Board liability for NIS2
Under Art. 20 NIS2, management is personally liable for cybersecurity. 7 questions will show your risk.
Has management formally approved a security policy and risk analysis?
Has management completed cybersecurity training (Art. 20(2))?
Do you have a formal risk assessment updated in the last 12 months?
Do you have a documented and tested incident response plan?
Do you assess security of key suppliers and have contractual clauses?
Do you have documentation of measures per decree 227/2025 (SK) / 264/2025 (CZ)?
Does management review compliance at least quarterly with written records?
We'll e-mail you the result
Drop your e-mail and we'll send the generated output plus a short note on what to do next.
We only use your e-mail to deliver the output and related follow-up. No spam, one-click unsubscribe. Details at /privacy.
Legal basis
Legal basis: NIS2 Directive 2022/2555 Art. 20 (governance — management body must approve and oversee cybersecurity measures and can be held liable under national law); SK Act 69/2018 Coll. § 19(6)(h) and § 20(4)(h) (informing the statutory body; persons responsible for approving measures and oversight); CZ Act 264/2025 Coll. § 14(1)(a) point 2 and § 14(2)(b) (requirements for senior management). Where corrective measures are not met, NBÚ can temporarily ban the statutory body of an operator of a critical essential service (§ 29j(4) of Act 69/2018) and NÚKIB a statutory-body member of a higher-regime provider (§ 58 of Act 264/2025 Coll.).
The tool is indicative. For legal assessment of a specific case contact a lawyer specialized in cyber law.