Directive NIS2 European Union
Cart 0
Art. 20

Good security, no paperwork: the article 20 gap


· Cryptaguard · 6 min read

The organisations most exposed to NIS2 enforcement are not the ones with weak controls. They are the ones with strong controls that no management body has ever formally approved.

A specific obligation, not a statement of principle

Most of NIS2 is written as outcomes. Article 20 is not. It names three acts, each of which either happened or did not, and each of which leaves a record or fails to.

Art. 20(1)
Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article.
Directive (EU) 2022/2555

Approve. Oversee. Be liable. Then article 20(2) adds a fourth: follow training, and offer comparable training to staff.

Why this is where enforcement lands

Put yourself in a supervisor's position with finite inspection capacity. Assessing whether an entity's network segmentation is adequate takes specialist time and produces a contestable judgment. Asking for the minutes in which the management body approved the risk-management measures takes one email and produces a binary answer.

Governance evidence is cheap to request, hard to fabricate after the fact, and unambiguous. It is the natural first move, and it is the move for which mature security teams are least prepared — because the work was done, just never ratified.

The uncomfortable part

An organisation with excellent security and no documented board approval is in breach of article 20. The quality of the controls is not a defence to the absence of the decision.

What "approve" has to look like

A minuted decision, by the body that actually governs the entity, referring to an identifiable set of measures, on a date. Not a slide noted in passing. Not an email from the CISO saying the programme is on track. The three things an inspector will look for:

  1. A resolution or minuted decision naming what was approved — a risk assessment, a measures register, a policy set — with version and date.
  2. Evidence of oversight since: recurring reporting to the management body, with enough substance to show it was read and acted upon.
  3. Training records for the members of the management body themselves, not only for staff.

The second is the one that decays. Many entities approve once, during their NIS2 project, and then let the reporting lapse. Article 20 requires oversight of implementation, which is continuous by construction.

Liability is national, and the ban is not

Article 20 says management bodies "can be held liable", and leaves the form of that liability to national law. It therefore differs across the 27 — in some member states it attaches to existing directors' duties, in others it is a distinct administrative exposure.

What does not vary is article 32(6):

Art. 32(6)
Member States shall ensure that [...] competent authorities may [...] request that the relevant bodies or courts [...] temporarily prohibit any natural person exercising managerial responsibilities at chief executive officer or legal representative level in that essential entity from exercising managerial responsibilities in that entity.
Directive (EU) 2022/2555

This applies to essential entities, after other enforcement has failed. It is not a fine that a company absorbs. It removes a named individual from their role, which is why article 20 changed the tone of boardroom conversations in a way that the €10 million ceiling did not.

The fix is unglamorous

Nothing here requires new technology. It requires a decision to be taken by the right body, recorded properly, and refreshed on a cycle. For most organisations that is one agenda item, one template, and a recurring calendar entry.

The reason it does not happen is that it belongs to nobody: too administrative for the security team, too technical for the corporate secretary. Assigning it explicitly is most of the work.

What to do about it
  • Get a minuted management body decision that names the approved measures, with a version and a date.
  • Establish recurring cybersecurity reporting to that body, and keep the evidence it was considered.
  • Record training for the management body itself — article 20(2) is about them, not only about staff.
  • Assign ownership of this record explicitly. It falls between the security team and the corporate secretary, and lands with neither by default.
Cart 0