The Signal · A-02 · Series A

NIS2 Is an Organisational Reform Instrument Disguised as a Cybersecurity Directive

13 July 2026·6 min read

NIS2 is filed, by almost everyone who deals with it, under cybersecurity. The directive expands the scope of the original Network and Information Systems Directive, brings more entities into scope, tightens incident reporting timelines, and strengthens supply chain security requirements. The compliance programmes built to address it are run by security and IT functions, staffed by technical people, and focused on technical controls. This is the natural reading of a directive with cybersecurity in its name, and it is a reading that misses the directive's most consequential provision.

NIS2 is, at its core, an organisational reform instrument. Its most significant requirement is not technical. It is the imposition of direct, personal, and non-delegable accountability on the management bodies of in-scope entities for cybersecurity governance. NIS2 is the first major instrument of its kind to make senior leaders individually liable for the cybersecurity posture of their organisations, and that provision will reshape governance in ways that the technical compliance programmes addressing the directive are not equipped to deliver.

The Provision That Matters

Buried in a directive full of technical requirements is Article 20, which addresses governance, and it is the part of NIS2 that will have the most lasting effect.

The provision requires that the management bodies of in-scope entities approve the cybersecurity risk management measures, oversee their implementation, and, crucially, can be held liable for the entity's failure to comply. It further requires that members of management bodies undergo training to gain sufficient knowledge to identify risks and assess cybersecurity risk management practices. The directive thereby establishes that cybersecurity is a board responsibility, that the board must be competent to discharge it, and that individual board members carry personal accountability for failure.

This is a profound shift, and it is easy to underestimate because it is expressed in a few lines of a long technical directive. Under previous frameworks, cybersecurity was something boards oversaw at a distance, delegated to technical functions, and engaged with primarily when something went wrong. NIS2 makes it a direct board responsibility, requires board members to be personally competent in it, and attaches personal liability to failure. The directive moves cybersecurity from the technical periphery of governance to its accountable centre.

The organisations treating NIS2 as a technical compliance exercise are addressing the directive's technical requirements and missing this. They are building the incident reporting capability, the supply chain security measures, the technical controls, while the provision that requires their board to take personal, competent, liable ownership of cybersecurity governance goes unaddressed, because it is not a technical problem and the technical function running the compliance programme is not positioned to solve it.

Why This Is an Organisational Reform

The accountability provision is not a discrete requirement that can be satisfied with a policy document and a board training session. It is a change to how the organisation is governed, and discharging it properly requires organisational reform.

For a board to take genuine, competent ownership of cybersecurity governance, several things have to change. The board needs to be genuinely competent in cybersecurity, which most boards are not, and acquiring that competence is not a matter of a single training session but of sustained capability development and, frequently, changes to board composition. The board needs information about the organisation's cybersecurity posture in a form it can actually use to govern, which most organisations do not currently provide, because the information flows up to the board in technical formats designed for oversight at a distance rather than governance at the centre. The board needs to integrate cybersecurity into its actual decision-making, which means cybersecurity considerations must reach the board in time to influence decisions rather than being reported after the fact.

Each of these is an organisational change, not a technical control. They concern board composition, information architecture, governance process, and the integration of cybersecurity into institutional decision-making. They are the kind of change that a technical compliance programme cannot deliver, because they are not technical, and the function running the technical compliance programme has neither the remit nor the authority to reform the organisation's governance.

This is why NIS2 is an organisational reform instrument wearing technical clothing. The technical requirements are real and must be met. But the directive's distinctive demand, the one that separates it from the frameworks that preceded it, is a governance reform that the technical compliance programme is structurally unable to deliver.

The UK Position

The UK is not directly subject to NIS2, having left the EU before the directive took effect. But the UK position is more entangled with NIS2 than this suggests, in ways that matter to UK CNI operators.

UK entities that operate in the EU, supply EU-based essential and important entities, or form part of supply chains that reach into NIS2-scope organisations are affected by the directive's requirements through their commercial relationships, even where they are not directly in scope. NIS2's supply chain security provisions require in-scope entities to manage the cybersecurity risk of their suppliers, which means UK suppliers to EU CNI find NIS2 requirements flowing to them contractually. The directive's reach extends beyond its formal jurisdiction through the supply chains it governs.

More significantly, the UK's own regulatory trajectory is moving in the same direction. The UK Cyber Bill, expected to reach enforcement in 2026, carries its own provisions on senior accountability for cybersecurity governance. The direction of travel in both jurisdictions is toward personal, board-level accountability for cybersecurity, and UK CNI operators who treat NIS2 as a purely EU concern are likely to find the same governance reform demanded of them by domestic legislation shortly afterward. The organisational reform that NIS2 requires of EU entities is the organisational reform that the UK regulatory framework is moving toward requiring of UK entities. Treating it as someone else's problem is a deferral, not an exemption.

What Genuine Compliance Requires

An organisation that wants to comply with NIS2 in substance, rather than merely in technical form, has to treat the directive as the governance reform it is.

This means engaging the board directly, not as the recipient of a compliance report but as the owner of a governance responsibility. It means building the board's genuine competence in cybersecurity, which may require changes to board composition and a sustained development programme rather than a single briefing. It means redesigning the information architecture so that the board receives cybersecurity information in a form it can govern with, and receives it in time to influence decisions. It means integrating cybersecurity into the organisation's actual governance processes, so that the board's accountability is discharged through real engagement rather than formal sign-off.

This is harder, slower, and more disruptive than building technical controls, which is precisely why most organisations are not doing it. The technical compliance programme is tractable, ownable by a clear function, and satisfying to complete. The governance reform is diffuse, requires board-level engagement, and threatens existing arrangements. The path of least resistance is to do the technical work and treat the governance provision as a matter of documentation, a policy stating that the board owns cybersecurity, a training session to evidence board competence, a sign-off to demonstrate oversight.

That path produces the appearance of compliance and the reality of exposure. When the first significant enforcement actions land, and the personal liability provision is tested, the distinction between organisations that reformed their governance and organisations that documented their intention to will become consequential, and personal, for the board members who carry the accountability the directive assigned them. NIS2 is a cybersecurity directive only on its surface. Beneath the technical requirements, it is an instrument that holds individual senior leaders personally liable for a governance responsibility most of them have not yet genuinely taken on.