Swiss groups with EU subsidiaries are hearing increasingly broad claims about NIS2 board liability. The underlying governance obligation is real, but the shortcut is misleading. Article 20 of Directive (EU) 2022/2555 requires the management bodies of entities within scope to approve and oversee the cybersecurity risk-management measures in Article 21, and it requires them to follow training. It also provides that management bodies can be held liable for infringements by the entity of Article 21. It does not create automatic, uniform personal civil or criminal liability across the EU, nor an EU-wide October 2026 enforcement deadline. The starting point for a Swiss parent is therefore entity-by-entity scope and evidence, not a generic group-wide liability slogan.
What the Directive actually says about management bodies
The authoritative text is Directive (EU) 2022/2555 on EUR-Lex: https://eur-lex.europa.eu/eli/dir/2022/2555/oj. Article 20 has three practical components. Management bodies must approve the measures required by Article 21. They must oversee their implementation. Members must follow training and should encourage regular training for employees. These duties make board-level cyber governance demonstrable, rather than leaving it as an implicit consequence of general corporate oversight.
The liability sentence must be read with equal care. Article 20 provides for management bodies to be held liable for infringements by the entities of the Article 21 obligations. National law determines how that statement is implemented and enforced. The Directive does not itself set an automatic personal fine for every director, a standard criminal offence across all Member States, or a universal private cause of action. Counsel should map the transposing law, sectoral rules, company law and the local authority's powers for each relevant subsidiary. A group policy can support consistency, but it cannot replace that local analysis.
Scope is not determined by the Swiss parent address
A Swiss parent company is not automatically within NIS2 scope because it owns an EU subsidiary. The relevant question is whether the individual EU entity meets the applicable national rules on sector, service, size and establishment. The Directive distinguishes essential and important entities, with the general size-cap rule and listed sectors subject to specified exceptions. A technology, manufacturing, health, logistics or digital-services group may have subsidiaries with very different outcomes. Services delivered across borders can add complexity, especially where a national implementation interprets establishment or sectoral classification differently.
The formal transposition deadline was 17 October 2024 and NIS1 was repealed on 18 October 2024. Those dates are not a substitute for checking the current national position. The European Commission's NIS2 policy material is at https://digital-strategy.ec.europa.eu/en/policies/nis2-directive. A Commission targeted-amendment initiative discussed in 2026 is a proposal, not law. Boards should avoid presenting a proposed change as a new binding deadline before the legislative process and national implementation provide one.
◆ Key Takeaway
NIS2 makes cyber oversight, approval and training express management-body duties for in-scope entities. It does not impose automatic uniform personal liability on Swiss parent directors; defensible governance begins with local scope, national law and evidence that Article 21 measures are working.
Turn Article 21 into board evidence
Article 21 requires appropriate and proportionate technical, operational and organisational measures. Its domains include risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, secure acquisition and maintenance, effectiveness assessment, cyber hygiene and training, cryptography, human resources and access control, asset management, and multi-factor authentication or continuous authentication where appropriate. The board's role is not to approve a technical control catalogue once and then receive a dashboard indefinitely. It is to challenge whether the measures reflect the entity's services, dependencies, incidents and residual risks.
Incident governance needs the same specificity. For significant incidents, NIS2 sets an early warning within 24 hours, an incident notification within 72 hours and, normally, a final report within one month. Those timings should be converted into tested subsidiary procedures, with decision owners, counsel contacts, evidence preservation and regulator communication paths. A parent can supply a group incident framework, but the entity must retain the ability to identify an event, qualify it under applicable national law and act on time. ENISA's technical guidance offers a practical source for implementation work: https://www.enisa.europa.eu/publications/technical-guidance-on-the-implementation-of-the-nis2-directive.
Sanctions and Swiss reporting should not be conflated
NIS2 sets minimum maximum administrative fine ceilings for entities: for essential entities, at least EUR 10 million or 2% of global annual turnover, whichever is higher; for important entities, at least EUR 7 million or 1.4%, whichever is higher. These are entity-level ceilings in the Directive, not automatic penalties and not automatic personal fines. National law and supervisory practice determine the actual enforcement outcome. This distinction belongs in board papers, risk registers and communications to group leadership.
Swiss mandatory cyber-incident reporting is a separate regime with its own scope and triggers. The NCSC describes that duty at https://www.ncsc.admin.ch/ncsc/en/home/meldepflicht.html. An incident may require assessment under both a Swiss reporting obligation and an EU subsidiary's NIS2 process, but neither analysis should be inferred from the other. A single group incident record should capture facts once, while legal and regulatory owners assess each jurisdiction's notification path independently.
- Build an entity-by-entity scope register. Record each EU subsidiary's country, sector, services, size, national implementation status and accountable legal owner.
- Map local management-body duties. Obtain advice on the relevant transposing law and company-law consequences rather than assuming Directive language operates identically everywhere.
- Schedule evidenced board approval and oversight. Keep minutes, risk decisions, challenge records and remediation follow-up linked to Article 21 domains.
- Deliver and record suitable management training. Cover the entity's threat model, service dependencies, incident process and board escalation role, not generic awareness alone.
- Test the 24-hour, 72-hour and one-month incident workflow. Include decision authority, external counsel, national regulator contact points and evidence preservation.
- Measure Article 21 implementation against residual risk. Track deficiencies, compensating controls, owners and due dates instead of relying solely on compliance attestations.
- Maintain parallel Swiss and EU reporting decision trees. Use common incident facts but make jurisdiction-specific notification decisions and retain their rationale.
The most useful 2026 board action is not a declaration that NIS2 liability has arrived everywhere. It is a governed process that can show which entities are in scope, what their management bodies approved, how implementation was challenged and how a significant incident will be handled. That evidence will remain valuable as national practice develops, while keeping Swiss parent leadership focused on the risks it can actually govern.