EP_8.02Executive Liability, Penalties & Future EvolutionArticle 64NIS2 Article 20

Can a Director Go to Jail Over the CRA? Where Personal Liability Actually Comes From

The Cyber Resilience Act creates no personal criminal liability for directors. Its fines land on the company. The exposure that reaches the individual board member is written down somewhere else entirely, and confusing the two is how a risk committee mis-files its single largest governance question.

Jim McKenney (Digital Product Security Consultant)
8 min read
2026-08-14
Target Persona & Statutory Exposure

Prepared specifically for Board Directors, Non-Executive Directors, Corporate Risk Committees.. This memorandum provides defensible engineering blueprints, risk boundary definitions, and compliance checklists under Article 64, NIS2 Article 20.

Can a director go to jail under the Cyber Resilience Act? Under the CRA itself, no. The Regulation creates no personal criminal liability for directors, officers, or board members. Its enforcement teeth are administrative fines, and by their own terms those fines bite the company, not the person who chairs its risk committee.

That answer reassures the wrong people. The board members who exhale when they hear it are often the ones carrying the real exposure, because the personal liability is real. It simply does not live in the CRA. It lives in a different instrument of EU law, and in national statutes the CRA never names. Close the file after reading the penalties article and you will mis-file the single largest governance question on your own desk.

A corporate boardroom where directors review a cybersecurity governance report, one document labelled corporate fine and a second labelled personal duty sitting side by side on the table
The CRA fine and the director's personal duty are two different documents. A board that reads only the first has not read its own risk.

The CRA penalty reaches the balance sheet, not the boardroom

Article 64 of the CRA is titled Penalties, and it does exactly one thing to an enforcement target: it sets administrative fines on the offender. Non-compliance with the essential cybersecurity requirements and the core manufacturer obligations can cost up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher. The operator-side duties sit in a lower band at €10 million or 2%. The offender the article contemplates is "an undertaking", measured against "its total worldwide annual turnover". That is a legal person. It is your company, not your chief executive.

A fine of that shape is a corporate liability in the plainest sense. It draws down cash, it dents the reputation the board is there to steward, and it is the kind of number that belongs in the risk register with a euro figure beside it. What it does not do is name a natural person or send one anywhere. The arithmetic behind those two bands, and how a market-surveillance authority arrives at a specific figure inside them, is worked through in EP 8.01. For governance purposes the point is narrower: the CRA's own sanction is aimed at the entity. If personal exposure existed only here, a director could treat CRA compliance as an operational matter to be delegated and audited like any other. It does not exist only here.

Where the personal exposure is actually written down

The instrument that reaches the individual is the NIS2 Directive, Directive (EU) 2022/2555, and the provision is Article 20, titled Governance. It is short, and every board secretary in a regulated sector should be able to recite its shape. Member States must ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures the entity takes to comply with Article 21, oversee their implementation, and can be held liable for the entity's infringements of that obligation. A second paragraph requires that members of the management body follow training, so they can identify risks and assess the measures put in front of them.

Read those verbs as a director, not a lawyer. Approve, oversee, be held liable, train. The liability is not a general fiduciary abstraction imported from company law. It is written into a cybersecurity statute and attached to a specific, checkable set of acts. This is the clean line the two regimes draw between them: the CRA fine lands on the company's balance sheet, and NIS2 Article 20 is what reaches the individual sitting on the management body.

A diagram showing two separate liability channels: the CRA Article 64 channel flowing to the company as an administrative fine, and the NIS2 Article 20 channel plus national law flowing to the individual director as personal liability
Two channels, two targets. The CRA sanction terminates at the undertaking; the personal duty runs through NIS2 Article 20 and national law to the director.

One caveat keeps this accurate rather than alarmist. NIS2 Article 20 reaches the management body of an entity that is in NIS2 scope, an essential or important entity as the Directive defines those categories: energy, water, transport, digital infrastructure, and manufacturers of certain product classes among them. Not every company that ships a product with digital elements under the CRA is automatically a NIS2 entity. So the director duty is conditional on the company's regulatory footing. In practice the condition bites hard anyway. Many CRA manufacturers are themselves NIS2 entities, and a large share of their industrial customers plainly are, which is why the operator liability threaded through sectors like water and wastewater utilities puts the same personal duty on the customer's board that the supplier is trying to satisfy. Where NIS2 applies, the obligation on the individual is explicit and cannot be delegated away.

Why the answer is "it varies by member state"

Above NIS2 sits a national layer, and here precision means resisting the urge to quote a statute you have not read. NIS2 is a directive, so member states transpose Article 20 into their own law, and they do it against existing regimes of director duty, company law, and in some cases criminal liability. Germany, France, and the Netherlands each carry general director-duty and gross-negligence doctrines, and several member states provide for director disqualification as a sanction in their own right. The exact reach, the threshold of fault, and whether any of it is criminal rather than civil all vary by member state, and a board operating across the Union has to map its real exposure jurisdiction by jurisdiction rather than assume a single European rule.

What is common across the transpositions is the pattern, not the penalty. Personal exposure attaches where a director knew, or on the evidence should have known, that the entity's cybersecurity measures were inadequate, and failed to act. That is a documentary test. It is answered by what the board did and recorded, or did not. Which is exactly why the discharge of the duty is a filing problem before it is a security problem.

The board discharges this duty on paper, or it does not discharge it

An authority reconstructing a board's conduct after an incident does not have access to the directors' intentions. It has the minutes. If the management body approved the risk-management measures, the approval has to be a minuted decision with a date and a version reference, not a shared assumption that someone signed off at some point. If the board oversaw implementation, oversight has to show up as a recurring agenda item with status reported against it, not a line that appears once a year. If members trained, the training has to be logged. An oversight duty that leaves no trace reads, to a regulator, as an oversight duty that was never performed.

This is where a risk committee earns its standing. The work is not to become fluent in cryptography. It is to run a cadence that produces, every quarter, a record that answers the three NIS2 verbs on their face. Below is the template I hand to boards that want that record to exist before they need it rather than after.

A quarterly board calendar showing four review points across the year, each one recording approval of measures, oversight status, and training completion into the minutes
The oversight duty is a cadence, not an event. Four minuted reviews a year is what a defensible record looks like.

What to minute every quarter

Put this on the risk-committee agenda four times a year. Each line is written so the minute it produces answers a question an authority would otherwise ask you to answer under worse conditions.

Approve: record the decision, not the sentiment.

  • The current cybersecurity risk-management measures, by named version and date, were tabled and approved by the management body this quarter (or reaffirmed, if unchanged, with that reaffirmation minuted).
  • Any material change to those measures since the last meeting was identified, and the board recorded that it reviewed and approved the change.

Oversee: record that you looked, and what you saw.

  • Implementation status was reported against the approved measures, with open gaps, owners, and target dates named in the minute.
  • Open security incidents and their regulatory-reporting status were reviewed, including incident-reporting readiness for products still within their support period.
  • Supplier and product obligations the company owes downstream (support-period commitments, vulnerability handling) were reviewed as a standing item, not raised ad hoc.

Train: record that the body is competent to judge what it approved.

  • Training completion for each member of the management body is logged and current, with date and provider.
  • Any newly appointed director has a scheduled onboarding on the cybersecurity risk picture before their first approval vote.

Attribution: keep the two regimes separate in your own papers.

  • The corporate exposure (CRA Article 64 administrative fines, sitting on the company) and the personal exposure (NIS2 Article 20 plus national transposition, sitting on the individual) are tracked as distinct risks, so neither is mistaken for the other.

Run that four times a year and the record exists. Skip it, and the intention may well have existed — but the intention is not what gets read back to you in the proceeding. The minute is.

This Site Uses No Cookies

Eigenia does not set cookies. The only thing stored in your browser is one preference, saved in local storage, noting that you have seen this notice.