Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon
Back to BlogBoard Advisory
NIS2 Enforcement Has Arrived: How Boards Must Prepare for EU Cybersecurity Accountability in 2026

NIS2 Enforcement Has Arrived: How Boards Must Prepare for EU Cybersecurity Accountability in 2026

NIS2 enforcement is no longer theoretical. With EU court referrals and daily fines now live, boards must act now or face direct personal liability under the directive.

July 31, 202610 min readBy Adil Karam

The European Commission has moved NIS2 enforcement from policy debate to courtroom reality, and the consequences for boards that have not acted are no longer hypothetical. On July 8, 2026, the Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union for failing to transpose the directive,

asking the Court to impose financial sanctions including a lump sum and daily penalty payments.

The signal to every board member sitting within scope of NIS2 is unambiguous: the EU's enforcement machinery is fully operational, and cybersecurity governance is now a personal legal obligation, not an IT department concern.

With NIS2, cybersecurity is no longer something a board can delegate and forget about. The directive places responsibility squarely at the management level and, in specific circumstances, holds individual directors personally liable.

If your board still treats a breach as a future IT problem, your directors may find themselves personally named in an enforcement action before your next annual general meeting.

The Scope Is Larger Than Most Boards Realize

NIS2 applies to roughly 160,000 organisations across the EU, a 16-fold increase on the original NIS scope, covering 18 sectors and two categories of regulated entity: essential and important.

Those sectors span

digital infrastructures, energy, transport, banking and financial market infrastructures, health, drinking water and wastewater, public administrations, and space, as well as postal and courier services, waste management, chemicals, manufacturing, digital providers, and research.

The enforcement escalation has moved with striking speed.

The NIS2 escalation ran in three waves: formal notices to 23 member states on 28 November 2024, reasoned opinions to 19 on 7 May 2025, and CJEU referrals for four states on 8 July 2026.

Boards cannot take comfort in their member state's transposition pace.

For organizations in Ireland, Spain, France, and the Netherlands, the infringement proceedings change nothing about the underlying obligations. NIS2 requirements have been binding since October 2024 regardless of national transposition status. The proceedings add financial consequences for governments; they do not create a grace period for regulated entities.

The ENISA 2024 report noted that awareness remains a challenge: approximately 40% of newly in-scope organisations were not yet aware of their NIS2 obligations as of late 2024.

Unawareness does not constitute a defense. Supervisory authorities are now auditing, and

audit programmes have launched in 14 member states targeting essential entities.

What the Directive Specifically Requires of Your Board

The critical distinction in NIS2 is the separation between obligations that apply to the organization and obligations that apply personally to each member of the management body. Article 20 is the provision every director must understand.

Article 20 of the NIS2 directive is explicit: the governing bodies of organisations that fall under the directive must approve cybersecurity measures and actively oversee their implementation. This is a fundamental shift compared to the original NIS1 directive, under which cybersecurity in practice largely rested with the IT department.

Article 20(2) introduces a training requirement: management bodies must ensure they possess sufficient knowledge and skills to identify and assess cybersecurity risks, and they are encouraged to extend such training to wider staff.

This is not a one-time induction briefing.

Article 20(2) requires that all board members receive cybersecurity training sufficient to understand risks and assess cybersecurity practices; training is mandatory at appointment and annually thereafter, and completion should be documented.

The delegation argument carries no legal weight.

The management body cannot delegate away its NIS2 accountability. While the board may delegate operational cybersecurity to the CISO or a risk committee, the legal obligation to approve, oversee, and be trained remains with the management body itself. Delegation of tasks does not equal delegation of liability.

The question supervisory authorities will ask is not whether your organization has a cybersecurity program, but whether your board can demonstrate it understood, approved, and actively oversaw that program through documented evidence.

In serious cases of negligence, supervisory authorities can hold individual managers liable, including through temporary bans on exercising managerial functions. This shifts the question from "is the organization compliant" to "can leadership demonstrate that they fulfilled their oversight responsibilities."

The Penalty Exposure: Financial and Personal

Boards accustomed to thinking about cyber risk in insurance terms need to reassess. The exposure under NIS2 operates on two tracks simultaneously.

Entity CategoryMaximum Administrative FineSupervision ModelManagement Liability
Essential Entity€10 million or 2% of global annual turnover (higher applies)Proactive; regular audits, on-site inspections, mandatory security auditsYes; temporary ban from managerial functions
Important Entity€7 million or 1.4% of global annual turnover (higher applies)Reactive; triggered by incidents or evidence of non-complianceYes; personal liability for infringements
Both CategoriesBinding instructions, forced audit at entity's expense, public disclosure of infringementBoth face Article 20 board obligationsTraining non-completion is a documented gap

Beyond fines, competent authorities can issue binding instructions, order security audits at the entity's expense, suspend certifications or authorizations, and, for essential entities, temporarily ban executives from management functions.

A director who fails to oversee NIS2 compliance can be barred from holding management positions across any essential entity, not only the one where the violation occurred.

That is a career consequence that no directors' and officers' insurance policy was written to address.

According to a Gartner report, by 2026, 75% of CEOs will be personally liable for cyber-physical security incidents as a result of regulations like NIS2. This prediction underscores the urgency of board-level engagement with cybersecurity.

Framework Alignment: What Governance Evidence Must Look Like

Boards that already have ISO 27001 certification should not assume that satisfies NIS2.

ISO 27001:2022 covers roughly 70% of the Article 21 measures by ENISA's mapping. Five measures are fully covered; five are partially covered. The 30% gap needs explicit NIS2-tagged work.

The NIST Cybersecurity Framework 2.0 provides a complementary governance layer, particularly its "Govern" function, which maps closely to the board approval and oversight obligations in Article 20. ENISA's NIS2 implementation guidance and the NIS Cooperation Group's June 2026 Article 21 mapping document are the most operationally specific resources available to boards building their governance evidence trail.

From a practical governance standpoint, supervisory authorities will assess four things: formal board resolutions approving Article 21 risk management measures; documented evidence of recurring cybersecurity briefings to the management body; individual training records with completion dates and content mapping; and board-level escalation records demonstrating that material risk information reached directors before it reached regulators.

Approval at a single point in time is not sufficient. Article 20 requires ongoing supervision. This typically means periodic reviews, status reporting from the operational level to the management body, and evidence that the body acted on the information.

Cross-Border Enforcement Coordination

The EU Cooperation Group, ENISA, and national CSIRTs increasingly act as a coordinated supervisory network, and entities operating across multiple member states should expect more joint inspections and coordinated enforcement actions through 2026 and beyond.

Organizations with operations in Germany, France, Italy, and the Netherlands face the most immediate supervisory pressure;

supervisors have issued 70 formal orders across Germany and France, 47 by the BSI under Germany's NIS2 law and 23 by ANSSI.

The Digital Omnibus Amendments

On 20 January 2026, the Commission proposed a targeted NIS2 amendment as part of the wider digital and cybersecurity package. It does not reopen the core directive but would add a small mid-cap category, remove micro and small DNS providers from scope, introduce ransomware-payment disclosure obligations under Article 23, and require non-EU in-scope entities to designate an EU representative.

Boards should not treat this amendment proposal as a signal to delay current compliance work; the core Article 20 board accountability provisions are not under revision.

Cyber Insurance Recalibration

Underwriters are repricing coverage for NIS2-scope entities based on board governance maturity, not just technical controls. Organizations that cannot demonstrate documented board-level oversight of cybersecurity risk management are increasingly finding either that premiums are unaffordable or that specific exclusions render coverage ineffective at the moment of an incident.

Supply Chain Liability Extension

Article 21(2)(d) creates direct obligations for third-party risk: entities must assess the cybersecurity posture of direct suppliers, the quality and resilience of their products and services, and the security of supplier development practices. In practice, this means extending third-party risk management programs to include NIS2-equivalent contractual clauses and supplier incident notification obligations.

Boards approving Article 21 measures must ensure supply chain security assessments are included in what they are formally approving.

Board Readiness Assessment: Where Does Your Governance Stand?

Use this checklist to assess your board's current NIS2 posture before your next supervisory authority interaction.

Governance RequirementStatusEvidence Required
Board has formally approved Article 21 cybersecurity risk management measures☐ Complete / ☐ Partial / ☐ Not startedBoard resolution or documented minutes
All management body members have completed documented cybersecurity training☐ Complete / ☐ Partial / ☐ Not startedTraining records with dates and content scope
Recurring cybersecurity briefings to board are scheduled and minuted☐ Complete / ☐ Partial / ☐ Not startedMeeting calendar and attendance records
Cyber risk is quantified in financial terms on board risk register☐ Complete / ☐ Partial / ☐ Not startedBoard-format risk register entry
Incident escalation procedure ensures board notification before regulator notification☐ Complete / ☐ Partial / ☐ Not startedDocumented escalation protocol
Supply chain cybersecurity assessments are included in approved Article 21 measures☐ Complete / ☐ Partial / ☐ Not startedSupplier assessment records
Organization has identified its NIS2 category and relevant national competent authority☐ Complete / ☐ Partial / ☐ Not startedScope determination document

If you have more than two items marked "Not started," your board carries documented liability exposure today, not at some future enforcement date.

How I Help

Most boards do not know precisely what NIS2 requires of them as individuals: mandatory cybersecurity training, formal approval of specific risk management measures, documented ongoing oversight, and a personal accountability trail that survives a supervisory audit. Through my Board Advisory service, I deliver a focused 90-minute board briefing that maps each director's exact Article 20 obligations, quantifies penalty exposure in financial terms your CFO and audit committee can act on, and gives every member of the management body a defensible governance framework before your next board meeting. This is not a generic awareness session; it is a structured engagement that produces the documented evidence supervisory authorities will request.

For organizations that need to build the underlying compliance infrastructure, my Compliance service translates the ten Article 21 measures into an implementable program with clear ownership. If your security architecture needs alignment with NIS2's technical requirements, my Security Architecture service addresses those gaps directly. Organizations operating across multiple EU member states benefit from the cross-border regulatory mapping I provide through my vCISO service, and for those managing AI systems within NIS2-scope entities, my AI Governance service addresses the emerging intersection of AI risk and NIS2 supervisory obligations.

Contact me to schedule a no-obligation discovery call. Enforcement is active, supervisory authorities are auditing, and the window for proactive preparation is narrowing. The conversation takes 30 minutes; the liability of not having it is considerably more consequential.

#NIS2#EU Cybersecurity Regulation#Board Accountability#Regulatory Compliance#Cybersecurity Governance#EU Enforcement
PDFShare:

Adil Karam

Security & AI Governance Advisor

Helping organizations navigate security leadership and AI governance challenges.

Ready to Put These Insights Into Action?

Whether you need AI governance, security leadership, or compliance guidance—let's discuss how to apply these strategies to your organization.