- Meaning
- Company leadership / managing directors
- Duty under NIS2
- Approve measures and oversee them
- Training
- Mandatory
- Liability
- Members can be held liable
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is the management body?
The Management body (the directive speaks of management bodies) is the leadership level of an organisation – the managing directors, the board or comparable governing bodies. Under NIS2 it carries the ultimate responsibility for the cybersecurity of the whole entity. The directive thereby names a concrete, accountable address: cybersecurity is no longer a purely technical matter but a duty of leadership and oversight. The management body is therefore the human anchor of Governance – the point at which responsibility for risks and measures finally comes together.
The concrete duties
- Risk management measures: approve and sign them off
- Their implementation: oversee it
- Mandatory training: take part in it
Responsibility and liability
What is new compared with NIS1 is that the directive addresses the management level explicitly: under Article 20(1) of the NIS2 Directive, management bodies must approve the risk management measures, oversee their implementation, and for infringements by the entity they can be held liable. Whether that leads to a personal claim in an individual case, and on what scale, is determined by national law; this page takes no position on any particular national liability standard. Irrespective of that, the entity faces fines. Article 34 sets minimum ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, whichever is higher, and Member States may set higher amounts. Cybersecurity can therefore no longer be handed over to IT in full – the operational implementation can be, the responsibility stays at the top.
⚠ Note on the responsibility of the management bodyA board decision along the lines of "IT will take care of it" does not discharge the duty: approval and oversight are expressly tasks of the management body and cannot be delegated away. Anyone who neither approves measures nor demonstrably oversees them cannot plead ignorance once damage occurs. Whether and to what extent personal liability arises is decided by national company and supervisory law, on the facts of the individual case. This article is general orientation and does not replace legal advice.
The duties of the leadership in plain words
What the leadership has to do – and what it should avoid:
- Do: Actively approve the risk management measures and minute the approval.
- Do: Take part in the mandatory training yourself, do not only send staff.
- Do: Have implementation and effectiveness reviewed regularly and reported back to you.
- Do not: Push responsibility wholesale to the IT department – what can be delegated is the implementation, not the ultimate responsibility.
- Do not: Put cybersecurity on the agenda only after an incident has happened.
- Do not: Give approvals verbally, without documenting them in a traceable way.
What this means in practice
The management body has to understand security, not implement it itself. Readable reports, clear decision papers and traceable evidence are decisive for that. The management of an IT service provider, for example, can have a risk report put in front of it every quarter, approve the prioritised measures in that meeting and document its attendance at training. Documented approvals of this kind are at the same time the evidence that the leadership has actually met its legal duty to approve and to oversee. If a significant incident occurs, the NIS2 reporting chain also applies, with an early warning within 24 hours, an incident notification after 72 hours and a final report after one month – processes whose functioning the leadership is answerable for.
Next steps
Four points for the next leadership meeting:
- Check whether your entity has to register – the registration duty and its deadline are set by each Member State, so ask the authority responsible for you which channel and which date apply.
- Put cybersecurity on the standing agenda of the leadership meeting.
- Set out in writing how responsibilities are divided between the leadership, IT security and the business units.
- Schedule and document your own attendance at training.
Cybersecurity therefore belongs in the standing agenda of the leadership rather than being handled whenever something goes wrong. Recurring agenda items on the risk situation, the status of measures and open incidents create continuous engagement and relieve the leadership if liability is ever at issue. That is what counts when it matters. Anyone who also sets out in writing how responsibilities are divided between the management, IT security and the business units keeps delegation and ultimate responsibility cleanly apart, and turns an abstract NIS2 duty into a traceable leadership process that visibly carries the security of the entity and stays provable in an inspection.
Further reading: European Commission – NIS2 Directive
Frequently asked questions
What is the management body under NIS2?
The management body is the leadership level of an organisation, for example the managing directors, the board or a comparable governing body. Under Article 20 of NIS2 it has to approve the risk management measures, oversee their implementation and take part in mandatory training. The management body therefore carries the ultimate responsibility for the cybersecurity of the whole entity, which the directive treats expressly as a duty of leadership and oversight and no longer as a purely technical matter.
Can the management be held liable under NIS2?
Article 20(1) of the NIS2 Directive requires management bodies to approve the risk management measures and oversee their implementation, and provides that they can be held liable for infringements by the entity. Whether personal liability follows, and in what amount, is determined by the national law of the Member State concerned. The entity itself faces fines: Article 34 sets minimum ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts. The operational work can be delegated; the ultimate responsibility of the management body remains.
Does the leadership have to implement security itself?
No. The technical implementation of the security measures can be delegated to the IT department or to service providers. The management body does, however, have to understand the measures, formally approve them and oversee their implementation, and it has to take part in mandatory training so that it can judge risks and take informed decisions. Documented approvals serve at the same time as evidence that the leadership has met its legal duty to approve and to oversee.