Law & Compliance · 2026-09-18 · 13 min read
NIS2 and the management body: what you personally stand to lose — money, office, and a training duty the BSI may audit

Michael Kaiser
Co-Founder & Head of Systems, Vincency
The question reaching boardrooms since the German NIS2 act entered into force on 6 December 2025 is always the same one: "Do I personally pay?" The honest answer is more precise than the fear behind it. You personally risk three things — money through internal liability to your own company, your office through a temporary prohibition, and an auditable training duty you carry as an organ. What you do not risk is the headline everyone quotes: the ten-million fine does not land on the managing director. It lands on the entity, and the fine catalogue does not even name the provision that governs you.
This piece walks the liability chain the way the statute built it: who counts as a management body under Section 2 no. 13 BSIG, what Section 38 actually obliges that person to do, the three routes along which a breach reaches the individual, and why the sanction frame in Section 65 points at the company instead. For anyone running an important or essential entity under Section 28 BSIG, this is the paragraph architecture worth knowing before the first incident, not after.
Who counts as management — and why the IT lead does not
Section 2 no. 13 BSIG defines Geschäftsleitung as a natural person appointed by law, articles or partnership agreement to run the affairs of and represent an essential or important entity. That is the managing director of a GmbH, the board member of an AG, the personally liable partner running a KG. It is deliberately a natural person — not the IT director, not the CISO, not the external security provider. The statute puts the duty where German corporate law already puts the responsibility: on the organ that can be held to account inside the company.
The consequence cuts both ways. A company cannot lower the duty into the organisation by hiring a security officer, and the officer cannot inherit it by doing the work. Execution may be delegated — supervision may not, and that asymmetry is the hinge of the whole liability question.
What Section 38(1) orders — implement and supervise
The operative sentence of Section 38(1) BSIG is short: management bodies of essential and important entities must implement the risk-management measures required under Section 30 and supervise their implementation. Two verbs, and the German version is sharper than the directive it transposes. Article 20 of the NIS2 directive speaks of approving the measures; the German statute demands their implementation and continuing supervision — an ongoing act, not a signature.
Supervision in this sense is a documented state, not an intention. It means the management body knows which of the ten measure areas of Section 30(2) are covered, by whom, and with what residual gap — and can show that it checked. What is checked is still bounded by the proportionality clause of Section 30(1) sentence 2: a sixty-employee manufacturer is owed measures scaled to its risk exposure, not a group-grade apparatus. But whatever scale applies, the supervision itself is not scaled away.
Route one: internal liability — Section 38(2) reaches private assets
Section 38(2) BSIG states that a management body breaching its duties under paragraph 1 is liable to its own entity for a culpably caused damage under the company-law rules applicable to the entity's legal form. For the GmbH that is the mechanism of Section 43(2) GmbHG — the managing director who negligently breaches his duties is liable to the company — and for the AG the parallel rule of Section 93(2) AktG. The direction matters: the company claims against its own organ, privately, with assets on the line.
What counts as the damage is the practical question. Remediation and recovery cost after an incident that a supervised implementation would have contained, third-party claims the entity settles, and the cost of ordered measures all qualify in principle. Whether a fine imposed on the company can itself be passed through to the officer is contested — the fine punishes the entity, and shifting it would blunt exactly that design. What is not contested: the chain requires fault. A management body that resolved the measures, implemented them and demonstrably monitored their effectiveness has removed the liability trigger before any court reaches the damages figure.
Route two: prohibition of office — the last resort of Section 61(9)
The sharpest instrument in the statute sits at the end of an enforcement chain most directors have never read. Where an essential entity fails to comply with a BSI order despite a deadline, Section 61(9) no. 2 BSIG allows the competent sectoral supervisory authority — not the BSI itself — to temporarily prohibit an unreliable management body from exercising the office to which it was appointed. It is expressly the last resort, it is linked to the unheeded order, and it ends the moment the entity complies.
Two limits keep the instrument rare. The wording addresses essential entities only; for important entities, Section 62 BSIG opens an ex-post review where facts justify the suspicion of non-compliance — and the prohibition clause is not worded for them. And the trigger is deliberate non-compliance after an order and a deadline, not a discovered gap. The path to a prohibited director runs through an ignored instruction, not through an incident.
Route three: the training duty the BSI may audit — Section 38(3)
Section 38(3) BSIG obliges management bodies to take part in training regularly, with a defined content: sufficient knowledge and skills to identify and assess risks and risk-management practices in information security, and to judge their effects on the entity's own services. It is a duty to understand enough to supervise — not a duty to become an engineer, and not a one-off.
The provision is not fine-backed — Section 65 does not list it — but it is auditable, and that is the detail worth marking. Section 61(1) lets the BSI order audits expressly covering Section 38(3); Section 62 opens the same check for important entities on suspicion. When an auditor asks what the board did, the answers are either documented or they are claims. Date, content and participant are a three-line record that converts a duty into evidence.
What the fine catalogue does not contain — why Section 65 does not point at you
The number everyone quotes — ten million euros or two percent of turnover — comes from Section 65 BSIG, and its catalogue names breaches of the measure duties of Section 30, the reporting deadlines of Section 32, the registration duty of Section 33, and disobedience of orders under Section 61. Section 38 does not appear in the list. There is no personal fine line for a lazy board.
The architecture is deliberate. The high brackets — ten million for essential, seven million for important entities, and the turnover rule of two or 1.4 percent only above five hundred million of global revenue — are addressed to the entity. Section 65(9) goes further and excludes Section 17(2) of the regulatory-offences act inside those brackets, the usual mechanism for fining the individual who failed to perform a duty owed by another. The legislator keeps the big fine on the company and keeps the personal layer where it placed it: internal liability, auditable duties, and for essential entities the ultima-ratio prohibition.
| Layer | What the provision requires | When it reaches you |
|---|---|---|
| Implementation + supervision | Section 38(1): implement the Section 30 measures, supervise their implementation | Permanent organ duty; execution delegable, supervision not |
| Internal liability | Section 38(2) with company law (§ 43(2) GmbHG, § 93(2) AktG) | Culpable breach plus damage to the entity — private assets |
| Training duty | Section 38(3): regular training to identify and assess risks | Auditable via Section 61(1) / Section 62 — not fine-backed |
| Prohibition of office | Section 61(9) no. 2: temporary ban on exercising the office | Essential entities only, last resort, by the sectoral authority — ends on compliance |
The timeline: what already applies and what is still coming
Half the anxiety in the market comes from treating every stage as live. The statute's own schedule separates them:
| Point in time | What applies then | For whom |
|---|---|---|
| Since 6 December 2025 | BSIG in force: Sections 30, 32, 33 and 38 binding | Every entity in scope of Section 28 |
| Since March 2026 | Registration window closed; duties active | 17,729 entities registered at 30 June 2026, against roughly 30,000 expected |
| Now | Individual audit orders under Section 61(1) — expressly including the Section 38(3) training duty; ex-post checks for important entities under Section 62; fines under Section 65 available | Essential entities proactively; important entities on suspicion |
| From December 2028 | Systematic evidence demands under Section 61(3) — earliest three years after entry into force; hospitals: five years | Essential entities not already audited under paragraph 1 |
The reading for a board in September 2026: the duties under Section 38 are already fully in force and already auditable on an individual basis. What is not yet live is the blanket evidence wave — the BSI cannot systematically demand proof from every essential entity before December 2028. Exposure today concentrates on the individual order, the suspicious incident and the fine-backed duties, not on a mass review.
Four records a management body should hold today
Section 38 does not grade intentions; it is discharged or breached in documentation. Four records cover the three routes above:
| Record | What it evidences | The limb it answers |
|---|---|---|
| Implementation resolution of the management body | The measures were not merely known but resolved — scope, owner, date | Section 38(1) "implement" |
| Responsibility matrix | Who executes (IT, CISO, provider) and who supervises (the organ) | Section 38(1) "supervise" — delegation without abdication |
| Effectiveness documentation | The review of effectiveness required by measure area 9 of Section 30(2), reported upward | Supervision made checkable |
| Training record | Date, content, participant — the board's own Section 38(3) duty | The auditable limb, in three lines |
None of this requires a consultant. It requires that the security conversation happened where the statute placed it — at the organ table — and that someone wrote it down. The file that answers an audit is the same file that answers a D&O questionnaire and the same file that defeats an internal-liability claim before it is drafted.
The honest remainder: what the statute does not demand
Three absences are worth as much as the duties. The statute demands no technical depth from the organ — the training duty aims at the ability to assess, not to administer. It demands no faultless outcome — the liability trigger is culpable breach, not the occurrence of an incident; a breached company with a supervised implementation has an answer, a quiet one does not. And it permits no abdication — outsourcing the work to a provider leaves the supervision exactly where Section 38 put it.
Whoever takes one sentence from this piece: the personal risk under NIS2 is real but narrow — it runs through documentation, not through the ten-million headline. The statute was written so that the organ cannot say it did not know, and so that the organ that did its duty can prove it did.
Related service
Turning obligations into systems
This article clarifies the legal position. It gets implemented in software and processes: product inventory, reporting channel, data access, invoice format, update documentation. We take the inventory off mid-sized companies, order the obligations by deadline and effort and, if you wish, implement them.
IT strategy consultingFrequently asked questions about NIS2 management liability
Is the managing director personally liable with private assets for NIS2 breaches?
Not through the fine — through internal liability, yes. Section 38(2) BSIG points to the liability rules of company law: a managing director who culpably breaches the implementation and supervision duty is liable to his or her own entity for the resulting damage — for a GmbH that is the mechanism of Section 43(2) GmbHG, for an AG Section 93(2) AktG. The damage covers remediation and recovery cost and third-party claims; whether a fine imposed on the company can itself be passed through to the officer is contested, because the fine punishes the entity. Fault is always required: whoever resolved, implemented and demonstrably monitored the measures has removed the basis of liability.
Can the BSI have a managing director removed from office?
Yes — but down a long chain and only for essential entities. Section 61(9) no. 2 BSIG lets the competent sectoral supervisory authority temporarily prohibit an unreliable management body from exercising the office to which it was appointed. Preconditions: the BSI issued an order, set a deadline, the entity failed to comply, and the prohibition is expressly a last resort — it ends once the order is fulfilled. So it is not the BSI that decides over the office but the sectoral authority. For important entities the wording does not address the measure; Section 62 reaches them only on concrete suspicion.
Does the managing director face a personal fine?
Not via Section 38. The fine catalogue of Section 65 BSIG lists breaches of the measure duties, the reporting, registration and notification duties, and disobedience of orders — the management-duty provision does not appear in it. The high brackets of ten and seven million euros address the entity, not the person, and Section 65(9) expressly excludes the usual redirection of a fine onto the acting officer (Section 17(2) OWiG) within those brackets. The personal edge of the statute therefore sits not in the fine but in internal liability and — for essential entities — in the prohibition of office.
Can management delegate the duties to a CISO or a service provider?
The execution yes, the responsibility no. Section 38(1) BSIG joins two verbs: implement and supervise. The operative implementation can go to an IT lead, a CISO or an external provider; the supervision of that implementation stays with the management body and cannot be delegated away. In practice: a documented responsibility matrix separating execution from supervision protects both sides — it shows the regulator a functioning leadership and the delegate that he executes rather than carries.
What counts as training under Section 38(3) BSIG?
The provision requires management bodies to take part in training regularly, with a defined learning goal: sufficient knowledge and skills to identify and assess risks and risk-management practices in information security and to judge their effects on the entity’s own services. No form is prescribed — a leadership briefing on the threat picture, risks and the state of measures serves the purpose better than a generic e-learning track. The duty is still auditable: Section 61(1) lets the BSI order audits expressly covering the training duty, and Section 62 opens that for important entities on suspicion. Date, content and participants should be documented.
We are only an important entity — does all of this apply to us?
The management duties apply identically to both categories: Section 38 BSIG speaks expressly of management bodies of essential and important entities — implementation, supervision, internal liability and training do not differ. What differs is supervision: for important entities the BSI may only check on concrete suspicion (the ex-post regime of Section 62), the fine ceilings sit at seven million euros or 1.4 percent instead of ten million or two percent, and the prohibition of office in Section 61(9) addresses essential entities in its wording.
Does D&O insurance cover this risk?
Partly — and the policy is worth reading against the three layers. Typical D&O contracts cover pecuniary losses from officer liability, which is exactly the internal liability Section 38(2) BSIG can trigger, including defence against unfounded claims. Fines, by contrast, are excluded in most wordings, and a regulatory prohibition of office is not an insurable kind of loss. Worth checking above all: cover for the company-law recourse, contributory-negligence clauses, cyber modules, and whether the policy expressly includes or excludes BSIG breaches.
Sources, status and note: All provisions were checked verbatim against the statute texts, retrieved on 18 September 2026: Section 38 BSIG for the implementation, supervision, liability and training duties of the management body; Section 2 no. 13 for who counts as management; Section 28 for the two entity categories; Section 30 for the measure catalogue and the proportionality clause; Section 32 and Section 33 for the reporting and registration duties; Section 61 for the audit powers and the prohibition of office in paragraph 9 no. 2; Section 62 for the ex-post regime covering important entities; and Section 65 for the fine catalogue and the exclusion of Section 17(2) OWiG in paragraph 9. The internal-liability mechanism rests on Section 43(2) GmbHG and Section 93(2) AktG. On the European level, Directive (EU) 2022/2555, Articles 20 and 34, for corporate accountability and the enforcement measures the BSIG transposes. The registration figures are from the BSI page NIS-2 in Zahlen, status 30 June 2026. This piece assesses the legal position; it does not replace advice on the individual case.
Related insights