NIS2 knowledge base

NIS2 duty of care: what must boards be able to demonstrate?

The NIS2 duty of care is a governance cycle. The organisation identifies material risks, selects appropriate and proportionate measures, assigns ownership, tests effectiveness and uses the result for decisions and improvement.

The duty of care is a board-level control question

Executive directors approve risk-management measures and supervise implementation. They need enough information to understand why measures are appropriate, which residual risks remain and whether the controls operate effectively.

Supervisory boards use the same risk and evidence picture to assess direction, progress and exceptions within their oversight role.

Ten measure areas as a governance framework

The NIS2 measure areas cover risk analysis and policy, incident handling, continuity and crisis management, supply-chain security, secure acquisition and maintenance, effectiveness assessment, cyber hygiene and training, cryptography, personnel and access security, asset management and strong authentication and communication.

The board does not operate each control, but should understand coverage, ownership, proportionality and evidence.

Use an all-hazards risk analysis

Assess cyber, physical, technical, human and supplier causes that can affect network and information systems or critical services. Scenarios help connect the measure areas and reveal shared dependencies and recovery priorities.

Begin with the interests that require protection

These interests help the board compare impact and explain why one measure or scenario receives priority.

  • continuity of critical services;
  • safety of people, products and operations;
  • financial position and contractual commitments;
  • reputation and stakeholder trust;
  • personal data, confidential information and system integrity.

What should be demonstrably organised?

Maintain the risk assessment, decisions, owners, policies, operational evidence, tests, incidents, supplier reviews, exceptions and improvement actions. Management reporting should show whether the complete control cycle works and where intervention is needed.

Frequently asked questions

What is the NIS2 duty of care?

It is the obligation to manage cybersecurity risk through appropriate and proportionate measures across the required areas.

Must the board approve every individual control?

The board approves the risk-management measures and direction at an appropriate level and supervises implementation; operational details can be delegated within clear governance.

How can effectiveness be demonstrated?

Through tests, exercises, audits, reviews, metrics, incidents, corrective actions and other evidence relevant to the control and risk.

Review the duty of care through a board lens

Use the Masterclass to discuss risk, proportionality, evidence, effectiveness and the information that boards need for oversight.

Discuss the appropriate training route