Montro
NIS2 & GDPR9 min read

NIS2, Decoded: Scope, Obligations, and Personal Liability

NIS2, Decoded: Scope, Obligations, and Personal Liability
AuthorNamita Razdan
Published on1 Oct 2026

TL;DR:  NIS2 comes down to three questions. Are you in scope - and if so, are you an "essential" or an "important" entity? What does it require - chiefly the Article 21 risk-management measures and the Article 23 incident-reporting timeline? And who is personally liable - because under Article 20, NIS2 makes cybersecurity a board responsibility, with management held accountable for failures, and for essential entities the possibility of executives being barred from their roles.


Most cybersecurity regulation lands on the organisation. NIS2 lands on the organisation and, unusually, on the people running it. That is the shift that has made boards pay attention to a directive they might otherwise have delegated downward - and it is why understanding NIS2 is less about the technical measures than about three questions a leadership team has to be able to answer.


The three are: are we in scope, what does it require of us, and who carries the liability if we get it wrong.


Question one: whether you are in scope, and which kind


The first question is not what NIS2 requires. It is whether it applies to you at all, and that is less obvious than it sounds, because NIS2 widened the net considerably over the original NIS Directive.


Scope turns on two things: sector and size. NIS2 covers a long list of sectors - energy, transport, banking, health, water, digital infrastructure, public administration and more, and within those sectors it generally catches medium and large enterprises.


If you operate in one of the covered sectors and clear the size threshold, you are very likely in scope, whether or not you think of yourself as "critical infrastructure."


But being in scope is only half the answer, because NIS2 sorts covered entities into two tiers, and the tier changes what you experience. Essential entities - broadly, the larger organisations in the highest-impact sectors - face proactive, ex-ante supervision: regular audits, inspections, the regulator coming to you. Important entities face reactive, ex-post supervision: scrutiny triggered by an incident or evidence of a problem.


Both tiers carry the same core obligations; what differs is how closely you are watched and how hard you are penalised. So the scope question has two parts - in or out, and if in, which tier, and both shape everything downstream.


Question two: what it requires


For entities in scope, the substance of NIS2 sits in two articles.


Article 21 is the operational core: a set of cybersecurity risk-management measures the entity must implement, proportionate to the risk it faces.


These span risk analysis, incident handling, business continuity and crisis management, supply-chain security, security in acquisition and development, policies to test whether the measures are working, cyber hygiene and training, encryption, and access control. The list is deliberately broad: NIS2 expects a whole risk-management system, not a handful of controls.


An organisation already running a mature security programme - an ISO 27001 environment, for instance, can evidence much of Article 21 from what it already has, though NIS2 adds obligations that sit outside that standard.


Article 23 is the reporting duty, and it runs on a defined timeline. When an incident has a significant impact, the entity has to notify in stages: an early warning, then a fuller notification, then a final report, each within a set window measured from the point of awareness.


The staging matters because it front-loads the obligation: you are expected to raise a flag fast, well before you fully understand what happened. This is a different posture from "investigate, then report," and it catches organisations that are not set up to escalate quickly.


Between them, Article 21 and Article 23 are the "what" of NIS2 - build the risk-management system, and be able to report fast when something goes wrong.


Question three: who is personally liable


This is the question that changed the conversation, because NIS2 does not leave accountability at the organisational level. Under Article 20, the management body itself carries duties, and can be held personally liable for failing them.


Specifically, management bodies of in-scope entities must approve the Article 21 risk-management measures and oversee their implementation, and members must undertake training so they can actually assess the risks they are signing off.


The accountability is not abstract. Article 20 enables Member States to hold management-body members personally liable for infringements of the risk-management obligations, and for essential entities there is provision for temporary bans - executives prohibited from holding management functions after a serious failure.


Two features make this sharper than boards often expect. First, the liability attaches to *infringements* - a failure to comply with the measures, and is not limited to cases of gross negligence or deliberate wrongdoing. Second, the exact mechanism varies by Member State, because NIS2 is a directive transposed into national law, so the precise shape of personal liability depends on the jurisdiction the entity operates in.


The through-line is that NIS2 removes the ability to treat cybersecurity as purely an IT matter delegated downward. It is now, by design, a board responsibility with personal consequences attached.


Where AI complicates all three


NIS2 predates the current wave of AI adoption, but it lands on it squarely, because its obligations attach to the systems supporting your services - and increasingly those systems are, or contain, AI.


Each of the three questions is affected. Scope-wise, an AI tool inside a covered service is part of the network and information systems NIS2 governs. Obligation-wise, the Article 21 measures - supply-chain security especially, have to account for the AI features and providers your services now depend on.


And liability-wise, a board approving the Article 21 measures is approving coverage of an estate that includes AI it may not fully see. You cannot take responsibility for a system you have not accounted for, and AI is the part of the estate most likely to be unaccounted for.


The rest of this cluster works through the pieces: who exactly is in scope, the Article 21 measures in detail, the incident-reporting clock, supply-chain and fourth-party risk, and the personal-liability question in its own right. They all come back to the same three questions; in scope, what's required, who's liable - asked of an estate that now includes AI.


Frequently asked questions


Who is in scope for NIS2?


Montro's summary: NIS2 applies to medium and large entities operating in its covered sectors - energy, transport, banking, health, water, digital infrastructure, public administration and others across the directive's annexes.


In-scope entities are then classified as either essential or important, which determines how they are supervised and the level of penalties they face. The first compliance step is establishing both whether you are in scope and, if so, which tier you fall into.


What is the difference between essential and important entities?


Both must meet the same core obligationsthe,  Article 21 risk-management measures and the Article 23 reporting duties - but they are supervised and penalised differently. Essential entities face proactive, ex-ante supervision (audits and inspections) and higher maximum fines; important entities face reactive, ex-post supervision triggered by incidents, and lower maximums.


Essential entities also face the sharper end of the personal-liability provisions, including the possibility of temporary management bans.


What does NIS2 require organisations to do?


At its core, two things. Implement the Article 21 cybersecurity risk-management measures - a broad set covering risk analysis, incident handling, business continuity, supply-chain security, access control, encryption, training and more, proportionate to the risk. And meet the Article 23 reporting obligations - notifying significant incidents on a staged timeline, from an early warning through to a final report.


On top of these, Article 20 places approval, oversight and training duties on the management body itself.


Can executives be personally liable under NIS2?


Yes. Under Article 20, NIS2 enables Member States to hold members of the management body personally liable for infringements of the risk-management obligations, and for essential entities it provides for temporary bans from management functions after serious failures.


Notably, this liability attaches to infringements generally, not only to gross negligence, and the exact mechanism depends on how each Member State has transposed the directive, so Irish entities should look to Ireland's implementing law for the specifics.

Namita Razdan

Namita Razdan

Co-founder

Fifteen years of financial services compliance and technology consulting across HSBC, EY, Accenture, and NTT Data - and the person in the room when regulators ask the hard questions. At Montro, she owns regulatory accuracy and sets the firm's position on EU AI Act, DORA, NIS2, and GDPR.

Blog

Read next

Explore more from our library

View all

Stay informed on EU AI governance

Monthly updates on regulatory changes, compliance trends, and platform releases

By subscribing you agree to our Terms and Conditions and Privacy Policy

Montro AI governance dashboard showing tool risk tiers