Ga naar inhoud

NIS2 ·

NIS2 chain liability: what boards must ensure in 2026

August 2026. NIS2 and national cybersecurity law strengthen board accountability — also for chain partners and vendors supporting essential services. Boards must prove cyber risks are actively governed, not only outsourced to IT.

What must the board ensure?

  • mandate and budget for security and chain risk;
  • periodic reporting: incidents, open risks, vendor status;
  • decisions on residual risk acceptance — in writing;
  • training: board understands NIS2 scope and notification duties.

Chain and contracts

Essential entities must assess chain risk. For SME vendors that means contracts with notification timelines, audit rights and exit clauses. Align with NIS2 hub and vendor management.

Practical governance

Plan a short quarterly board cyber item: open CAPs, critical vendors, exercises. Document attendance and decisions — supervisors and due diligence ask for this.

In 2026 directors are personally challenged when notification duties are missed. Mandate who notifies on behalf of the organisation and who communicates externally.

Link chain liability to ISO 27001 management review — one agenda, tags NIS2/ISO. Duplicate meetings without shared minutes do not help supervision.

Deep dive in the knowledge base

Run the NIS2 readiness scan

Align NIS2 expectations with your existing management system.

Start NIS2 scan

← Back to overview