For most of corporate history, many companies absorbed the consequences of a security failure and shifted the accountability of an incident to their IT department.
But NIS2 and DORA ended that arrangement. These two EU regulations moved cybersecurity accountability from the IT department to the individuals in the boardroom.
Here is exactly what changed, and what "reasonable steps" has to look like now:
Under these regulations, the board—not the CISO or IT function—is the accountable party. Neither accepts delegation as a defence.
The directive covers medium and large entities with 50 employees and above or €10M+ annual turnover in the 18 sectors. Some entity types are in scope regardless of size. Non-EU providers serving EU customers must appoint an EU representative.
Read: Directive (EU) 2022/2555 (NIS2) — Art. 2 and Annexes I & II for scope, size thresholds and size-cap exceptions, and Art. 26 for the EU representative requirement.
Under Article 20, approving and overseeing cybersecurity measures is your board's job, and the directive expects management to know enough to judge whether those measures are any good. For essential entities, a supervisory authority can ask a court to temporarily ban a named CEO or legal representative from holding a management role.
Read: Directive (EU) 2022/2555 (NIS2) — Art. 20(1)–(2) for the management body's approval, oversight and knowledge duty, and Art. 32(5)(b) for the temporary prohibition. Art. 33(5) sets the parallel, less prescriptive route for important entities.
A significant incident triggers a three-stage obligation:
Read: Directive (EU) 2022/2555 (NIS2) — Art. 23(4)(a)–(d) for the staged reporting obligation.
Essential entities face fines of at least €10 million or 2% of worldwide annual turnover, whichever is higher. For important entities it is at least €7 million or 1.4%. These are the floors the directive sets and not the ceilings of the fines imposed.
Read: Directive (EU) 2022/2555 (NIS2) — Art. 34(4) and 34(5) for the administrative fine floors.
DORA covers banks, insurers, investment firms and crypto-asset service providers, along with the ICT providers those firms depend on. If you supply a European financial institution, your customer has obligations it cannot meet without your cooperation, and those obligations will arrive in your contract.
Read: Regulation (EU) 2022/2554 (DORA) — Art. 2 for who is in scope, Art. 30 for the contract terms financial entities must impose on their ICT providers, and Art. 31 for how a provider gets designated critical.
Under Article 5, your board owns the digital operational resilience strategy. It has to approve it, review it periodically, make sure it is properly resourced, and keep oversight of how it is working.
Handing it to the CISO does not discharge the duty because every member state has to make sure penalties can reach members of the management body personally.
Read: Regulation (EU) 2022/2554 (DORA) — Art. 5 for the board's governance duties, and Art. 50(5) for penalties reaching members of the management body personally.
Once your team classifies an incident as major, the clock is already running:
Read: Commission Delegated Regulation (EU) 2025/301 — Art. 5 for the time limits, made under DORA Art. 19(4).
1. Can you describe your organization's attack surface to your board?
This is a question about your inventory: every domain, cloud service, forgotten test environment, third-party connection, and exposed employee credentials that an attacker can find without needing your permission.
2. Do you know your current security status right now?
A penetration test tells you what was true on the day it was run. Both regulations assume you know what is true now and not based on an annual reassurance exercise.
3. Can you name which regulations create personal liability for you specifically?
If you are not sure, that is the finding. Saying “I don’t know” is no longer a viable defense.
Aftra gives C-suite and boards a continuous, external view of your exposure that both regulations assume you already have—including the employee credential exposure most security tooling never looks at.