Skip to main content
NIS2 BOARD ACCOUNTABILITY

Article 20 makes this personal. Your accountability trail should too.

NIS2 Article 20 requires management bodies to approve the cybersecurity risk-management measures an entity takes, oversee their implementation, and can be held liable for infringements. Article 20(2) specifically requires management-body members to follow training sufficient to identify and assess cyber risk.

This is the clause that moves cyber risk from the IT budget line onto the people in the room where it is decided. And it changes what "oversight" has to mean: an approval minuted once a year is a document, not oversight. A defensible trail shows what was approved, when, on what evidence — and what changed between one approval and the next.

Who these duties bind

The management bodies of essential and important entities alike. The training obligation in Article 20(2) sits on the members personally: each must be able to identify and assess cyber risk, which in practice means the board pack has to be readable by someone whose job is not security.

What Article 20 asks

NIS2 Article 20 · the management-body obligations
The obligationWhat it means in practice
Approve the risk-management measuresA decision, on record, that can be pointed to — not a policy nobody dates
Oversee their implementationContinuous sight of whether the approved measures actually run — not an annual attestation
Training sufficient to identify and assess riskMembers demonstrably equipped to read what is put in front of them
Liability for infringementsThe trail is the defense: approvals, evidence and timing, attributable

What it asks, in operating terms

NIS2 board accountability · how TruSecure answers it
What Article 20 asksWhere it is answered
Approve measures on the recordBoard reporting · timestamped, attributable approvals
Oversee implementation continuouslyBoard reporting · risk, control, incident and supplier data rolled up from live state
Show what changed since the last approvalEvidence automation · every figure opens to the control and the evidence behind it
Give members material they can assessBoard reporting · board-ready views, not console telemetry

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what an accountability trail is made of:

NIS2 accountability trail · board excerptSample data
Measures approved
12 Feb 2026 · resolution referenced
Oversight cycle
quarterly · from live control state
Management training
current · refresh scheduled
Open risks carried to board
3 · appetite decisions attached
Evidence
sealed · sha256:4d19…c630

Where teams usually start

With a demo walked through by TruSecure — the board-ready views, an approval trail with timestamps, and the same record an examiner would ask to see. Onboarding then produces the first board-ready accountability pack; the subscription keeps it generated from live state, cycle after cycle.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 Article 20 requires management bodies to approve and oversee cybersecurity risk-management measures, can hold them personally liable, and requires management-body members to undergo training to identify and assess cyber risk. TruSecure records every approval as a continuous accountability trail.