Article 20(2) makes cybersecurity training a duty of the management body itself. A board-level session that meets it, produces the evidence a supervisor asks for, and leaves directors able to ask the right questions.
Book a scoping callNIS2 does not ask the management body to receive a briefing. It names approval, competence and accountability as duties of the individuals who sit on it.
The management body approves the cybersecurity risk management measures and oversees their implementation. Delegating the work is expected. Delegating the accountability is not available.
Article 20(2) requires members to follow training, so that they can identify risks and assess cybersecurity practices themselves rather than accept assurances from the people they supervise.
Supervisory powers reach the management body directly. Penalties reach €10 million or 2% of worldwide turnover for essential entities, and €7 million or 1.4% for important entities.
The directive also encourages entities to offer similar training to employees on a regular basis. The board duty is the one written as a requirement, which is why it is worth handling as a distinct engagement. See the full NIS2 picture.
Half a day, built around your organisation rather than around the directive. The agenda below is the standard shape and it moves to fit the room.
The obligation is recurring, so the format matters as much as the content. Every option below is delivered in English or German.
A half-day on site or as a scheduled slot inside a board meeting, tailored to your sector and your current programme status.
A shorter yearly session that keeps the evidence current and picks up what changed in supervision, guidance and case law.
A one-to-one or small-group briefing for incoming board members, so the duty is met on arrival rather than at the next annual cycle.
Board training works when the room is engaged rather than briefed. Sessions are facilitated in governance language, built around decisions the management body actually takes, and structured so directors can ask basic questions freely. The measure of a good session is the quality of the questions in the second hour.
The content comes from practitioners who build NIS2 frameworks for a living, so what the board hears is grounded in how the obligations are actually implemented rather than in how the directive reads. Translated into the terms a board decides in.
Who delivers the session is settled on the scoping call. Depending on your sector, your language and the composition of your board, that is either a NexGenio facilitator or a qualified specialist from our accredited partner network. The requirement we hold constant is the qualification and the independence, not the name on the agenda.
Delivery sits outside the management chain being discussed. That is what lets the evidence stand on its own, and it is also what makes the session useful, because directors can put a question to an outside facilitator that is harder to put to the person who reports to them. Sessions are available in English and in German.
Thirty minutes to establish your sector, tier, board composition and where your programme currently stands.
The agenda and scenarios are rebuilt around your operation. A generic deck is the fastest way to lose a board.
On site or remote, English or German, inside your meeting or as a standalone half-day.
Agenda, materials, attendance record and date, in the form a supervisor or auditor will ask to see.
Pricing is set on the scoping call, because a five-person board in one sector and a two-tier supervisory structure across three countries are genuinely different engagements.
A short call establishes your board composition, your sector and your language, and produces a fixed quote for the session.
Book a scoping call