can the board be personally liable for NIS2 violations
Yes, board members of essential entities can be held personally liable
For essential entities, Article 21(2) of the NIS2 Directive provides for the possibility that managers may be held personally responsible for approving and overseeing the cybersecurity measures of their organization. This is not a minor matter in the Directive: the board must know, approve and actively oversee the risk management measures, not merely sign off on a policy document. How this works in practice — which board members, under what conditions, and with what consequences — is determined in the national transposition, in the Netherlands the Cyber Security Act.
This directly addresses the question what happens if an organization fails to meet the NIS2 obligations: alongside measures that may be taken against the organization as a whole, the Directive specifically addresses the board member as a natural person with this provision. This represents a shift from many other compliance obligations, where the legal entity is usually the point of contact and the board remains at a distance. To make that responsibility concrete, it helps to understand which ten measures must be taken according to NIS2 — because approval and oversight require that the board knows what it is approving, not merely that something has been approved.
Where this is based: Article 21 and the national law
The basis lies in Article 21(2) of Directive (EU) 2022/2555, which gives Member States the option to hold board members of essential and important entities responsible for breaches of the duty of care. The precise implementation — who this applies to, under what circumstances and with what consequences — is for the national legislator; in the Netherlands this is the Cyber Security Act, and the NCSC provides guidance on how the duty of care and the notification obligation work in practice. For the exact wording of the provision and the status of the Dutch transposition, the official text is the point of reference.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.