Compliance · NIS2

NIS2 tabletop exercises: what Articles 20 and 21 actually require

The NIS2 Directive (EU) 2022/2555 is being enforced across the EU through national transposition laws; Germany's has been in force since 6 December 2025. It demands risk management, crisis management and a trained, personally accountable management body. Sooner or later a regulator will ask what your evidence is, and a documented tabletop exercise is the strongest evidence you can produce.

~29,500
companies in scope in Germany alone
BSI estimate
Art. 20
approval, oversight and training duties
Directive (EU) 2022/2555
24 h
early warning, then 72-h notification and a final report after 1 month
Art. 23 Directive (EU) 2022/2555
6 Dec 2025
German transposition in force
NIS2UmsuCG / BSI
Scope

Who is covered (and why the clock has already run out in Germany)

NIS2 reaches far beyond classic critical infrastructure. The directive sorts covered organisations into two tiers, essential entities and important entities, and national transposition laws attach registration and reporting duties to both.

In Germany alone, the federal cyber security authority (BSI) estimates roughly 29,500 companies in scope of the transposed law. Which tier applies follows from sector and company size; the substantive duties (risk management, incident reporting, management training) apply in both. Other member states run their own registers and portals, but the underlying directive articles are identical, so the preparation work travels well across borders.

Tier 1

Essential entities

The directive's top tier, subject to the most intensive supervision, and the highest expectations for documented evidence.

Tier 2

Important entities

The second tier, with essentially the same catalogue of duties: measures under Article 21, reporting under Article 23, governance under Article 20. Important does not mean less obliged.

Status 2026

Germany: the registration deadline has expired

In-scope companies in Germany had to register with the BSI by 6 March 2026. That deadline has passed: anyone still unregistered is in default and should register without delay. Since 1 June 2026 the BSI's reporting and contact-point portal (MUK) has been fully operational. The counter where a 24-hour early warning must land already exists. Waiting to see is not a legal position.

Article 20

The management body is personally on the hook

Article 20 of the directive is addressed to management bodies, not IT departments. Three duties that cannot be delegated away, with liability attached.

01

Approve

Management bodies must approve the cybersecurity risk-management measures taken to comply with Article 21. A signature under a concept nobody at the table can explain will hardly satisfy that duty.

02

Oversee

They must oversee the implementation of those measures, continuously, which presumes they can judge whether crisis management would actually hold.

03

Train

Members of the management body are required to follow training on a regular basis, and entities are encouraged to offer similar training to their employees.

Article 20 also makes management bodies liable for infringements of the Article 21 duties, within the limits set by national law. In Germany, §38 BSIG spells this out as personal approval, oversight and training duties of the Geschäftsleitung, with liability to match.

Honesty matters here: the directive mandates measures and training, not the tabletop exercise itself. But when you have to prove that your management body is trained and genuinely oversees implementation, a webinar attendance certificate is thin: it proves presence, nothing more. A documented tabletop exercise proves judgement: which decisions the management body took under time pressure, when, on what information, and with what outcome. As training and oversight evidence, that is the strongest artefact you can produce.

Article 21

Crisis management is a mandatory measure, not a bonus

Article 21(2)(c) lists business continuity (backup management, disaster recovery) and crisis management among the measures every covered entity must implement.

National laws copy this list; Germany anchors it in §30(2) BSIG: business continuity, backup management, recovery and crisis management. (Digital-infrastructure providers additionally fall under Implementing Regulation (EU) 2024/2690, which details these requirements.) Taking it seriously means more than firewalls and patch cycles:

  • a crisis team with defined roles, deputies and alerting paths,
  • recovery priorities set by the business, not by IT alone,
  • the ability to communicate internally and externally when primary channels are down,
  • and proof that all of this exists beyond paper.

A BCM manual on the shelf satisfies the letter of the law. Whether it survives contact with reality is decided in the first real incident, or, far more cheaply, in the first serious exercise.

Article 23

The reporting chain: three deadlines you don't want to look up mid-incident

Article 23 requires a staged notification of significant incidents to the national CSIRT or competent authority. The clock starts when you become aware of the incident, not when the chaos ends.

Stage
Deadline
What it must contain (short form)
Early warning
within 24 h of becoming aware
First notice: is the incident suspected to stem from unlawful or malicious acts, and could it have cross-border impact?
Incident notification
within 72 h of becoming aware
Update of the early warning; an initial assessment of severity and impact, with indicators of compromise where available.
Final report
no later than 1 month after the notification
Detailed description of the incident, the type of threat or root cause, applied and ongoing mitigation measures.

Three deadlines look manageable on paper. In reality, the 24-hour question lands in the middle of the worst night your company has had: who decides the incident is significant? Who drafts the early warning while the same people are isolating systems? Who holds the portal credentials, and who covers for them on holiday? These questions decide between on time and late, and they cannot be asked for the first time on the day itself. In Germany, §32 BSIG mirrors this chain, with the BSI as the receiving authority.

That is exactly why Verdus exercises ship with dedicated reporting-chain injects: your team is confronted with the notification question at the least convenient realistic moment, the decision is captured with a timestamp. The debrief shows in black and white whether your early warning would have made the 24-hour window.

National guidance

Rehearse emergencies: the regulators' own standards say it

National frameworks converge on the same point. Germany's BSI Standard 200-4, the national reference for business continuity management, and the IT-Grundschutz course dedicate an entire chapter to rehearsing emergencies (Notfälle üben).

That is no accident; it is the supervisory logic in one sentence: an emergency concept that has never been rehearsed is a hypothesis. Only an exercise shows whether alerting paths work, deputies step in, and decisions are taken where the plan says they are. Knowing the standard and executing it under pressure are two different maturity levels, and supervisors care about the second.

Verdus Cyber operationalises that requirement: instead of an annual paper walkthrough you get a live, escalating exercise in the browser whose timeline, decisions and findings drop straight into your BCM documentation. You are not exercising beside the standard: you are generating the exercise evidence that distinguishes a lived BCM.

In practice

What a NIS2-ready exercise looks like

Five things separate a defensible crisis exercise from an afternoon of slides, and all five are built into Verdus Cyber.

01Realistic pressure65+ injects across 20+ categories: from the first SOC escalation to press enquiries and the call from your biggest customer. The exercise escalates live in the browser: phones ring, the clock runs.
02Reporting-chain injectsThe Article 23 deadlines are built in as dedicated injects: your team must decide under time pressure whether, when and what to report to the authority, exactly as in a real incident.
03Decision timestampsEvery decision is captured with a timestamp: who, when, on what basis. A vague sense that it went okay becomes a defensible timeline.
04Debrief as evidenceThe debrief package documents participants, scenario, decisions and findings: usable as training and oversight evidence towards supervisors, auditors and your own board.
05Management at the tableScenarios with explicit executive decisions (ransom, communications, notification) so that Article 20 training is not abstract but documented.
Scope note

And DORA? Only if you are in finance.

DORA, Regulation (EU) 2022/2554, applies exclusively to financial entities and critical ICT third-party providers, and has applied since 17 January 2025. It brings its own, partly tighter reporting deadlines: initial report 4 hours after classifying an incident as major (at the latest 24 hours after awareness), intermediate report at 72 hours, final report after one month, plus explicit digital operational resilience testing duties, including scenario-based tests (Articles 25/26).

For every other sector, NIS2 and its national transpositions set the bar. If you are a financial entity, we have the matching scenario with the DORA reporting chain ready.

Read the DORA guide See the banking scenario with DORA context
FAQ

Frequently asked questions

How often should we run a tabletop exercise?

The directive does not set a fixed exercise interval. Article 20 requires management training on a regular basis without defining one. In practice, at least one serious exercise per year has become the norm, plus a further run after major changes: new systems, restructuring, a new crisis team. What matters most is that every exercise is documented.

Who should take part?

The core is your crisis team: the management body, IT and security, legal, communications and the affected business units. Because of Article 20, the management body belongs at the table, as decision-makers, not spectators. Verdus separates controller and participant views so a facilitator can steer the pressure deliberately.

Is a PowerPoint training session enough evidence?

A slide deck with an attendance list may formally count as training, but it is weak evidence: it proves presence, not capability. A documented exercise with timestamps and a decision log shows that the management body can actually assess risks: which is what Article 20 asks of it.

What do we need to document?

Scenario and assumptions, participants and roles, the timeline with timestamps, decisions taken with their rationale, gaps found and the measures derived from them. Verdus generates this package automatically in the debrief: a timeline with decision timestamps, findings and an action list.

Does DORA apply to us?

Only if you are a financial entity or a critical ICT third-party provider: DORA (EU) 2022/2554 is finance-only and has applied since 17 January 2025. Everyone else falls under NIS2 and its national transpositions. If in doubt, we clarify the classification in the first call.

What does a NIS2 tabletop exercise cost?

Honest answer: it depends on format and depth, self-moderated, specialist-led or through the partner programme. The three delivery models are on our pricing page; we give you a realistic range in the first call, not after three workshops.

See pricing

Make your NIS2 duties exercise-proof.

In thirty minutes we will show you what a NIS2-ready exercise looks like for your organisation: scenario, reporting chain, debrief evidence.