The National Cybersecurity Agency has updated the FAQs concerning the obligations of the administrative and management bodies of NIS entities. The update provides interpretative guidance on certain aspects of the application of the NIS 2 regulations, helping to clarify the role of administrative and management bodies within the cybersecurity governance framework.
With regard to the responsibilities of administrative bodies, it is confirmed that the approval of the documents required under Article 23 of the NIS Decree is the exclusive responsibility of the collegial body or, where applicable, the sole decision-making body, and cannot be delegated. However, the performance of activities necessary for the operational implementation of the obligations laid down by the legislation may be delegated.
It is further specified that the documents to be submitted for approval by the administrative bodies must set out the guidelines and strategic planning for security measures. Documentation of an technical and operational nature, such as procedures, operational instructions and manuals, may be drawn up and updated by the relevant departments without the need for approval by the governing bodies.
It is further clarified that NIS entities may organise the documentation in the manner they deem most appropriate, either through a single document or through a set of coordinated documents. Updating the technical and organisational documents referred to in the strategic documentation does not require the latter to be re-approved.