August 2026. NIS2 and national cybersecurity law strengthen board accountability — also for chain partners and vendors supporting essential services. Boards must prove cyber risks are actively governed, not only outsourced to IT.
What must the board ensure?
- mandate and budget for security and chain risk;
- periodic reporting: incidents, open risks, vendor status;
- decisions on residual risk acceptance — in writing;
- training: board understands NIS2 scope and notification duties.
Chain and contracts
Essential entities must assess chain risk. For SME vendors that means contracts with notification timelines, audit rights and exit clauses. Align with NIS2 hub and vendor management.
Practical governance
Plan a short quarterly board cyber item: open CAPs, critical vendors, exercises. Document attendance and decisions — supervisors and due diligence ask for this.
In 2026 directors are personally challenged when notification duties are missed. Mandate who notifies on behalf of the organisation and who communicates externally.
Link chain liability to ISO 27001 management review — one agenda, tags NIS2/ISO. Duplicate meetings without shared minutes do not help supervision.
