Article 20 makes this personal. Your accountability trail should too.
NIS2 Article 20 requires management bodies to approve the cybersecurity risk-management measures an entity takes, oversee their implementation, and can be held liable for infringements. Article 20(2) specifically requires management-body members to follow training sufficient to identify and assess cyber risk.
This is the clause that moves cyber risk from the IT budget line onto the people in the room where it is decided. And it changes what "oversight" has to mean: an approval minuted once a year is a document, not oversight. A defensible trail shows what was approved, when, on what evidence — and what changed between one approval and the next.
Who these duties bind
The management bodies of essential and important entities alike. The training obligation in Article 20(2) sits on the members personally: each must be able to identify and assess cyber risk, which in practice means the board pack has to be readable by someone whose job is not security.
What Article 20 asks
| The obligation | What it means in practice |
|---|---|
| Approve the risk-management measures | A decision, on record, that can be pointed to — not a policy nobody dates |
| Oversee their implementation | Continuous sight of whether the approved measures actually run — not an annual attestation |
| Training sufficient to identify and assess risk | Members demonstrably equipped to read what is put in front of them |
| Liability for infringements | The trail is the defense: approvals, evidence and timing, attributable |
What it asks, in operating terms
| What Article 20 asks | Where it is answered |
|---|---|
| Approve measures on the record | Board reporting · timestamped, attributable approvals |
| Oversee implementation continuously | Board reporting · risk, control, incident and supplier data rolled up from live state |
| Show what changed since the last approval | Evidence automation · every figure opens to the control and the evidence behind it |
| Give members material they can assess | Board reporting · board-ready views, not console telemetry |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what an accountability trail is made of:
- Measures approved
- 12 Feb 2026 · resolution referenced
- Oversight cycle
- quarterly · from live control state
- Management training
- current · refresh scheduled
- Open risks carried to board
- 3 · appetite decisions attached
- Evidence
- sealed · sha256:4d19…c630
Where teams usually start
With a demo walked through by TruSecure — the board-ready views, an approval trail with timestamps, and the same record an examiner would ask to see. Onboarding then produces the first board-ready accountability pack; the subscription keeps it generated from live state, cycle after cycle.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 Article 20 requires management bodies to approve and oversee cybersecurity risk-management measures, can hold them personally liable, and requires management-body members to undergo training to identify and assess cyber risk. TruSecure records every approval as a continuous accountability trail.