# NIS2 Article 20: liability and evidence | Policy Confirm

Canonical URL: https://policyconfirm.com/blog/nis2-article-20-management-liability
Source: Policy Confirm (https://policyconfirm.com)
Published: 2026-05-04
Modified: 2026-05-04
Summary: NIS2 Article 20 makes management personally accountable for cybersecurity oversight. Learn what evidence supervisory authorities expect and how to produce it.

---
Compliance May 4, 2026

# NIS2 Article 20 and personal liability: What management actually needs to prove

Originally published: May 2026

Last updated: May 2026

NIS2 has moved from preparation to enforcement. National authorities across the EU now have audit powers, fines, and the ability to suspend managerial functions. For executives and board members, the most consequential change is not technical. It is personal.

Article 20 of the NIS2 Directive places direct accountability on management bodies for the approval and oversight of cybersecurity risk management measures. In serious cases of negligence, supervisory authorities can hold individual managers liable, including through temporary bans on exercising managerial functions.

This shifts the question from "is the organization compliant" to "can leadership demonstrate that they fulfilled their oversight responsibilities". These are not the same question, and the second one is harder to answer.

## What Article 20 actually requires

The text of Article 20 is short, but the implications are wide.

Management bodies of essential and important entities must:

-   approve the cybersecurity risk management measures taken under Article 21
-   supervise their implementation
-   be held liable for infringements of Article 21 by the entity

In practice, this means a management body cannot delegate accountability. It can delegate execution. The distinction matters during an audit, an incident review, or a court case. Approval and oversight must be visible. They must leave traces.

For background on how Article 21 connects to documented policies, see [How structured policy management strengthens your cyber security posture](https://policyconfirm.com/blog/structured-policy-management-cyber-security) .

## Why "we have policies" is not the answer

Most organizations under NIS2 scope already have policies in place. Information security policies. Acceptable use. Incident response. Business continuity. Supply chain security.

The presence of policies is not what regulators are testing.

What they are testing is whether the management body actively approved them, whether implementation is supervised, and whether the people bound by the policies were informed and acknowledged them. Without those three things, a stack of well-written documents is administrative paperwork. It is not evidence of governance.

This is the same structural pattern that creates audit failure under ISO 27001 and SOC 2. The difference under NIS2 is that the consequence is no longer institutional. It can attach to named individuals on the board.

## The four evidence questions a supervisory authority will ask

When a national authority audits a management body's compliance with Article 20, the questions follow a predictable pattern. They are not abstract. They look for documents, dates, and identifiable people.

### 1\. Did the management body approve the relevant policies?

Approval must be documented. A board minute, a signed approval record, or a system log showing who approved which policy version on which date.

Verbal approval is not evidence. References to "standard practice" are not evidence. The authority is looking for an artifact tied to a person and a date.

### 2\. Were the policies communicated to the people bound by them?

A policy that exists in a folder but was never communicated to staff cannot be enforced. Worse, it cannot be defended. If an incident occurs and the relevant policy was never seen by the employees responsible, the management body's oversight is treated as deficient.

Communication must be demonstrable. A shared link is not communication. An email blast is weak. A structured acknowledgement record is the strongest available artifact.

This is covered in detail in [How to prove policy acknowledgement during an audit](https://policyconfirm.com/blog/how-to-prove-policy-acknowledgement-audit) .

### 3\. Did the relevant individuals acknowledge them?

Article 20 oversight is meaningful only if the policies it approves actually reached the people they apply to. Acknowledgement closes that loop.

Each acknowledgement must:

-   be tied to a named individual
-   reference the specific policy version in force at the time
-   carry a reliable timestamp
-   be retrievable without reconstruction

If acknowledgement cannot be shown, the supervisory authority will treat the policy as effectively uncommunicated. This is the most common point of failure under audit conditions.

### 4\. Was implementation supervised over time?

Approval at a single point in time is not sufficient. Article 20 requires ongoing supervision. This typically means periodic reviews, status reporting from the operational level to the management body, and evidence that the body acted on the information.

A review schedule with documented outputs is sufficient. A claim of "regular review" with no artifacts is not.

## What this means for the board

For executives and board members, the practical implication is uncomfortable but clear. Cybersecurity oversight under NIS2 is not a delegated function. It is a personal one.

The defensible position is to establish a small, repeatable evidence chain:

-   documented approval of each policy version
-   structured distribution to all relevant individuals
-   explicit acknowledgement records that survive audit sampling
-   periodic review with documented outputs

When a supervisory authority asks the board "show me how you fulfilled your Article 20 responsibilities", the answer should fit on one page. If it requires reconstruction, the answer is already weak.

Smaller organizations sometimes treat NIS2 as a regulation aimed at large enterprises. Article 20 is one of the reasons this assumption is dangerous. Personal liability does not scale down with company size. The first formal NIS2 enforcement actions across EU member states are now beginning, and supervisory authorities have indicated they will not treat early non-compliance as a transition issue.

## How acknowledgement evidence supports Article 20 directly

Among the four evidence questions above, acknowledgement is the one most likely to be missing or weak in current setups. This is also the area where the management body has the least direct control during an audit. Either the records exist, or they do not.

A structured policy acknowledgement process produces the artifact a supervisory authority is looking for. Not a description of the process. Not a percentage. An immutable, timestamped, version-specific record tied to an identifiable person.

That record is what allows a board member to answer the question "did the relevant individuals acknowledge the policy you approved" without hesitation, without reconstruction, and without exposure.

For a structured way to evaluate whether existing acknowledgement processes would survive audit sampling, see the [Policy acknowledgement audit checklist](https://policyconfirm.com/blog/policy-acknowledgement-audit-checklist) .

## A note on supply chain and vendors

NIS2 Article 21 explicitly extends compliance into supply chain security. This has direct implications for management oversight. Policies that apply to vendors, contractors, and other third parties must be acknowledged with the same rigor as those applying to employees.

This is a frequent gap. Most organizations have an employee acknowledgement process. Few extend it to vendors. Under NIS2, that gap is now a board-level exposure. See [Vendor policy acknowledgement](https://policyconfirm.com/blog/vendor-policy-acknowledgement) for how to extend the same evidence model to third parties.

## Conclusion

Article 20 changes the audience for compliance documentation. It is no longer just the auditor or the security team. It is the management body itself, individually.

The defensible position under NIS2 is to make oversight evidence boring, complete, and immediately retrievable. Approval records. Communication records. Acknowledgement records. Review records.

Each one ties a specific person to a specific decision at a specific point in time. Together, they form the artifact that a supervisory authority will accept as evidence of fulfilled oversight responsibility.

When that evidence does not exist, the question stops being institutional and becomes personal.

### Get audit-ready policy acknowledgement records

Policy Confirm provides version-specific, timestamped acknowledgement records that meet the evidence standard expected under NIS2 Article 20.

[Get started](https://app.eu.policyconfirm.com)

Try with up to 10 recipients No credit card

Get started in seconds Magic link access

Choose between EU or US hosting

## About the author

The team behind Policy Confirm has hands-on experience across full-stack development, product growth, compliance leadership, and executive technology roles such as CTO and CPTO. They have led and supported ISO 27001 implementations, policy governance initiatives, and audit-driven compliance projects in regulated environments. This background informs a practical, audit-oriented approach to policy management and policy acknowledgements.

## Related content

-   [How structured policy management strengthens your cyber security posture](https://policyconfirm.com/blog/structured-policy-management-cyber-security)
-   [The auditor's checklist for policy management](https://policyconfirm.com/blog/auditors-checklist-policy-management)
-   [Policy acknowledgement audit checklist (2026 edition)](https://policyconfirm.com/blog/policy-acknowledgement-audit-checklist)
-   [How policy acknowledgement supports EU AI Act compliance](https://policyconfirm.com/blog/eu-ai-act-policy-acknowledgement)
-   [Vendor policy acknowledgement](https://policyconfirm.com/blog/vendor-policy-acknowledgement)

## Legal disclaimer

The information provided in this article does not, and is not intended to, constitute legal advice; instead, all information, content, and materials available on this site are for general informational purposes only. You should contact your attorney to obtain advice with respect to any particular legal matter.
