NIS2 governance combines national supervision, EU-level cooperation (Cooperation Group, CSIRTs network, EU-CyCLONe, ENISA), management body accountability (Art 20), and a substantial penalty framework (Art 34). Management body liability is one of NIS2's most consequential changes vs NIS1.
Management body accountability (Article 20)
Management bodies of essential and important entities:
- Approve the cybersecurity risk-management measures (Art 21).
- Oversee implementation.
- Are responsible for ensuring compliance.
- Can be held liable for breaches.
Management body members must follow training to gain sufficient knowledge to:
- Identify risks
- Assess cybersecurity risk management practices
- Understand impact of risks on the entity's services
Training obligation typically interpreted as periodic (annual or as significant changes occur).
Liability
Member States must lay down rules for management body liability. Implementation varies; some Member States provide for direct personal liability of management body members, others channel liability through the entity.
Operational implication
Cybersecurity at C-suite / board level by mandate. Compliance is not a CISO-only concern; CEO, CFO, board members accountable. Pre-NIS2 patterns of treating cybersecurity as IT-team responsibility no longer defensible.
National competent authorities (Articles 8-9)
Each Member State designates one or more competent authorities for NIS2. Authorities have:
- Investigative powers (information requests, audits, inspections)
- Corrective powers (orders, suspensions, penalties)
- Cooperation obligations with other authorities
DE: BSI primary; BNetzA for telecoms; sector regulators for specific aspects. FR: ANSSI primary; CNIL for personal data overlap. Other MS: varied designations.
Supervision (Articles 32-33)
Essential entities — ex-ante supervision
Authorities can:
- Conduct on-site inspections
- Conduct off-site supervision
- Conduct random checks
- Request information
- Conduct security audits
- Request evidence of policy implementation
Essential entities face proactive supervision regardless of incidents.
Important entities — ex-post supervision
Authorities exercise supervisory powers when:
- Specific incident triggers concern
- Information about non-compliance received
Less proactive intervention; reactive to signals.
Audits
Authorities can order independent security audits at entity's expense for both essential and important entities (different triggers).
Penalties (Article 34)
Essential entities
Maximum administrative fines:
- €10 million OR 2% of total worldwide annual turnover in preceding financial year, whichever is higher.
Important entities
Maximum administrative fines:
- €7 million OR 1.4% of total worldwide annual turnover in preceding financial year, whichever is higher.
Factors considered (Article 34(3))
- Gravity and duration of breach
- Damage caused
- Intentional or negligent character
- Action taken to mitigate
- Previous breaches
- Cooperation with authorities
- Size of entity
- Other aggravating / mitigating circumstances
Member State discretion
Member States can set higher penalty caps in national law. DE NIS2UmsuCG largely follows EU caps. Some Member States set higher.
Public bodies
Member States may decide whether and to what extent administrative fines apply to public administration entities.
Other corrective measures (Article 32(4))
Authorities can:
- Issue warnings
- Adopt binding instructions
- Order entities to bring measures into compliance
- Order remedies to address specific deficiencies
- Order entities to inform recipients of significant incidents
- Order entities to implement recommendations following audits
- Designate a monitoring officer (essential entities)
- Order suspension of certification/authorization (essential entities)
- Order temporary prohibition of management body members from exercising managerial functions (essential entities, repeated/severe violations)
The last two are NIS2's strongest enforcement tools — operational suspension and management body sanctions.
EU-level cooperation
Cooperation Group (Article 14)
Strategic-level. Composed of Member State representatives + Commission + ENISA. Tasks include:
- Strategic guidance
- Member-state-specific risk assessments
- Information exchange
- Coordination of national strategies
CSIRTs network (Article 15)
Operational-level. National CSIRTs cooperate via the network. Tasks include:
- Mutual assistance
- Information exchange on incidents and threats
- Coordination on cross-border incidents
EU-CyCLONe (Article 16)
Crisis-level. Cyber Crisis Liaison Organisation Network. For large-scale cybersecurity incidents and crises. Operational cooperation between Member States.
ENISA
Cross-cutting support. Provides:
- Technical assistance to Member States and Commission
- Guidelines and recommendations
- Threat-landscape reporting (ENISA Threat Landscape annual report)
- Capacity-building support
- Cooperation among national CSIRTs
CVD coordinated vulnerability disclosure (Article 12)
Member States designate one or more CSIRTs as coordinator for coordinated vulnerability disclosure. Coordinators:
- Receive vulnerability reports
- Facilitate dialogue between reporter and affected entity
- Coordinate disclosure timing
- Manage cross-border CVD
ENISA maintains an EU-wide CVD database (Article 12(2)).
Notable enforcement (early state)
As of 2026-05-12:
- Transposition completed in most Member States.
- Authorities ramping investigation capacity.
- First substantial enforcement actions emerging 2026.
- DE BSI has issued initial guidance; investigations underway.
- France ANSSI has commenced supervision activities.
Major enforcement decisions will accumulate through 2026-2028 establishing interpretive precedents.
SRE and AI-agent fit notes
Management body training for AI
Cyber risk landscape includes AI-specific risks. Management body training should cover:
- Foundation-model dependencies and supply-chain implications
- AI feature attack surface (prompt injection, output handling, tool misuse)
- Vendor risk assessment for AI providers
- AI incident response
Audit preparation
For NIS2-scope clients facing supervision:
- ISO 27001 audit infrastructure largely transfers.
- Document Article 21 (a)-(j) coverage.
- Demonstrate Article 20 management body involvement.
- Show Article 23 incident response readiness.
Stefan-context implementation sketch
- For client engagements: support client's NIS2 governance maturation.
- Management body training delivery can be a service offering for in-scope clients.
- Audit preparation services align with engagement work.