NIS2 doesn't treat board cyber competence as good governance advice. It's a personal, individual obligation on every management body member, not a policy the board simply signs off. Article 20 writes a direct training duty into law, on top of a separate approval-and-liability obligation that makes untrained approval a governance failure in its own right. In this article, we explore exactly what the text requires in terms of Board Cyber Crisis Training.
Article 20 of the NIS2 Directive is titled "Governance," and it sets out two distinct duties for the management bodies of essential and important entities. The first is approval and accountability:
"Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article."
The second, in the very next paragraph, is the training mandate:
"Member States shall ensure that the members of the management bodies of essential and important entities are required to follow training, and shall encourage essential and important entities to offer similar training to their employees on a regular basis, in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity."
Three details matter here:
Article 20(1) makes something easy to miss explicit: the management body "can be held liable for infringements by the entities" of Article 21. Approval isn't a formality — it's the point at which personal liability attaches. A board that approves cybersecurity risk-management measures without the knowledge Article 20(2) requires is approving something it cannot genuinely assess, which is exactly the gap Article 20 was written to close.
Article 21 sets out what the board is actually approving — the cybersecurity risk-management measures entities must take, covering areas including:
An untrained board asked to approve measures across all ten of those areas is, in practice, approving a document it cannot meaningfully interrogate — which undermines the "oversee its implementation" language in Article 20(1) just as much as the approval itself.
Article 20 is not a box-ticking exercise on paper. Supervisory reviews test whether the board's engagement was substantive. In practice, that means being able to answer questions such as:
Every one of these questions assumes a board capable of engaging with the substance, not just the signature line, which is precisely the competence Article 20(2)'s training requirement exists to build.
NIS2 doesn't prescribe a curriculum, but the wording of Article 20(2) points to a specific, applied competence rather than general awareness:
This is exactly the gap purpose-built executive training is designed to close, rather than a generic compliance module. Cybersecurity Training for Executives is built directly around the regulatory drivers behind NIS2 Article 20 and DORA's equivalent provisions, while the Board Cyber Crisis Programme tests that competence under realistic tabletop pressure, surfacing exactly the decision-making and crisis communication gaps Article 20(1)'s liability exposure makes costly to discover for the first time during a real incident.
Article 20(1) makes the board directly responsible for overseeing implementation of the cybersecurity risk-management measures it approves — and NIS2's incident reporting obligations, with their 24-hour, 72-hour and one-month deadlines, sit squarely inside those measures. A board can't oversee something it hasn't engaged with, and that's harder when the underlying documentation is scattered rather than structured for review.
The NIS2 Incident Response Document Library maps the 146 documents behind a complete NIS2 incident response programme, including the 15 mandatory artefacts a board should recognise on sight, the incident response plan and the reporting templates for each deadline chief among them. The NIS2 Master Document Register gives the board a single maintained view of ownership and review status to work from at each periodic approval cycle, rather than approving a policy set it has never actually reviewed line by line.
1. Does NIS2 legally require cybersecurity training for board members?
Yes. Article 20(2) requires the members of the management bodies of essential and important entities to follow training, so that they gain sufficient knowledge and skills to identify cybersecurity risks and assess risk-management practices and their impact on the entity's services.
2. What exactly does NIS2 Article 20 require of the board?
Article 20 has two parts. Article 20(1) requires the management body to approve the entity's cybersecurity risk-management measures, oversee their implementation, and accept liability for infringements. Article 20(2) separately requires every management body member to follow training that builds real risk-identification and assessment competence.
3. Is staff training mandatory under NIS2, or only board training?
Board training is mandatory language... "are required to follow training." Staff training is framed more softly: entities are "encouraged" to offer similar training to employees on a regular basis. Board-level training carries the stricter legal obligation.
4. Can board members be held personally liable under NIS2 for cybersecurity failures?
Article 20(1) states that management bodies can be held liable for the entity's infringements of Article 21's risk-management measures, without prejudice to national liability rules for public institutions and officials. This liability exposure is a core reason the accompanying training duty in Article 20(2) exists.
5. How often should NIS2 board training be repeated?
NIS2 doesn't fix an interval for board training the way it does for incident reporting deadlines, but Article 20(2)'s framing of staff training "on a regular basis" reflects the same underlying expectation — training needs to be refreshed as risks, regulations and the entity's operations evolve, not delivered once at appointment.
6. What's the difference between approving cybersecurity measures and understanding them?
Approval under Article 20(1) is a governance act with liability attached; understanding is the competence Article 20(2)'s training requirement is designed to guarantee before that approval happens. Supervisory reviews assess whether approvals reflect genuine engagement with the entity's risk profile, not just a signature.
7. Which cybersecurity risk-management measures does the board actually need to understand?
The ten measure areas set out in Article 21, including risk analysis, incident handling, business continuity, supply chain security, secure systems development, effectiveness assessment, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication and secure communications.
8. How does NIS2 board training connect to incident response documentation?
The board's oversight duty under Article 20(1) extends to the cybersecurity risk-management measures it approves, which include incident handling and the reporting obligations behind NIS2's 24-hour, 72-hour and one-month deadlines. Training needs to leave the board able to engage with that actual documentation, not just discuss cybersecurity risk in the abstract.