For many executive teams, NIS2 still feels like a security project. That is a misconception. The legislation raises the bar not only for technical measures, but for board-level involvement, demonstrable oversight, and well-founded decision-making.
Why NIS2 Hits the Boardroom
NIS2 does something earlier cybersecurity rules did not: it puts the management body itself on the hook. Under Article 20 of the directive, boards, executive committees, and equivalent governing bodies of essential and important entities must approve cybersecurity risk-management measures, oversee their implementation, and can be held personally liable when things go wrong. Recital 137 of the directive stresses the need for a high level of responsibility for cybersecurity risk management, requiring that measures be approved and their use supervised by the management body itself.
That is a deliberate shift. Ahead of the transposition deadline, the European Commission estimated that fewer than a quarter of boards in newly in-scope entities had any formal cybersecurity oversight mechanism in place. For most of those organizations, cybersecurity was a budget line the board approved once a year, not a topic it actively governed. NIS2 ends that arrangement — and it does so with consequences attached.
What NIS2 Really Asks of Governance
Article 20 is short, but it creates obligations that touch nearly every part of how a board operates. Management bodies of essential and important entities must approve cybersecurity risk-management measures, oversee their implementation, and can be held personally liable for breaches — a requirement that is not optional and cannot be delegated away. A board can hand day-to-day security work to a CISO or a risk committee, but the legal duty to approve, oversee, and be trained stays with the board itself.
The training obligation is often underestimated. Members of the management body must undergo training sufficient to identify cybersecurity risks, assess how the organization manages them, and evaluate the impact of those risks and measures on the services the entity provides. This is not a one-off awareness session; supervisory authorities increasingly expect it to be a recurring, documented part of board life.
Liability is where the shift becomes concrete for individual directors. Several national transpositions allow competent authorities to seek a temporary ban on a director or legal representative from holding managerial functions, alongside fines that can reach into the millions of euros. The trend across member states, as national laws are finalized, is toward strengthening — not softening — this personal accountability.
Group structures add a further wrinkle. Where cybersecurity decisions are made centrally at a global headquarters, NIS2’s requirement that local management bodies both approve and supervise implementation can fragment decision-making across a group, pushing many organizations toward a hybrid model that keeps ultimate accountability at the local entity while allowing day-to-day execution to sit centrally.
From Duty of Care to Evidence: Which Documentation Counts
A board that has “discussed cybersecurity” is not the same as a board that can prove it exercised oversight. Supervisory authorities are not asking whether the topic came up — they are asking for the paper trail.
Auditors increasingly expect documented evidence that the board formally reviewed and approved the organization’s risk-management measures, and that it discussed specific, named risks — supply chain exposure, incident readiness, concrete threat scenarios — rather than a generic cybersecurity update on the agenda. A single line in the minutes saying “cybersecurity was discussed” will not hold up under scrutiny.
It is advisable to ensure that board approvals under Article 20 are properly recorded — in board resolutions or meeting minutes — since competent authorities are likely to request this documentation as part of a compliance assessment, and may also ask senior managers for formal attestations regarding the organization’s cybersecurity risk management.
Training records matter just as much as approval records. Among the categories of evidence a board is typically asked for, proof that relevant individuals actually acknowledged and completed required training is often the weakest link — not because the training didn’t happen, but because there is no immutable, timestamped, person-specific record that it did. A description of a training program is not evidence. A dated, individually attributable completion record is.
This is also where operational guidance is starting to fill in the gaps left by the directive’s high-level language. ENISA’s June 2025 Technical Implementation Guidance — a roughly 170-page companion to the EU’s Implementing Regulation — sets out, for thirteen thematic areas, not just what a measure should achieve but concrete examples of the evidence an organization can show an assessor. Boards do not need to read all of it, but their compliance and risk teams should be treating it as the de facto evidence checklist.
Which Decisions Leadership Needs to Take Now
Turning obligation into evidence is a leadership decision, not a technical rollout. Five decisions belong on the board agenda this quarter:
1. Confirm scope and classification. Determine formally — and document — whether the organization qualifies as essential or important, and under which national transposition. In the Netherlands, this determination now has a hard deadline attached (see below); in Belgium it has already been operational for some time.
2. Formally approve the risk-management measures. Not a rubber stamp on an IT proposal, but a documented board decision referencing the specific measures being adopted, minuted in a way that would satisfy an auditor.
3. Commission board-level training — and record it. Schedule cybersecurity training for management body members specifically, distinct from general staff awareness training, with individual, dated completion records.
4. Establish a standing reporting rhythm. Move cybersecurity from an occasional agenda item to a recurring one, with defined metrics the board actually reviews (see the KPI section below).
5. Decide the certification or verification pathway. Determine whether existing ISO 27001 certification, a national framework such as CyFun, or a fresh verification path is the right route to demonstrable compliance — a decision explored in the next section.
Each of these is a governance action, not a technical one. A CISO can prepare the material; only the board can make — and be seen to have made — the decision.
When External Verification or Certification Becomes Relevant
At some point, internal assurance stops being enough — either because the entity’s risk tier demands independent confirmation, or because the board wants a defensible answer when a regulator or a major client asks “how do you know?”
ISO 27001 is a voluntary international standard, while NIS2 is mandatory EU legislation, and ISO 27001 certification does not on its own guarantee NIS2 compliance — though its controls map closely to NIS2’s risk-management requirements and are explicitly recognized as compliance evidence in frameworks such as Belgium’s CyFun, Slovenia’s national guidelines, and ENISA’s own technical guidance. In practice, this means an existing ISO 27001 certificate is a strong starting point, but boards should ask their compliance function to confirm that its scope and Statement of Applicability genuinely cover what national NIS2 legislation requires — not assume it automatically does.
A targeted gap analysis against board accountability requirements, supply chain security, and crisis management is generally necessary, since these are areas an existing information security management system may not fully address. For organizations without an existing certification, a purpose-built national verification path — CyFun in Belgium being the clearest example — is often the faster, more directly mapped route to a recognized compliance status.
The decision of which path to pursue is ultimately a board-level risk and resourcing choice: how much assurance does the entity’s risk tier require, how quickly does that assurance need to be demonstrable, and how does that map onto capacity already built through existing certifications.
Board KPIs and Reporting Structure
Boards that treat cybersecurity as a governance topic need metrics that belong in a governance report, not a security operations dashboard. A workable structure typically includes:
- Coverage and classification status — confirmed entity classification, registration status with the relevant national authority, and scope boundaries.
- Measure implementation status — a concise view of which Article 21 measures are approved, in progress, and evidenced, against the risk-management baseline.
- Incident metrics — significant incidents reported within statutory notification windows, near-misses, and time-to-detection trends.
- Supply chain assurance — proportion of critical suppliers assessed, contractually bound to security and notification obligations, and re-assessed on a defined cycle.
- Governance evidence — training completion at board level, dates of formal approval decisions, and outstanding audit or verification findings with remediation status.
The purpose of this structure is not exhaustive reporting — it is defensibility. A board that can produce these five categories on request has, in effect, already assembled the evidence a supervisory authority or a verification body will ask for.
For organizations in the Netherlands, this reporting rhythm has a concrete trigger. The Dutch Senate approved the Cyberbeveiligingswet (Cbw) and the Wet weerbaarheid kritieke entiteiten on 7 July 2026, and both laws take effect on 15 August 2026, bringing new cybersecurity obligations for more than 8,000 organizations across eighteen sectors. There is no transition period: from the first day, all obligations apply, including registration, duty-of-care measures, and personal liability for directors, with fines that can reach €10 million or 2% of global annual turnover for essential entities, and €7 million or 1.4% for important entities. Boards whose reporting structure is not yet in place have a genuinely short runway to close that gap.
Dutch authorities have been explicit that organizations should not wait for the law to formally enter into force, since the underlying risks already exist today — early action leaves an organization both better protected now and better prepared for the legislation once it lands.
Conclusion
The question for boards is no longer whether cybersecurity belongs on the agenda — it is how quickly the topic gets translated into ownership, reporting, evidence, and a verifiable path to demonstrable compliance. NIS2 does not reward good intentions; it rewards organizations that can show, on request, exactly what was decided, by whom, when, and how it was verified. For most boards, that is less a technology gap than a governance one — and it is one that can be closed within a single quarter of deliberate decisions.
If your board is still working out where it stands on classification, verification pathway, or reporting structure, a short, no-obligation conversation is usually the fastest way to get clarity. Get in touch for a free intake and we’ll help map the most efficient path to demonstrable NIS2 governance.