CEO · NIS2 Article 20(2)

NIS2 Article 20(2): The CEO Training Duty You Cannot Delegate

NIS2 pushes the cybersecurity knowledge duty onto management body members. If the CEO is a member of that body in an essential or important entity, Article 20(2) requires a personal training record — not only an organizational training program.

In brief: Member States had to transpose NIS2 by 17 October 2024. Article 20(2) requires management body members of essential and important entities to follow cybersecurity training. For a CEO who is part of that body, a four-eyes-approved NIS2 terminology record is a timestamped artifact of engagement with the vocabulary — not a replacement for training.

When the training duty lands on the person, not the org

Most EU regulatory duties address the entity. NIS2 moved the dial. Article 20 addresses the management body directly — the human beings who sit on it — and then specifies, in paragraph (2), a knowledge requirement no CISO or training vendor can discharge on the CEO's behalf.

Note on scope: Article 32 (supervisory and enforcement measures, including the management-function-ban request power in Art. 32(5)(b)) applies to essential entities. Important entities sit under Article 33's parallel but more limited regime. Personal-liability rules attach through national transposition of the directive, not directly from Art. 32(6) on its face.

"Member States shall ensure that the members of the management bodies of essential and important entities are required to follow training, and shall encourage essential and important entities to offer similar training to their employees on a regular basis, in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity." NIS2 Directive, Article 20(2)

Read the asymmetry carefully. For the management body, training is required. For employees, entities are encouraged. That structural split is the hinge: the management-body training record is not the same as general awareness training. National transposition controls the enforcement mechanics; Germany's implementation law was published as BGBl. 2025 I No. 301 on 5 December 2025 and entered into force the following day.

What this costs the CEO personally

Article 20(2) does not come with its own fine schedule. It matters as part of the evidence file when a national supervisor asks the management body to show approvals, training, and engagement after an incident, audit, or enforcement inquiry.

When the training duty matters:

On the personal side, a national-law management-function order or named supervisory action is a board-level and counsel-level issue, not only an IT issue.

The board meeting question the CEO cannot wing

A CEO who walks into a board meeting and says "I think we're broadly NIS2-compliant" has lost the audit-committee conversation. The right answer has a ledger behind it: training completed on date X, management body approval of the NIS2 risk-management measures on date Y, version history of the terminology the board signed off on.

The NIS2 transposition deadline was 17 October 2024. On 7 May 2025, the Commission sent reasoned opinions to 19 Member States for failure to notify full transposition. The practical CEO task is to build the evidence ledger before a supervisor asks for it.

How terminology governance helps (honestly: partial)

Compliance Glossary does not deliver training and does not replace a CISO-run awareness program. What it does is produce a time-stamped artifact of the CEO's personal engagement with the NIS2 vocabulary — alongside the training records, not in place of them.

None of this makes a CEO "NIS2 trained." It produces a defensible governance record of the vocabulary layer — inspectable by regulator, D&O underwriter, and acquirer without a scramble.

The economics

For current pricing, see the Atlassian Marketplace.

Frequently asked questions

Can a CEO delegate the NIS2 Article 20(2) training duty to the CISO?

No, not if the CEO is a member of the management body of an essential or important entity. Article 20(2) requires members of management bodies to follow training so that they gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices. A CISO can run the program, but cannot be the training record for a management-body member.

What does "sufficient knowledge and skills" mean in practice?

Article 20(2) does not define a curriculum. Our operational interpretation, consistent with ENISA management-body awareness materials, centers on a paper trail: dated training completion records for each management body member, minutes of board sessions covering cyber-risk topics, and evidence that the CEO engaged with the substantive terminology of NIS2 and the entity's own risk register, rather than rubber-stamping.

Does approving NIS2 terminology count as training?

No. Approving terminology is not a substitute for a training program. It is a different artifact. A CEO who has four-eyes approved, versioned definitions of NIS2 terms has a documented record of personal engagement with the regulatory vocabulary that sits alongside training completion records, not in place of them.

When does NIS2 bite a CEO who never trained?

Member States had to transpose NIS2 by 17 October 2024, and the Commission sent reasoned opinions to 19 Member States on 7 May 2025 for failure to notify full transposition. Article 20(2) becomes practical when a national supervisor asks the management body for training evidence after an incident, audit, or enforcement inquiry.

Which sources were checked?

Sources checked 2026-06-22: NIS2 Directive (EU) 2022/2555, the European Commission NIS2 page, the Commission 7 May 2025 reasoned-opinion notice, and Germany's BGBl. 2025 I No. 301.

Install before the next board meeting

For current pricing, see the Atlassian Marketplace.

Evaluate in Confluence Read the Security Whitepaper

Related reading