Glossary · Term

Governance explained

Governance covers leadership, responsibilities and decision structures for security and compliance – under NIS2 expressly a duty of the management body.

At a glance
Meaning
Leadership, responsibility and decision structures
Link to NIS2
Cybersecurity is a leadership duty
Liability
Management bodies can be held liable
Related
GRC, management body
Updated
June 2026
Editorial team
Compliance Compass

What is governance?

Governance describes the overarching steering level of an organisation: it sets out who is responsible for security and compliance and how decisions are taken, approved, documented and monitored. Governance makes sure that security is steered deliberately and not left to chance or to individual IT staff. In contrast to the concrete work of Risk management, which deals with individual risks, governance sets the frame: objectives, roles, responsibilities and reporting lines. It is the strategic bracket around risk management and compliance.

Governance under NIS2

NIS2 makes cybersecurity expressly a task for the leadership. Under Article 20 the management body must approve the risk management measures, oversee their implementation and take part in regular training itself. The directive thereby moves cybersecurity from a purely technical question to a leadership and oversight task. Governance is the mechanism that translates these legal expectations into concrete responsibilities, approval processes and evidence – the precondition for an organisation being able to demonstrate its NIS2 duties in an audit-proof way.

Liability of the management body

Responsibility can no longer be handed downwards. Article 20 provides that the members of the management body can be held liable for infringements; on top of that, Article 34 sets minimum fine ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, whichever is higher, and Member States may set higher amounts. Because the directive has applied since 18 October 2024 and each Member State transposes it on its own timetable, the management body should be able to show that it has not simply nodded measures through once, but has approved them, overseen them and, where necessary, adjusted them on an ongoing basis. Operational tasks may sit with IT. The ultimate responsibility stays at the top. Good governance lowers the liability risk, because decisions, approvals and controls are documented without gaps.

Governance, risk and compliance

Governance is the first pillar of GRC. Together with risk management and compliance with legal duties it forms the frame for compliance that is actually lived – written down in Security policies. Picture a mid-sized energy supplier that sets up a quarterly security committee once NIS2 applies to it: the management has the risk status reported there, approves measures and minutes every decision, and those minutes later serve as evidence. Talking alone is not enough. Only the minutes turn an intention into solid proof that cybersecurity really is steered at leadership level.

What do you need to do?

Governance stays abstract until it is translated into meetings, approvals and minutes. These five steps make a start:

Who decides, who implements?

Governance depends on clearly assigned roles. The overview below separates the decision from the implementation:

TaskDecidesImplements
Approve risk management measuresmanagement bodyCISO / IT security
Oversee implementationmanagement bodyCompliance / internal audit
Operate technical protective measuresCISO / head of ITIT team / service provider
Notification to the competent authority (24 h / 72 h / 1 month)management bodyIncident response / reporting officer

Further reading: European Commission – NIS2 Directive

Frequently asked questions

What does governance mean?

Governance covers the leadership, responsibility and decision structures with which an organisation steers security and compliance. It sets out who carries which risks, who approves measures and how their effectiveness is monitored and documented. Governance is therefore the strategic bracket around risk management and compliance. It makes sure that security is steered deliberately and not left to chance or to individual IT staff – with clear objectives, roles and reporting lines.

Why does governance matter under NIS2?

The NIS2 Directive puts the leadership expressly under obligation. Article 20 requires the management body to approve the risk management measures, to oversee their implementation and to take part in regular training. Cybersecurity thereby moves from a purely technical question to a leadership task. Article 34 sets minimum fine ceilings of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts. On top of that, members of the management body can be held liable for infringements.

Can cybersecurity be delegated to IT?

Operational measures can be delegated to the IT team or to service providers, but the ultimate responsibility for cybersecurity cannot. It stays with the management body, which has to understand, steer and evidence security even when the technical work sits elsewhere. NIS2 requires the leadership to approve measures and to oversee their implementation. Good governance lowers the liability risk, because decisions, approvals and controls are documented without gaps and can therefore be produced in an inspection.

Governance

Approvals you can prove later

Compliance Compass records every leadership decision, every approval of measures and every training certificate – so that you can evidence the responsibility of your management body instead of risking it.