INDEPENDENT NIS2 RESOURCEGovernance · Resilience · ImplementationEU framework / national application
HomeRequirementsManagement accountability
Article 20 / Requirement

Management accountability

Management bodies have a role in approving and overseeing cybersecurity risk-management measures and receiving relevant training.

What this means in practice

Translate the provision into accountable decisions and documented processes. The exact application depends on the entity, the relevant national law and any applicable sector-specific rules.

Implementation questions

  1. Assign leadership oversight
  2. Schedule reporting and training
  3. Record approvals and decisions

Evidence to organise

RecordWhat to check
Board or management minutesOwner, currency, approval and follow-up actions
Oversight reporting packOwner, currency, approval and follow-up actions
Training recordsOwner, currency, approval and follow-up actions
These are planning prompts, not an exhaustive legal checklist or proof of compliance.

Official sources and context

Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.