Skip to content
CyberNIS2

Glossary

Management Accountability

A major shift under NIS 2: cyber compliance now personally engages the legal and financial liability of executives, not just that of the legal entity.

Management accountability is a major shift introduced by NIS 2: responsibility for cyber compliance no longer rests solely with the company as a legal entity — it now personally engages the legal and financial liability of its executives (managers, board members). They have a legal obligation to approve security measures and undergo training dedicated to cyber threats.

What the directive says

Article 20 of NIS 2 requires the management bodies of essential and important entities to:

  • Approve the cybersecurity risk-management measures implemented by the entity.
  • Oversee their effective implementation.
  • Undergo training specific to cyber threats so they can make informed decisions.
  • Be held personally accountable in the event of proven failures to comply with the directive's obligations.

Practical implications

  • A CEO, managing director or board member can be held personally liable for a sanction imposed on their company for NIS 2 non-compliance.
  • In the most serious cases, competent authorities can impose a temporary ban from holding management positions.
  • Delegating cybersecurity to the CISO alone is no longer enough — management must be actively involved and trained.

Best practice

Appoint a NIS 2 lead within senior management, document cyber governance decisions, and keep evidence of executive training.