Skip to main content
NIS2Directive (EU) 2022/2555

Article 20: Governance

NIS2 Art. 20, Chapter IV

1. Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article. The application of this paragraph shall be without prejudice to national law as regards the lia

150 words in the official text.

Sits inside (1)

Cites (1)

Recitals matched by wording (1)

These recitals name no article. The dataset matched them to this one by text similarity, and they are marked so nobody reads a match as a citation.

Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.

NIS2 32022L2555

Every connection on this page is drawn from the official text of Directive (EU) 2022/2555. Study aid, not legal advice.

See how NIS2 sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.