NIS2 Article 20: What the Management-Body Duty Demands from CFOs
For CFOs who sit inside the management body of an EU essential or important entity, NIS2 is a board-level cybersecurity governance duty. Article 20 requires approval and oversight; Member State law determines the personal-liability mechanics.
In brief: NIS2 Article 20 requires management bodies of essential and important entities to approve cybersecurity risk-management measures and oversee implementation. Essential entities face entity-level fines up to 10 million euros or 2 percent of global turnover; important entities face up to 7 million euros or 1.4 percent. Article 32(5)(b) separately creates a management-function-ban request power for essential entities, routed through national law. A four-eyes-approved, versioned, audit-trailed cybersecurity glossary is one concrete artifact a disciplined board produces as evidence of engagement.
The pain: management-body accountability is no longer abstract
For the last decade, EU cybersecurity regulation mostly landed on the company. NIS2 moved the governance conversation into the management body. The European Commission NIS2 page describes the directive as introducing top-management accountability for non-compliance with cybersecurity risk-management measures.
For a CFO inside an essential entity in energy, transport, banking, health, water, digital infrastructure, public administration, or space, or an important entity in postal, waste, chemicals, food, manufacturing, digital providers, or research, this is not a policy abstraction. If the CFO sits on the management body, Article 20 points at that body and says: approve the cybersecurity measures and oversee implementation. Article 23 adds incident-reporting duties. Article 21 sets the technical and organizational baseline. When those duties break, national transposition determines individual consequences.
The stakes
Entity-level fines (Article 34):
- Essential entities: up to 10 million euros or 2 percent of worldwide annual turnover, whichever is higher.
- Important entities: up to 7 million euros or 1.4 percent of worldwide annual turnover, whichever is higher.
Management-body layer (Article 20 and national law): Article 20 creates the approval, oversight, and training duties. Personal consequences for management-body members depend on Member State transposition. Article 32(5)(b) creates a separate request power for temporary management-function bans in essential entities.
A national order affecting a management-body member is board-level and counsel-level information. Depending on the facts and jurisdiction, it can matter for debt covenants, procurement questionnaires, insurance renewals, and transaction diligence.
Why NIS2 is becoming a procurement gate
NIS2 compliance is also moving into the supply chain. NIS2 requires covered entities to manage supply-chain cybersecurity risk (Article 21). As those supply-chain obligations land, EU entities in scope are scrutinizing the vendors who touch their networks. Vendors without governance evidence lose tenders to those who can produce it. For a CFO who owns the revenue forecast, NIS2 governance evidence has shifted from a defensive artifact into a revenue-enablement artifact.
What "active, continuous involvement" looks like as a paper trail
Article 20 does not define a single enforcement test. The defensible record is still practical: approvals that show the management body read and endorsed the measure, version history that shows definitions evolved with the threat landscape, training logs that show named individuals completed the knowledge requirement in Article 20(2), and the ability to produce all of the above inside the investigation window without scrambling.
Compliance Glossary for Confluence does not build an ICT risk-management program. What it does is produce the specific artifacts regulators and insurers ask to see alongside the program. Translated from product feature into board-report artifact:
- Four-eyes approval. Every cybersecurity term, from "significant incident" to "important entity" to internal categorizations of critical function, moves from draft to approved only when a second named person signs off. The user who submitted the change cannot be the user who approves it.
- Version history. Every definition carries a full audit trail of who edited what, when, and why. When a supervisor asks how the management body interpreted a key term on a date in the past, the answer is a stamped record, not a memory.
- Audit trail with timestamps. Every write operation generates a dated, attributable entry before the underlying change is committed, so the record of who decided what and when is preserved in full.
- Compliance scanner. Deterministic regex scanning flags where Confluence pages use a synonym or a deprecated variant of an approved cybersecurity term. This closes the loop between the management-approved definition and the way teams actually write.
- CSV export with full version history (PDF audit-package export on the 2026 roadmap). Full term set, approvals, and versions exported on demand for supervisor requests, insurance renewals, or NIS2 supply-chain questionnaires from your own customers.
None of this guarantees a zero-fine outcome. It is not a legal shield. It is one artifact among the records a disciplined board should be able to produce.
The economics
For current pricing, see the Atlassian Marketplace.
Frequently asked questions
Does NIS2 Article 20 make CFOs personally liable?
NIS2 Article 20(1) places cybersecurity risk-management approval and oversight duties on management bodies of essential and important entities. Whether and how a CFO has personal liability depends on the CFO's role and the Member State transposition. Article 32(5)(b) separately gives competent authorities of essential entities a national-law request power for temporary management-function bans.
What fines apply under NIS2 for a CFO's entity?
Essential entities face administrative fines up to 10 million euros or 2 percent of worldwide annual turnover, whichever is higher. Important entities face up to 7 million euros or 1.4 percent of worldwide annual turnover. These are entity-level caps in NIS2 Article 34. Personal consequences for management-body members are determined through national transposition.
What does "active, continuous involvement" mean as evidence?
Article 20 asks management bodies to approve cybersecurity risk-management measures, oversee their implementation, and follow training to identify cyber risks. Regulators want a paper trail. A four-eyes approval log on cybersecurity terminology, a version history of approved definitions, and dated training records are all concrete artifacts that show active involvement instead of rubber-stamping.
Does Compliance Glossary replace a NIS2 compliance program?
No. Compliance Glossary does not build an ICT risk-management program or replace an incident-response plan. It provides a versioned, four-eyes-approved, audit-trailed record of the cybersecurity terminology your management body has formally endorsed. That record is one artifact regulators and insurers expect alongside the program itself.
Which sources were checked?
Sources checked 2026-06-22: NIS2 Directive (EU) 2022/2555, the European Commission NIS2 page, the Commission 7 May 2025 reasoned-opinion notice, and Germany's BGBl. 2025 I No. 301.
Turn NIS2 governance evidence into a quiet audit
For current pricing, see the Atlassian Marketplace.
Evaluate in Confluence Read the Security WhitepaperRelated reading
- Compliance for Confluence — approved terms, page scanning, and audit evidence for CFO-owned controls and disclosures in Confluence
- Manager liability under DORA’s national transpositions — sibling exposure for EU financial-services CFOs under national transpositions (e.g. Ireland S.I. No. 20 of 2025)
- Regulatory complexity as the CFO's top emerging risk — how NIS2 sits alongside AI Act, DORA, and Pillar Two
- NIS2 Directive terminology for Confluence — the cybersecurity starter pack pre-loaded into the app
- Security Whitepaper — Forge architecture, data-residency, and vendor-assessment evidence