Skip to content

NIS2 ·

NIS2 chain liability: what boards must ensure in 2026

August 2026. NIS2 and national cybersecurity law strengthen board accountability, also for chain partners and vendors supporting essential services. Boards must prove cyber risks are actively governed, not only outsourced to IT.

What must the board ensure?

  • mandate and budget for security and chain risk;
  • periodic reporting: incidents, open risks, vendor status;
  • decisions on residual risk acceptance, in writing;
  • training: board understands NIS2 scope and notification duties.

Chain and contracts

Essential entities must assess chain risk. For SME vendors that means contracts with notification timelines, audit rights and exit clauses. Align with NIS2 hub and vendor management.

Practical governance

Plan a short quarterly board cyber item: open CAPs, critical vendors, exercises. Document attendance and decisions, supervisors and due diligence ask for this.

In 2026 directors are personally challenged when notification duties are missed. Mandate who notifies on behalf of the organisation and who communicates externally.

Link chain liability to ISO 27001 management review, one agenda, tags NIS2/ISO. Duplicate meetings without shared minutes do not help supervision.

Primary sources for this topic

Deep dive in the knowledge base

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

← Back to overview

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)