NIS2 Directive – Directive (EU) 2022/2555 – Recital 137
Recitals
Recital 137
Recital 137
Commission Impact Assessment on Data Sharing Unofficial title
This Directive should aim to ensure a high level of responsibility for the cybersecurity risk-management measures and reporting obligations at the level of the essential and important entities. Therefore, the management bodies of the essential and important entities should approve the cybersecurity risk-management measures and oversee their implementation.
https://nis2.digiphile.law/recital/recital-137.html
Text as at 19 September 2026.
This is an unofficial convenience version of the EU NIS2 Directive (Directive (EU) 2022/2555). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.