NIS2 for the Board

NIS2 makes the board accountable for cybersecurity, with fines of up to EUR 10 million and requirements for documented risk management. Berigo helps boards take control, with clear scoping, a realistic plan and documentation that stands up to supervision.

What is NIS2?

NIS2 stands for Network and Information Security Directive 2, the EU's new regulatory framework for digital security and resilience. The directive applies across the EU and, through the EEA Agreement, will also be implemented in Norway. NIS2 will become a mandatory requirement for Norwegian organisations in selected sectors, with clear obligations for management and the board.

Who is covered by NIS2?

If your organisation operates in, or supplies to, any of these sectors, NIS2 applies to you.

Essential entities (highest requirement level)

Organisations providing critical services within:

  • Energy: electricity, power systems, oil and gas, district heating
  • Transport: aviation, rail, maritime transport, road and logistics
  • Health: hospitals, laboratories, critical health services
  • Drinking water and wastewater
  • Digital infrastructure: data centres, cloud providers, internet exchanges, telecoms, DNS
  • Banking and financial market infrastructures
  • Public administration
  • Space systems

Important entities (second-highest requirement level)

Organisations of significance to the national and European economy:

  • Postal and courier services
  • Waste management
  • Chemicals
  • Manufacturing and industry
  • Fisheries and food production
  • ICT service providers
  • Research and R&D institutions
  • Broadband, hosting, SaaS, MSPs and supply-chain actors

The board is accountable

NIS2 makes the board accountable. Are you prepared?

Fines of up to EUR 10 million / 2% of turnover. Requirements for management. Requirements for documentation. This is now a board matter, not an IT topic.

Berigo helps boards take control.

Book a board briefing on NIS2

Why this concerns you as chair of the board

If the regulator arrived tomorrow, could the board document governance, control and follow-up?

NIS2 establishes:

  • administrative fines of up to EUR 10 million / 2% of global turnover
  • responsibility and follow-up duties for the board
  • the possibility of assessing fitness to hold management and board positions in cases of serious failure
  • orders directed at the board itself
  • requirements for documented risk management and internal control

This is no longer an IT issue. It is corporate governance in its purest form.

Why board chairs come to us

Berigo gives boards what they actually need:

  • clarity on whether the organisation is essential or important
  • what specifically applies to them
  • a realistic, documentable plan for working towards compliance
  • a governance and control structure that withstands supervision
  • board materials free of technical noise
  • confidence in the role

In short: Boards do not need more detail. They need clarity. That is what we deliver.

NIS2: the directive that now tests the board's ability to govern, and to document it

If your organisation falls under NIS2, the first supervisory review will not question the IT department. It will question the board.

They will ask how the board has:

  • followed up on risk
  • ensured a management system is in place
  • secured internal control
  • requested status updates
  • set requirements for management
  • documented its own follow-up

And they will expect clear answers.

Non-compliance can trigger significant sanctions

NIS2 requires member states to be able to impose:

Essential entities:

  • administrative fines of up to EUR 10 million, or
  • up to 2% of global turnover

Important entities:

  • up to EUR 7 million, or
  • up to 1.4% of turnover

(Directive (EU) 2022/2555, Art. 34)

But it is not the amounts that make this a board matter. It is the accountability.

What affects the chair directly

NIS2 establishes formal management accountability, which means:

1. Individual assessment of fitness

In cases of serious failure to follow up, the regulator may assess whether management and board members have discharged their duties at a level compatible with the role. This can affect their ability to hold management or board positions in the future.

2. Orders directed at the board

Authorities can direct measures at the board itself:

  • mandatory training
  • governance improvements
  • specific follow-up actions
  • changes of roles in the event of material failure

3. Supervisory processes that demand documentation

Not verbal explanations. Not “we are working on it”. Documentation.

This is a level of scrutiny that Norwegian boardroom culture has never been tested against before.

A reflection for the chair

If a supervisory review took place tomorrow, could you say with confidence that the board has control, oversight and documentation?

If the answer is uncertain, incomplete or hedged, the risk does not sit with IT. It sits with the board.

This is where top-level governance and supervision meet. This is where accountability becomes visible. And this is where a board chair either stands firm or stands exposed.

Berigo gives the board the assurance it is expected to have

We work directly with boards that want:

  • a clear determination: is the organisation “essential” or “important”?
  • a precise assessment of which requirements actually apply
  • a review of risk, documentation and governance maturity
  • a realistic plan for working towards compliance
  • documentation that stands up to questions from the regulator
  • ongoing support that makes the board confident in its own role

It is not complexity the board needs. It is clarity.

Control cannot be improvised

For a board chair, this is not a question of willingness. It is a question of control.

And control cannot be improvised when the authorities come asking.

Contact Berigo

Want to be confident about NIS2?

Book a confidential board briefing. We show you your status, your risk and what needs to be done, without the complexity.

Book a board briefing

Proven Executive Outcomes

M&A

Uncovered critical IT vulnerabilities in a major tech acquisition, securing deal value.

NIS2

Guided a Nordic critical infrastructure provider from limited visibility to board-approved NIS2 compliance in 6 months.

Is your Board ready for NIS2?

Download the 2026 Executive Checklist for Cyber Liability.

Your address is used to send you the guide, and handled as described in our privacy statement. privacy statement.