporary management ban is available as a last resort. Corporate fines must be capable of reaching at least EUR 10 million or 2% of worldwide turnover for essential entities, and EUR 7 million or 1.4% for important ones.
Why this matters to a UK board
NIS2, Directive (EU) 2022/2555, is EU law. A UK parent is not itself regulated by it simply for being the parent, but its EU subsidiaries may be essential or important entities, and their management bodies, which often include directors or executives based in the UK, carry the Article 20 duties under the law of the Member State concerned. UK domestic rules on directors' duties are not among the sources of the NIS2 knowledge base and are not discussed here.
There is also a group-level financial point: NIS2 fines are calculated on the worldwide turnover of "the undertaking to which the essential entity belongs" (Article 34(4)), which in practice draws the group's figures into the calculation.
Approve, oversee, answer for: the Article 20 duties
Article 20(1) requires Member States to ensure that management bodies "approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article." Recital 137 gives the rationale: a high level of responsibility for cyber security measures and reporting "at the level of the essential and important entities".
The measures the board approves are the ten minimum elements of Article 21(2):
- policies on risk analysis and information system security;
- incident handling;
- business continuity, such as backup management and disaster recovery, and crisis management;
- supply chain security;
- security in acquisition, development and maintenance, including vulnerability handling and disclosure;
- policies and procedures to assess the effectiveness of the measures;
- basic cyber hygiene practices and cybersecurity training;
- policies on cryptography and, where appropriate, encryption;
- human resources security, access control policies and asset management;
- multi-factor or continuous authentication, secured communications and secured emergency communication systems, where appropriate.
Evidence a supervisor may expect
For the digital providers covered by Implementing Regulation (EU) 2024/2690 (cloud, data centre, managed services and others), the board's role is spelt out: the security policy records its formal approval by the management bodies and is reviewed by them at least annually; at least one person reports directly to the management bodies on security; and risk assessment results and residual risks are accepted by the management bodies or accountable persons. ENISA's June 2025 guidance lists records of such approvals among its examples of evidence.
Director training is compulsory
Article 20(2): members of management bodies "are required to follow training"; Member States "shall encourage" entities to offer similar training to employees "on a regular basis". The objective is that they gain "sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity".
The directive does not prescribe a syllabus or frequency for director training; check the national transposing law. The Implementing Regulation, for the digital providers it covers, requires an awareness-raising programme for employees "including members of management bodies", and ENISA's guidance recommends involving management bodies in incident response tests where necessary.
Personal exposure: liability and management bans
Personal measures under NIS2
| Measure | Essential entities | Important entities |
|---|---|---|
| Management body can be held liable for Article 21 infringements (Art. 20(1)) | Yes | Yes |
| Persons representing or controlling the entity can be held liable for breach of duty to ensure compliance (Art. 32(6)) | Yes | Yes, via Art. 33(5) |
| Temporary prohibition from managerial functions at CEO or legal-representative level (Art. 32(5)(b)) | Yes, as a last resort | Not provided |
| Monitoring officer appointed to oversee compliance (Art. 32(4)(g)) | Yes | Not provided |
The management ban is tightly framed. It is available only where earlier enforcement measures have been ineffective and the entity has missed a deadline to remedy; it lasts only until the deficiencies are fixed; and recital 133 calls it a measure of last resort subject to procedural safeguards, including the right to an effective remedy, a fair trial, the presumption of innocence and the rights of the defence. It does not apply to public administration entities.
Fines: how the ceiling is set
Article 34 sets minimum ceilings that national law must provide for infringements of Article 21 (risk-management measures) or Article 23 (reporting):
- Essential entities: a maximum of at least EUR 10,000,000 or at least 2% of total worldwide annual turnover in the preceding financial year, whichever is higher.
- Important entities: a maximum of at least EUR 7,000,000 or at least 1.4% of that turnover, whichever is higher.
Worked example. A UK group with EUR 300 million worldwide turnover owns an essential entity in the EU. 2% of EUR 300 million is EUR 6 million, lower than EUR 10 million, so the fixed figure governs: national law must allow a fine of at least EUR 10 million. Were the entity important, 1.4% is EUR 4.2 million, so the EUR 7 million figure governs. For larger groups the percentage takes over: at EUR 1 billion, 2% is EUR 20 million.
When setting a fine, authorities must have regard to the Article 32(7) factors (Article 34(3)). Serious infringements include repeated violations, failure to notify or remedy significant incidents, ignoring binding instructions, obstructing audits, and giving false or grossly inaccurate information. Mitigating considerations include measures taken to limit damage, adherence to approved codes of conduct or certification mechanisms, and cooperation with the authorities.
Interaction with other regimes
- GDPR: where a data protection authority has already fined the same conduct, the NIS2 authority does not impose an Article 34 fine for it (Article 35(2)).
- Other penalties: Article 36 requires national penalties for other infringements; recital 132 leaves their criminal or administrative nature to national law.
- DORA: for financial entities under DORA, the Commission's 2023 guidelines say Article 20 of NIS2 should not apply, being intrinsically linked to Article 21.
Agenda items for the next board meeting
- Confirm which EU entities are in scope, whether essential or important, and the Member State with jurisdiction.
- Table the Article 21 measures for formal approval and minute the decision.
- Agree a reporting line on cyber security to the management body and a reporting frequency.
- Book director training and record attendance; plan staff training.
- Walk through the escalation path for a significant incident and the 24-hour early warning.
- Ask EU counsel how each relevant national law implements Article 20 liability and Article 34 fines.
National implementation is still uneven: on the Commission's transposition page, consulted on 2 October 2026, the latest news is the referral of Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026 for failing to notify transposition measures. Check the Commission's tracker for each country where you have an entity.
Prepare your board briefing with cited answers
Ask the NIS2 knowledge base questions such as "Are managers legally required to attend cybersecurity training, or is it just recommended?" and get the exact article in return.
The authoritative text is Directive (EU) 2022/2555 on EUR-Lex. This briefing explains the EU framework and is not legal advice on any director's position.
Frequently asked questions
Are directors personally liable under NIS2?
Article 20(1) requires that management bodies can be held liable for the entity's infringements of Article 21, and Article 32(6) requires that persons representing or controlling an entity can be held liable for breach of their duties to ensure compliance. How that liability operates is a matter for national law.
Do board members have to take cyber security training under NIS2?
Yes. Article 20(2) requires members of the management bodies of essential and important entities to follow training; offering similar training to employees is encouraged.
What is the maximum NIS2 fine for an important entity?
National law must allow a maximum of at least EUR 7 million or 1.4% of total worldwide annual turnover in the preceding financial year, whichever is higher (Article 34(5)).
Can NIS2 authorities remove a chief executive?
For essential entities, Article 32(5)(b) allows authorities, after other measures have failed and a remedial deadline has passed, to request a temporary prohibition on exercising managerial functions at CEO or legal-representative level, lasting until the deficiencies are remedied.
Does NIS2 Article 20 apply to banks under DORA?
According to the Commission's 2023 guidelines on Article 4, Article 20 should not apply where a sector-specific act such as DORA governs cyber security risk management, because it is intrinsically linked to Article 21.
Get the Kopik newsletter
New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.
By subscribing you agree to receive our newsletter. We never share your address.