NIS2 Article 20(2): The CEO Training Duty You Cannot Delegate
NIS2 pushes the cybersecurity knowledge duty onto management body members. If the CEO is a member of that body in an essential or important entity, Article 20(2) requires a personal training record — not only an organizational training program.
In brief: Member States had to transpose NIS2 by 17 October 2024. Article 20(2) requires management body members of essential and important entities to follow cybersecurity training. For a CEO who is part of that body, a four-eyes-approved NIS2 terminology record is a timestamped artifact of engagement with the vocabulary — not a replacement for training.
When the training duty lands on the person, not the org
Most EU regulatory duties address the entity. NIS2 moved the dial. Article 20 addresses the management body directly — the human beings who sit on it — and then specifies, in paragraph (2), a knowledge requirement no CISO or training vendor can discharge on the CEO's behalf.
Note on scope: Article 32 (supervisory and enforcement measures, including the management-function-ban request power in Art. 32(5)(b)) applies to essential entities. Important entities sit under Article 33's parallel but more limited regime. Personal-liability rules attach through national transposition of the directive, not directly from Art. 32(6) on its face.
"Member States shall ensure that the members of the management bodies of essential and important entities are required to follow training, and shall encourage essential and important entities to offer similar training to their employees on a regular basis, in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity." NIS2 Directive, Article 20(2)
Read the asymmetry carefully. For the management body, training is required. For employees, entities are encouraged. That structural split is the hinge: the management-body training record is not the same as general awareness training. National transposition controls the enforcement mechanics; Germany's implementation law was published as BGBl. 2025 I No. 301 on 5 December 2025 and entered into force the following day.
What this costs the CEO personally
Article 20(2) does not come with its own fine schedule. It matters as part of the evidence file when a national supervisor asks the management body to show approvals, training, and engagement after an incident, audit, or enforcement inquiry.
When the training duty matters:
- Significant incident + investigation. Regulators ask for training records and management body minutes. A CEO who cannot produce them is in the "gross negligence" conversation.
- Article 32(5)(b) request power. Competent authorities of essential entities may request that the relevant national body, court, or tribunal temporarily prohibit a CEO- or legal-representative-level manager from exercising managerial functions, in accordance with national law.
- Article 20(1) management-body duty. The personal-responsibility layer attaches through Member State transposition of Art. 20(1) — e.g. Germany's BSI Act §38 — not directly from Art. 32(6) on its face.
- D&O renewal and M&A diligence. Underwriters and acquirers now request governance evidence. "Our CEO has not attended cyber training" is an answer neither party accepts quietly.
On the personal side, a national-law management-function order or named supervisory action is a board-level and counsel-level issue, not only an IT issue.
The board meeting question the CEO cannot wing
A CEO who walks into a board meeting and says "I think we're broadly NIS2-compliant" has lost the audit-committee conversation. The right answer has a ledger behind it: training completed on date X, management body approval of the NIS2 risk-management measures on date Y, version history of the terminology the board signed off on.
The NIS2 transposition deadline was 17 October 2024. On 7 May 2025, the Commission sent reasoned opinions to 19 Member States for failure to notify full transposition. The practical CEO task is to build the evidence ledger before a supervisor asks for it.
How terminology governance helps (honestly: partial)
Compliance Glossary does not deliver training and does not replace a CISO-run awareness program. What it does is produce a time-stamped artifact of the CEO's personal engagement with the NIS2 vocabulary — alongside the training records, not in place of them.
- Four-eyes approval. Every cybersecurity term — from "significant incident" to "important entity" to internal categorizations — moves from draft to approved only when a second named person signs off. The CEO's approval is attributable and timestamped.
- Version history. Every NIS2 definition carries a full history of who edited what and when. When a supervisor asks how the management body interpreted a term on a past date, the answer is a stamped record.
- Audit trail with timestamps. Every write operation generates a dated, attributable entry before the change is committed; the record cannot be rewritten after the fact.
- Compliance scanner. Regex scanning flags Confluence pages using a synonym or deprecated variant of the approved term, closing the loop between what the CEO approved and what teams actually write.
- CSV export with full version history (PDF audit-package export on the 2026 roadmap). Full term set, approvals, and versions exported on demand for supervisors, insurance renewals, or customer supply-chain questionnaires.
None of this makes a CEO "NIS2 trained." It produces a defensible governance record of the vocabulary layer — inspectable by regulator, D&O underwriter, and acquirer without a scramble.
The economics
For current pricing, see the Atlassian Marketplace.
Frequently asked questions
Can a CEO delegate the NIS2 Article 20(2) training duty to the CISO?
No, not if the CEO is a member of the management body of an essential or important entity. Article 20(2) requires members of management bodies to follow training so that they gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices. A CISO can run the program, but cannot be the training record for a management-body member.
What does "sufficient knowledge and skills" mean in practice?
Article 20(2) does not define a curriculum. Our operational interpretation, consistent with ENISA management-body awareness materials, centers on a paper trail: dated training completion records for each management body member, minutes of board sessions covering cyber-risk topics, and evidence that the CEO engaged with the substantive terminology of NIS2 and the entity's own risk register, rather than rubber-stamping.
Does approving NIS2 terminology count as training?
No. Approving terminology is not a substitute for a training program. It is a different artifact. A CEO who has four-eyes approved, versioned definitions of NIS2 terms has a documented record of personal engagement with the regulatory vocabulary that sits alongside training completion records, not in place of them.
When does NIS2 bite a CEO who never trained?
Member States had to transpose NIS2 by 17 October 2024, and the Commission sent reasoned opinions to 19 Member States on 7 May 2025 for failure to notify full transposition. Article 20(2) becomes practical when a national supervisor asks the management body for training evidence after an incident, audit, or enforcement inquiry.
Which sources were checked?
Sources checked 2026-06-22: NIS2 Directive (EU) 2022/2555, the European Commission NIS2 page, the Commission 7 May 2025 reasoned-opinion notice, and Germany's BGBl. 2025 I No. 301.
Install before the next board meeting
For current pricing, see the Atlassian Marketplace.
Evaluate in Confluence Read the Security WhitepaperRelated reading
- Compliance for Confluence — approved terms, page scanning, and audit evidence for CEO-level compliance oversight in Confluence
- NIS2 Article 32 management-ban request power — sibling CEO NIS2 page on essential-entity enforcement mechanics
- NIS2 CFO personal liability — cross-persona read
- NIS2 Directive terminology for Confluence — the cybersecurity starter pack pre-loaded into the app
- Compliance Guide — overview of frameworks supported out of the box
- Security Whitepaper — Forge architecture, data-residency, vendor-assessment evidence