NIS2 Article 20 makes directors and senior management personally liable for cybersecurity failures. Fines reach €10M or 2% of global turnover. Here is exactly what the law requires — and how to protect yourself.
The NIS2 Directive (EU 2022/2555) entered into force on 16 January 2023, with member state transposition due by 17 October 2024. Its Article 20 introduces something that keeps many executives awake at night: personal liability for cybersecurity failures.
Unlike the GDPR, which fines the organisation, NIS2 targets the individuals in charge. If your organisation suffers a significant cybersecurity incident and you are a director, CEO, CISO, or equivalent, you may be held personally accountable — and the fines can be severe.
The directive covers approximately 100,000-150,000 medium and large entities across the EU across 18 critical sectors — from energy and transport to digital infrastructure and public administration.
Article 20 of NIS2 is the foundation of management liability. It states that member states must ensure that:
This is not a suggested best practice. It is a legal requirement with enforcement mechanisms.
The directive defines management bodies broadly:
| Role | Likely In Scope | Notes |
|---|---|---|
| CEO / Managing Director | ✅ Yes | Ultimate responsibility for cybersecurity governance |
| Board of Directors (executive) | ✅ Yes | Must approve risk measures and oversee implementation |
| CISO / IT Security Lead | ✅ Yes | Direct operational responsibility |
| CFO / Legal Counsel | ⚠️ Possibly | Where cybersecurity decisions fall under their remit |
| Non-executive directors | ⚠️ Depends on transposition | Some member states include oversight liability |
Member states have flexibility in transposition, so the exact scope varies. What is consistent: if you make decisions about cybersecurity strategy or budget, you are likely in scope.
The controversial provision is Article 20(3): "Member States shall ensure that management bodies can be held liable for non-compliance with the obligations referred to in paragraph 1."
This means:
| Entity Type | Maximum Fine | Also Applies To |
|---|---|---|
| Essential entities | €10,000,000 or 2% of total annual worldwide turnover (whichever is higher) | Personal liability under Art. 20 |
| Important entities | €7,000,000 or 1.4% of total annual worldwide turnover (whichever is higher) | Personal liability under Art. 20 |
These figures apply per incident. A single breach can trigger both an organisational fine and personal penalties against individual directors.
Member states may also impose criminal sanctions under national law, including disqualification from serving as a director for a period of time.
| Dimension | GDPR | NIS2 |
|---|---|---|
| Target of fines | Organisation (controller/processor) | Organisation + management individuals |
| Maximum fine | €20M or 4% of global turnover | €10M or 2% of global turnover (essential entities) |
| Personal liability | No (limited to Art. 82 for damages) | Yes (explicit Art. 20 provision) |
| Management training | Not required | Required (Art. 20(2)) |
| Decision oversight | Implied governance | Explicit board approval required |
The two frameworks are complementary. Many organisations fall under both regimes, meaning directors face dual liability exposure.
Based on NIS2 requirements and enforcement trends in early-adopting member states, here is what prudent management should do:
Create a board-level cybersecurity committee or assign cybersecurity as a standing agenda item. Document every meeting, every decision, and every resource allocation.
Under NIS2 Art. 21, risk assessments are mandatory. They must cover technical, operational, and organisational measures. Run free compliance scans regularly — they provide objective, timestamped evidence.
The board must formally approve cybersecurity measures. This should include: scope, budget, responsible persons, timelines, and incident response procedures.
Approval without follow-up is a liability risk. Establish reporting cadence: the CISO or equivalent reports to the board at least quarterly with metrics, incidents, and progress against the plan.
Article 20(2) explicitly requires management to complete cybersecurity training. This is not optional for staff only — the board itself must participate.
When a regulator investigates, the first thing they ask for is documentation. Here is what to maintain:
Article 20(2) requires: "Member States shall ensure that the management bodies of essential and important entities follow training ... to acquire sufficient knowledge and skills to enable them to identify and manage cybersecurity risks."
What constitutes "sufficient knowledge" in practice:
Training must be ongoing — a one-hour annual presentation is unlikely to satisfy the requirement. Directors should budget for recurring training as part of the cybersecurity programme.
You do not need to wait for your next board meeting to take action. The first step is understanding your current posture:
Free, no sign-up required. Checks HTTPS, cookie consent, privacy policies, security headers, forms, and legal pages against GDPR, NIS2, DORA, and EAA requirements.
Run free scan →Works on any platform: WordPress, Shopify, Webflow, Squarespace, Next.js — any URL.
If you are managing compliance for an organisation, EUComply Pro ($79/yr) provides auditor-ready PDF reports, continuous monitoring alerts, and compliance documentation that directly supports your NIS2 Art. 20 obligations.