NIS-2 Compliance: Criminal Exposure for European CTOs and CISOs (EN)
Executive summary
The NIS-2 Directive (EU 2022/2555) has transformed cybersecurity from an operational IT concern into a matter of personal accountability for European management bodies. Article 20 of the directive requires management bodies of essential and important entities to approve cybersecurity risk-management measures, oversee their implementation, and follow training – with a clear legislative statement that they can be held liable for infringements. Germany implemented this through its NIS-2 Transposition and Cybersecurity Strengthening Act, which entered into force on December 6, 2025. Under § 38 BSIG, this liability is non-delegable and cannot be excluded by contract. For CTOs and CISOs the question is more nuanced: they are typically not formal management-body members, but they operate under direct influence of Article 20 duties – and can face parallel exposure through supervisory duty violations (§ 130 OWiG), breach of trust (§ 266 StGB) in serious cases, and personal civil liability under general company law (§ 43 GmbHG, § 93 AktG). This guide explains the framework, the actors, and what practical steps European technology leaders should take now.
Table of contents
1. The NIS-2 framework in short
2. Article 20: What management bodies must now do
3. The definition problem: who counts as management body
4. Personal liability channels in Germany specifically
5. Criminal exposure beyond administrative fines
6. Where CTOs and CISOs sit in the liability chain
7. Fines: administrative and personal
8. Practical safeguards for European technology leaders
9. Cross-border considerations
10. Frequently asked questions
1. The NIS-2 framework in short
Directive (EU) 2022/2555 – the NIS-2 Directive – replaced the original NIS Directive with an expanded scope, tighter obligations, and – critically – explicit accountability of management bodies. The transposition deadline was October 17, 2024. As of mid-2026, implementation is uneven across Member States, but the framework is legally binding in all EU jurisdictions.
Structural change vs. NIS 1:
Vastly broader scope. Essential entities (energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ICT service management B2B, public administration, space) and important entities (postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research). Threshold: generally 50+ employees or €10 million+ turnover, with sector-specific exceptions.
Concrete risk-management measures under Article 21 – ten specified areas including incident handling, supply chain security, encryption, and access controls.
Incident reporting timelines: 24-hour early warning, 72-hour notification, one-month final report.
Personal accountability of management bodies under Article 20.
Fines up to €10 million or 2% of global turnover for essential entities; €7 million or 1.4% for important entities.
For European technology leaders, the change is not merely regulatory volume. It is a shift in the accountability model.
2. Article 20: What management bodies must now do
Article 20 has two operative paragraphs:
Paragraph 1 requires Member States to ensure that management bodies of essential and important entities:
Approve the cybersecurity risk-management measures taken to comply with Article 21;
Oversee their implementation; and
Can be held liable for infringements by the entities of Article 21.
Paragraph 2 requires management-body members to follow training, and encourages entities to provide similar training to their employees, to gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices.
Three practical consequences flow from this:
1. Cybersecurity is a board-level topic. Not a delegated IT matter. Management bodies must engage substantively.
2. Documentation matters. Approval decisions, oversight activities, and training completion must be evidenced. In enforcement, the burden effectively shifts to those who cannot produce records.
3. Liability follows the role. Whoever exercises management-body function – regardless of formal title – is potentially exposed.
What Article 20 does not do: It does not create a uniform pan-European criminal liability. Enforcement remains national. Member States must ensure that management bodies "can be held liable" – but the concrete legal instruments differ.
3. The definition problem: who counts as management body
NIS-2 does not define "management body" independently. It borrows the term from prior EU law (Directive 2013/34, banking law). In practice this means:
Clearly included:
Boards of directors and management boards (Vorstand, conseil d'administration, junta directiva)
Executive committees with strategic authority
Managing directors of limited liability entities (Geschäftsführer, gérant)
Supervisory bodies (Aufsichtsrat, conseil de surveillance) with respect to their oversight duties
Not directly included but heavily influenced:
CTOs and CISOs, unless they hold a formal management-body seat
Data Protection Officers (their DPO role is protected under Article 39 GDPR, but their operational conduct in the CTO/CISO capacity can trigger separate exposure)
Compliance Officers and Chief Information Security Officers reporting to the C-suite
The gray zone: Many CTOs and CISOs are members of executive committees or hold procuration/general power of representation. In these constellations, they may qualify as management-body members for NIS-2 purposes. This is the highest-risk position: management-body responsibility without necessarily having the authority to allocate budgets, hire staff, or force organizational change.
Practical rule: If your title is CTO or CISO and you have executive committee membership or general power of representation, assume Article 20 applies to you. Structure your role accordingly.
4. Personal liability channels in Germany specifically
Germany's implementation makes the point concrete. Under § 38 BSIG (in the version brought in by the NIS-2 Umsetzungs- und Cybersicherheitsstärkungsgesetz effective December 6, 2025):
Members of the management (Geschäftsleiter) of essential and important entities must approve the risk-management measures under § 30 BSIG.
They must oversee implementation.
They must participate in cybersecurity training.
These duties cannot be delegated. Delegation to third parties for the purpose of duty fulfillment is expressly prohibited.
Waivers by shareholder agreement, articles, or resolution are excluded.
If these duties are breached and cause damage to the company, personal civil liability follows under general company law:
§ 43 GmbHG for GmbH managing directors
§ 93 AktG for AG board members
§ 116 AktG for supervisory board members
Damages recoverable include not only fines but also incident-response costs, business interruption losses, reputation damage where quantifiable, and cybersecurity remediation investments that should have been budgeted earlier.
The Business Judgment Rule offers protection – but only where decisions were made on an adequate information basis, in good faith, in the interest of the company. Absence of documented risk analyses, absence of board-level cybersecurity discussion, absence of training records collapse the Business Judgment Rule defense.
5. Criminal exposure beyond administrative fines
NIS-2 itself does not directly criminalize non-compliance. But the duties it establishes activate several German criminal-law provisions:
§ 130 OWiG – Supervisory duty violation. The classic bridge. When an offense is committed within an organization that proper supervision would have prevented or materially impeded, management bodies face administrative fines up to €10 million (with the underlying offense fine potentially significantly higher). NIS-2 gives concrete content to "proper supervision" in the cybersecurity context.
§ 266 StGB – Breach of trust (Untreue). Where a management-body member causes financial damage to the company through breach of fiduciary duty, criminal exposure attaches. Deliberately failing to fund adequate cybersecurity when known risks materialize is a scenario that has already been discussed in German commentary. Sentence: up to five years, up to ten in aggravated cases.
§ 202a and following StGB – Data espionage and related offenses. Not directly triggered by non-compliance, but the responsibility chain in incident scenarios can implicate management leaders when they had knowledge of vulnerabilities.
§ 42 BDSG – Data protection criminal offense. In parallel, when a cybersecurity failure results in unauthorized processing or disclosure of personal data with commercial or malicious intent by identifiable individuals, § 42 BDSG applies.
§ 283 StGB – Bankruptcy offenses. In extreme scenarios where a cybersecurity incident leads to insolvency, culpable failure to implement NIS-2 measures may qualify as bankruptcy-relevant conduct.
The path from incident to prosecution: Incident occurs → BSI investigation → administrative fine proceedings → parallel prosecutor's inquiry into individuals → potential charging decisions. Insolvency practitioners, shareholders (via derivative claims), and supervisory authorities all contribute to this pipeline.
6. Where CTOs and CISOs sit in the liability chain
For technology leaders below formal management-body level, the picture is more nuanced but not comfortable.
6.1 If you are a management-body member
You are directly exposed under § 38 BSIG. You must approve, oversee, and train. You cannot delegate these duties away. Your protection lies in documented compliance – decision minutes, risk assessments, training records, incident-response evidence.
6.2 If you are an executive committee member without formal management-body seat
You are almost certainly still exposed. Your role has strategic influence over cybersecurity spend and organization. The question is not whether liability attaches – it is which specific legal channel will apply. Practical strategies for management-body members apply to you as well.
6.3 If you are a pure CISO reporting to a management-body member
Your exposure is more limited but not zero:
You have advisory and monitoring responsibility. Your professional recommendations, if ignored by the management body, need to be documented. Silent compliance with an inadequate strategy is a risk to you personally.
If you actively execute measures that themselves violate law (unauthorized surveillance, unlawful data access as part of an incident response), you can be personally criminally exposed under §§ 202a, 42 BDSG.
In some scenarios, you can be treated as a de facto management-body member if your operational authority is exceptionally broad.
6.4 If you are a DPO
Your DPO role under Article 39 GDPR is advisory and monitoring only. Personal criminal liability requires personal tatbestandsmäßig conduct – not merely occupying the DPO position. But: many DPOs operationally participate in decisions beyond pure advisory function. When they do, they carry the corresponding responsibility.
Common thread across all four positions: Documentation. Every recommendation, every objection, every escalation should exist in written form. In enforcement, the person with the paper trail wins.
7. Fines: administrative and personal
Corporate-level fines (Article 34 NIS-2):
Essential entities: up to €10,000,000 or 2% of total annual worldwide turnover of the preceding financial year, whichever is higher.
Important entities: up to €7,000,000 or 1.4% of total annual worldwide turnover of the preceding financial year, whichever is higher.
Additional non-monetary enforcement measures available to national authorities include ordering compliance, mandating adjustments, imposing binding instructions, ordering information disclosure to specific persons or the public, and – in serious cases – temporarily suspending certain business functions or issuing personal management-body suspensions.
Personal management-body suspension is one of the most striking innovations. Under NIS-2 Article 32(5)(a) and (b), when an essential entity persistently fails to comply, competent authorities may:
Temporarily prohibit specific natural persons from exercising managerial functions at the entity level in question.
Temporarily suspend the entity's certification or authorization.
This is not administrative fine territory. It is a career-terminating instrument for individuals who fail to steer their organizations into compliance.
Personal fines in Germany follow via § 30 OWiG applied to individuals in specific circumstances, as well as through direct application of BSIG penalty provisions where the individual violation criteria are met.
8. Practical safeguards for European technology leaders
Practical steps to reduce personal exposure – regardless of the specific legal channel:
8.1 Governance documentation
Board or executive-committee resolutions approving cybersecurity strategy and risk-management measures, updated at least annually.
Documented risk assessments in the form Article 21 requires: incident handling, supply chain, encryption, access control, and the remaining eight areas.
Minutes reflecting substantive discussion – not check-the-box entries.
8.2 ISMS or equivalent management system
ISO/IEC 27001 certification or documented equivalent framework (BSI IT-Grundschutz, sector-specific standards).
Internal and external audits with documented remediation plans.
Reporting from CISO to management body quarterly at minimum.
8.3 Training
Mandatory, documented cybersecurity training for management-body members. Not one-time – recurring.
Sector-specific and role-specific content, not generic awareness videos.
Training records kept as personal records, not only in HR systems.
8.4 Incident response readiness
Documented incident-response plan aligned to NIS-2 reporting timelines (24 hours, 72 hours, one month).
External counsel on speed-dial – both cyber-focused and criminal defense.
Tabletop exercises annually, documented with lessons learned and remediation.
8.5 D&O insurance and legal defense
Review D&O coverage explicitly for NIS-2 personal liability scenarios.
Understand coverage limits, exclusions, and defense-cost provisions.
Add cybersecurity-specific riders where standard coverage is unclear.
8.6 Position clarification
For CTOs and CISOs specifically: know your legal position. Are you management-body? Executive committee member? Pure operational leader? Write your role definition down. When ambiguous, seek legal advice on your specific responsibility scope.
8.7 Escalation records
If you propose necessary investments, controls, or organizational changes and they are declined, document the recommendation, the response, and the ongoing dialogue. In enforcement, "I raised this and was overruled" is a defense – but only if written.
9. Cross-border considerations
For technology leaders in pan-European organizations or with global structures:
Uneven implementation across Member States. As of mid-2026, some Member States (Belgium, Croatia, Cyprus, Finland, France, Germany, Hungary, Italy, Latvia, Lithuania, Luxembourg, Portugal, Romania, Slovakia, Spain) had adopted implementation. Others (Bulgaria, Czechia, Denmark, Estonia, Ireland, the Netherlands, Poland, Slovenia, Sweden) were still in progress. Where you fall matters, and the Commission has taken infringement action against non-implementing states.
Establishment concept. NIS-2 applies to entities established in the EU. Non-EU headquarters with EU subsidiaries generally see the directive attach at the subsidiary level. Group-level oversight duties from a non-EU parent do not eliminate subsidiary-level obligations.
Enforcement coordination. ENISA (EU Agency for Cybersecurity) plays a coordination role. Cross-border incidents involving multiple Member States trigger cooperation groups. For technology leaders in multinational firms, this means: NIS-2 enforcement in one Member State can trigger scrutiny in others.
Interaction with GDPR. A cyber incident often has parallel GDPR dimensions. Data protection authorities and NIS-2 authorities coordinate. Reporting obligations run in parallel. Managing both regulatory streams simultaneously is now the standard, not the exception.
Interaction with sector-specific regulation. Financial services (DORA, MaRisk), critical infrastructure (KRITIS in Germany, similar frameworks elsewhere), and healthcare have layered regulations. NIS-2 applies additionally, not exclusively.
10. Frequently asked questions
Am I personally liable under NIS-2 as a CISO?
You are typically not a formal management-body member and thus not directly subject to Article 20. But you can be exposed through: personal civil liability under general company law where you have management-body function; supervisory duty violations under § 130 OWiG in Germany or equivalent provisions in other Member States; personal criminal exposure under § 42 BDSG, §§ 202a, 202b, 202c, 303a, 303b StGB where you personally engage in prohibited conduct.
Can I contractually limit my liability?
In Germany, waivers of § 38 BSIG duties are excluded by statute. You cannot contract out of the core management-body obligations. Indemnification agreements are possible for some claims but subject to significant limitations, particularly for gross negligence or willful misconduct. D&O insurance is the more realistic protection.
What sentences have been imposed under NIS-2 so far?
Corporate fines are being imposed by BSI and equivalent authorities across Europe. Personal management-body suspensions are provided for but rarely publicized. Criminal convictions specifically linked to NIS-2 breaches are still uncommon in 2026, but administrative proceedings targeting individuals are increasing.
How does NIS-2 interact with the AI Act?
The two frameworks coexist. NIS-2 focuses on network and information system security. The AI Act adds compliance obligations for AI system deployment and management. For entities deploying AI in cybersecurity or in operations covered by NIS-2, both regimes apply in parallel.
What about non-EU parents of EU entities?
The directive applies to the EU entity. Non-EU parents are generally not directly subject. But their oversight failures over the EU entity can contribute to fines and – in some Member States – to personal liability of individuals in the EU entity structure.
How do I document compliance effectively?
Written board resolutions on cybersecurity approvals, quarterly management-body meetings with cybersecurity as a substantive agenda item, documented training completion, ISMS certification, third-party audit reports, incident-response exercises with formal after-action reviews, escalation records. All maintained on a schedule that can be produced in enforcement proceedings.
What is the biggest mistake European technology leaders make right now?
Treating NIS-2 as an IT project instead of a governance project. Cybersecurity investment justified only on operational risk terms – not on liability terms – misses the point. Documentation, board engagement, and role clarity are the differentiators between organizations that pass enforcement scrutiny and organizations that do not.
How does Germany compare to other EU Member States on NIS-2 enforcement?
Germany has been an early implementer with strong enforcement infrastructure (BSI, state-level cybersecurity agencies). France and Belgium have similarly ambitious implementations. Southern and Eastern European Member States have generally moved more slowly, though the Commission's infringement pressure is closing the gap. For pan-European organizations, Germany is a leading indicator.
Conclusion
NIS-2 has ended the era in which cybersecurity was an operational IT concern separated from personal accountability of management. Article 20 creates real, specific, non-delegable duties for management bodies, backed by administrative fines, personal liability, and – in Germany specifically – criminal exposure through §§ 130 OWiG, 266 StGB, and connected provisions.
For CTOs and CISOs, the framework is not always directly aimed at them – but the practical implications are. The organizations they lead face NIS-2 duties; the management bodies above them look to them to execute; and their own conduct is subject to the same legal scrutiny once specific facts pattern-match to StGB provisions.
The practical safeguards are known and available: documented governance, ISMS-based compliance, mandatory training, incident-response readiness, D&O insurance review, and – above all – documented escalation and objection when necessary steps are not being funded. Technology leaders who invest in these safeguards can operate under NIS-2 with substantially reduced personal risk. Those who do not are betting on prosecutorial discretion – a bet that is losing.
Legal disclaimer
This article is for informational purposes only and does not constitute legal advice. Every case is different. For advice on a specific matter, please schedule a confidential consultation.
About the author
Niklas Hanitsch is a German criminal defense attorney focused on economic crime, IT and cyber criminal law, compliance, and data protection criminal law. He advises executives, board members, founders, and technology leaders on the intersection of cybersecurity regulation, criminal exposure, and cross-border matters. Founder and CEO of SECJUR, a venture-backed compliance and cybersecurity automation company selected for the Google for Startups Cybersecurity Accelerator. Member of the Federal Commission on Cybersecurity of the German Economic Council (CDU) – a policy body advising the German federal government on cybersecurity legislation. Named Capital 40 Under 40 (2023) and winner of the German Startup Cup for Cybersecurity (GFFT, 2022). Previous positions: Legal at Amazon, Taylor Wessing Silicon Valley (advising US companies on European data protection law), Taylor Wessing Germany, and Bird & Bird.
Schedule a confidential consultation →