News

Article 20 in Practice: What Board-Level NIS2 Training Should Cover

NIS2 doesn't just ask your board to approve a policy once — it requires ongoing oversight and training. Here's what that actually looks like.

By Auditra Team · Published · Updated

Article 20 is the shortest operative article in NIS2 and the one that changes behaviour the most. It puts three duties on the management body of every essential and important entity: approve the cybersecurity risk-management measures taken under Article 21, oversee their implementation, and follow training so that members can identify risks and assess cybersecurity risk-management practices. Member states must also ensure that management bodies can be held liable for infringements — and for essential entities, supervisors can seek a temporary ban on a chief executive or legal representative exercising managerial functions until a breach is remedied.

Approval is a decision, not a signature

Approving the measures means the board understands what it is approving. In practice that is a documented agenda item with the risk assessment, the measures chosen, the residual risk accepted and the reasoning behind proportionality — the same reasoning a supervisor will ask for. Oversight then has to be recurring: a standing report on incidents, open findings, test and restore results, supplier risk and the status of remediation, at a cadence the board sets in advance rather than after an incident.

What the training should actually contain

Generic awareness e-learning does not meet Article 20. Board training should be built around four things. First, the organisation's own risk profile: which services matter, what would disrupt them, and what the realistic threat scenarios are. Second, the ten Article 21 measures at summary level — enough to ask whether each is addressed and how, without turning directors into engineers. Third, the incident reporting obligations, including the 24-hour, 72-hour and one-month stages and the board's own role when an incident escalates: who decides, who speaks, who is available out of hours. Fourth, the liability position itself, so the duty is understood as a personal one.

Set a recurring cadence — typically annual training plus a short refresh whenever the risk picture or the regulatory position changes materially — and keep attendance records, agendas and materials. Training that is not evidenced is, for supervisory purposes, training that did not happen.

Where to go next

The underlying controls a board is asked to approve are set out in the ten Article 21 measures, and the NIS2 Starter Kit provides the editable policy set behind them — the documents that actually go to the board for approval.

Related reading

Related

NIS2 penalties and management liability — the full reference page behind this article.

← All news