Cyber Security Blog

Does NIS2 Mandate Board Training? Articles 20 and 21 of NIS2 Explained

Written by Aditi Uberoi | 3 August 2026

NIS2 doesn't treat board cyber competence as good governance advice. It's a personal, individual obligation on every management body member, not a policy the board simply signs off. Article 20 writes a direct training duty into law, on top of a separate approval-and-liability obligation that makes untrained approval a governance failure in its own right. In this article, we explore exactly what the text requires in terms of Board Cyber Crisis Training

The Core Obligation: Article 20

Article 20 of the NIS2 Directive is titled "Governance," and it sets out two distinct duties for the management bodies of essential and important entities. The first is approval and accountability:

"Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article."

The second, in the very next paragraph, is the training mandate:

"Member States shall ensure that the members of the management bodies of essential and important entities are required to follow training, and shall encourage essential and important entities to offer similar training to their employees on a regular basis, in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity."

Three details matter here:

  • "Members," not "the board." As with the approval duty, this is worded at the level of the individual — every management body member is personally required to follow training, not just the board as a collective entity.
  • Board training is mandatory; staff training is encouraged. Article 20(2) draws a clear legal line — management bodies "are required" to train, while entities are merely "encouraged" to extend similar training to employees. This makes board training the stricter, non-discretionary half of the obligation.
  • Training exists to serve a specific purpose. It isn't generic awareness — it has to leave the board able to "identify risks and assess cybersecurity risk-management practices and their impact on the services provided," a working, applied competence rather than passive familiarity.

Why Approval Without Training Is a Governance Failure

Article 20(1) makes something easy to miss explicit: the management body "can be held liable for infringements by the entities" of Article 21. Approval isn't a formality — it's the point at which personal liability attaches. A board that approves cybersecurity risk-management measures without the knowledge Article 20(2) requires is approving something it cannot genuinely assess, which is exactly the gap Article 20 was written to close.

Article 21 sets out what the board is actually approving — the cybersecurity risk-management measures entities must take, covering areas including:

  • Risk analysis and information system security policies.
  • Incident handling.
  • Business continuity, backup management, and disaster recovery.
  • Supply chain security, including relationships with suppliers and service providers.
  • Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure.
  • Policies and procedures to assess the effectiveness of cybersecurity risk-management measures.
  • Basic cyber hygiene practices and cybersecurity training.
  • Policies and procedures regarding the use of cryptography and encryption.
  • Human resources security, access control policies and asset management.
  • The use of multi-factor authentication, secured communications and secured emergency communication systems.

An untrained board asked to approve measures across all ten of those areas is, in practice, approving a document it cannot meaningfully interrogate — which undermines the "oversee its implementation" language in Article 20(1) just as much as the approval itself.

What Supervisory Authorities Actually Check

Article 20 is not a box-ticking exercise on paper. Supervisory reviews test whether the board's engagement was substantive. In practice, that means being able to answer questions such as:

  • Did the board approve cybersecurity risk-management policies, strategies and measures consistent with the organisation's actual risk profile and legal obligations?
  • Were cybersecurity risks integrated into the organisation's broader enterprise risk management and governance framework?
  • Were material deficiencies, control weaknesses or audit findings identified, escalated, prioritised and remediated?
  • Were sufficient financial, technological and human resources allocated to implement and maintain cybersecurity risk-management measures?
  • Did the board receive regular reporting on the effectiveness of those measures?
  • Were governance decisions, risk assessments, resource allocation decisions and board deliberations appropriately documented and evidenced?

Every one of these questions assumes a board capable of engaging with the substance, not just the signature line, which is precisely the competence Article 20(2)'s training requirement exists to build.

What "Sufficient Knowledge and Skills" Looks Like in Practice

NIS2 doesn't prescribe a curriculum, but the wording of Article 20(2) points to a specific, applied competence rather than general awareness:

  • The ability to identify cybersecurity risks relevant to the entity's own operations and sector, not generic threat awareness.
  • Enough grounding in Article 21's measures to genuinely assess whether what's being approved is adequate, proportionate and properly resourced.
  • Understanding how a cybersecurity incident translates into service impact. The "impact on the services provided by the entity" language Article 20(2) specifically names.
  • Confidence to make and defend real decisions under pressure: escalation calls, disclosure decisions, and regulatory and stakeholder communication during a live incident.

This is exactly the gap purpose-built executive training is designed to close, rather than a generic compliance module. Cybersecurity Training for Executives is built directly around the regulatory drivers behind NIS2 Article 20 and DORA's equivalent provisions, while the Board Cyber Crisis Programme tests that competence under realistic tabletop pressure, surfacing exactly the decision-making and crisis communication gaps Article 20(1)'s liability exposure makes costly to discover for the first time during a real incident.

Where Board Training Meets Incident Documentation

Article 20(1) makes the board directly responsible for overseeing implementation of the cybersecurity risk-management measures it approves — and NIS2's incident reporting obligations, with their 24-hour, 72-hour and one-month deadlines, sit squarely inside those measures. A board can't oversee something it hasn't engaged with, and that's harder when the underlying documentation is scattered rather than structured for review.

The NIS2 Incident Response Document Library maps the 146 documents behind a complete NIS2 incident response programme, including the 15 mandatory artefacts a board should recognise on sight, the incident response plan and the reporting templates for each deadline chief among them. The NIS2 Master Document Register gives the board a single maintained view of ownership and review status to work from at each periodic approval cycle, rather than approving a policy set it has never actually reviewed line by line.

Common Mistakes Boards Make on NIS2 Training

  • Treating Article 20(2) as satisfied by a general security awareness deck. The provision requires training that enables the board to identify risks and assess risk-management practices. A passive slide presentation doesn't build that competence.
  • Approving Article 21 measures without engaging with what's inside them. Signature without comprehension is precisely the failure mode Article 20(1)'s liability language is designed to catch.
  • Assuming staff training substitutes for board training. Article 20(2) is explicit that board training is required while staff training is only encouraged. The two obligations don't offset each other.
  • No individual record per board member. Because the obligation is personal ("members," not "the board"), collective attendance at one session isn't the same as evidencing each individual member's currency.
  • Training delivered once at appointment and never refreshed. Article 20(2)'s "regular basis" language for staff training reflects the same expectation of ongoing competence the board itself is held to.

Getting Started

  1. Assess current board-level competence against what Article 20(2) actually requires — the ability to identify risks and assess risk-management practices, not general familiarity with cybersecurity terms.
  2. Separate approval from comprehension. Before the next Article 21 measures sign-off, confirm the board can substantively discuss what it's approving, not just receive a summary.
  3. Record training at the individual member level, since the personal liability exposure under Article 20(1) sits with each member, not the board as a body.
  4. Test the competence under pressure, using the Board Cyber Crisis Programme to run the board through realistic incident decision-making rather than relying on training delivered in the abstract.
  5. Tie training to the actual incident documentation the board is overseeing, using the NIS2 Master Document Register as the working reference at each review point.

Key Terms

  • Management Body: The board of directors or equivalent governing body of an essential or important entity, responsible under Article 20 for approving and overseeing cybersecurity risk-management measures.
  • Essential Entity: An organisation in a high-criticality sector subject to NIS2's stricter supervisory regime, including the governance obligations of Article 20.
  • Important Entity: An organisation in a sector NIS2 treats as important but less critical than essential entities, still subject to Article 20's governance and training requirements.
  • Cybersecurity Risk-Management Measures: The technical, operational and organisational measures entities must implement under Article 21, spanning risk analysis, incident handling, business continuity, supply chain security and more.
  • Management Body Liability: The personal accountability management bodies can face under Article 20(1) for infringements of Article 21 by the entity they govern.
  • Cyber Hygiene Practices: The basic cybersecurity practices and training referenced in Article 21 as part of the measures the board must approve and oversee.

Frequently Asked Questions about NIS2 Board Training Mandate 

1. Does NIS2 legally require cybersecurity training for board members?

Yes. Article 20(2) requires the members of the management bodies of essential and important entities to follow training, so that they gain sufficient knowledge and skills to identify cybersecurity risks and assess risk-management practices and their impact on the entity's services.

2. What exactly does NIS2 Article 20 require of the board?

Article 20 has two parts. Article 20(1) requires the management body to approve the entity's cybersecurity risk-management measures, oversee their implementation, and accept liability for infringements. Article 20(2) separately requires every management body member to follow training that builds real risk-identification and assessment competence.

3. Is staff training mandatory under NIS2, or only board training?

Board training is mandatory language... "are required to follow training." Staff training is framed more softly: entities are "encouraged" to offer similar training to employees on a regular basis. Board-level training carries the stricter legal obligation.

4. Can board members be held personally liable under NIS2 for cybersecurity failures?

Article 20(1) states that management bodies can be held liable for the entity's infringements of Article 21's risk-management measures, without prejudice to national liability rules for public institutions and officials. This liability exposure is a core reason the accompanying training duty in Article 20(2) exists.

5. How often should NIS2 board training be repeated?

NIS2 doesn't fix an interval for board training the way it does for incident reporting deadlines, but Article 20(2)'s framing of staff training "on a regular basis" reflects the same underlying expectation — training needs to be refreshed as risks, regulations and the entity's operations evolve, not delivered once at appointment.

6. What's the difference between approving cybersecurity measures and understanding them?

Approval under Article 20(1) is a governance act with liability attached; understanding is the competence Article 20(2)'s training requirement is designed to guarantee before that approval happens. Supervisory reviews assess whether approvals reflect genuine engagement with the entity's risk profile, not just a signature.

7. Which cybersecurity risk-management measures does the board actually need to understand?

The ten measure areas set out in Article 21, including risk analysis, incident handling, business continuity, supply chain security, secure systems development, effectiveness assessment, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication and secure communications.

8. How does NIS2 board training connect to incident response documentation?

The board's oversight duty under Article 20(1) extends to the cybersecurity risk-management measures it approves, which include incident handling and the reporting obligations behind NIS2's 24-hour, 72-hour and one-month deadlines. Training needs to leave the board able to engage with that actual documentation, not just discuss cybersecurity risk in the abstract.