NIS2 tabletop exercises: what Articles 20 and 21 actually require
The NIS2 Directive (EU) 2022/2555 is being enforced across the EU through national transposition laws; Germany's has been in force since 6 December 2025. It demands risk management, crisis management and a trained, personally accountable management body. Sooner or later a regulator will ask what your evidence is, and a documented tabletop exercise is the strongest evidence you can produce.
Who is covered (and why the clock has already run out in Germany)
NIS2 reaches far beyond classic critical infrastructure. The directive sorts covered organisations into two tiers, essential entities and important entities, and national transposition laws attach registration and reporting duties to both.
In Germany alone, the federal cyber security authority (BSI) estimates roughly 29,500 companies in scope of the transposed law. Which tier applies follows from sector and company size; the substantive duties (risk management, incident reporting, management training) apply in both. Other member states run their own registers and portals, but the underlying directive articles are identical, so the preparation work travels well across borders.
Essential entities
The directive's top tier, subject to the most intensive supervision, and the highest expectations for documented evidence.
Important entities
The second tier, with essentially the same catalogue of duties: measures under Article 21, reporting under Article 23, governance under Article 20. Important does not mean less obliged.
Germany: the registration deadline has expired
In-scope companies in Germany had to register with the BSI by 6 March 2026. That deadline has passed: anyone still unregistered is in default and should register without delay. Since 1 June 2026 the BSI's reporting and contact-point portal (MUK) has been fully operational. The counter where a 24-hour early warning must land already exists. Waiting to see is not a legal position.
The management body is personally on the hook
Article 20 of the directive is addressed to management bodies, not IT departments. Three duties that cannot be delegated away, with liability attached.
Approve
Management bodies must approve the cybersecurity risk-management measures taken to comply with Article 21. A signature under a concept nobody at the table can explain will hardly satisfy that duty.
Oversee
They must oversee the implementation of those measures, continuously, which presumes they can judge whether crisis management would actually hold.
Train
Members of the management body are required to follow training on a regular basis, and entities are encouraged to offer similar training to their employees.
Article 20 also makes management bodies liable for infringements of the Article 21 duties, within the limits set by national law. In Germany, §38 BSIG spells this out as personal approval, oversight and training duties of the Geschäftsleitung, with liability to match.
Honesty matters here: the directive mandates measures and training, not the tabletop exercise itself. But when you have to prove that your management body is trained and genuinely oversees implementation, a webinar attendance certificate is thin: it proves presence, nothing more. A documented tabletop exercise proves judgement: which decisions the management body took under time pressure, when, on what information, and with what outcome. As training and oversight evidence, that is the strongest artefact you can produce.
Crisis management is a mandatory measure, not a bonus
Article 21(2)(c) lists business continuity (backup management, disaster recovery) and crisis management among the measures every covered entity must implement.
National laws copy this list; Germany anchors it in §30(2) BSIG: business continuity, backup management, recovery and crisis management. (Digital-infrastructure providers additionally fall under Implementing Regulation (EU) 2024/2690, which details these requirements.) Taking it seriously means more than firewalls and patch cycles:
- a crisis team with defined roles, deputies and alerting paths,
- recovery priorities set by the business, not by IT alone,
- the ability to communicate internally and externally when primary channels are down,
- and proof that all of this exists beyond paper.
A BCM manual on the shelf satisfies the letter of the law. Whether it survives contact with reality is decided in the first real incident, or, far more cheaply, in the first serious exercise.
The reporting chain: three deadlines you don't want to look up mid-incident
Article 23 requires a staged notification of significant incidents to the national CSIRT or competent authority. The clock starts when you become aware of the incident, not when the chaos ends.
Three deadlines look manageable on paper. In reality, the 24-hour question lands in the middle of the worst night your company has had: who decides the incident is significant? Who drafts the early warning while the same people are isolating systems? Who holds the portal credentials, and who covers for them on holiday? These questions decide between on time and late, and they cannot be asked for the first time on the day itself. In Germany, §32 BSIG mirrors this chain, with the BSI as the receiving authority.
That is exactly why Verdus exercises ship with dedicated reporting-chain injects: your team is confronted with the notification question at the least convenient realistic moment, the decision is captured with a timestamp. The debrief shows in black and white whether your early warning would have made the 24-hour window.
Rehearse emergencies: the regulators' own standards say it
National frameworks converge on the same point. Germany's BSI Standard 200-4, the national reference for business continuity management, and the IT-Grundschutz course dedicate an entire chapter to rehearsing emergencies (Notfälle üben).
That is no accident; it is the supervisory logic in one sentence: an emergency concept that has never been rehearsed is a hypothesis. Only an exercise shows whether alerting paths work, deputies step in, and decisions are taken where the plan says they are. Knowing the standard and executing it under pressure are two different maturity levels, and supervisors care about the second.
Verdus Cyber operationalises that requirement: instead of an annual paper walkthrough you get a live, escalating exercise in the browser whose timeline, decisions and findings drop straight into your BCM documentation. You are not exercising beside the standard: you are generating the exercise evidence that distinguishes a lived BCM.
What a NIS2-ready exercise looks like
Five things separate a defensible crisis exercise from an afternoon of slides, and all five are built into Verdus Cyber.
And DORA? Only if you are in finance.
DORA, Regulation (EU) 2022/2554, applies exclusively to financial entities and critical ICT third-party providers, and has applied since 17 January 2025. It brings its own, partly tighter reporting deadlines: initial report 4 hours after classifying an incident as major (at the latest 24 hours after awareness), intermediate report at 72 hours, final report after one month, plus explicit digital operational resilience testing duties, including scenario-based tests (Articles 25/26).
For every other sector, NIS2 and its national transpositions set the bar. If you are a financial entity, we have the matching scenario with the DORA reporting chain ready.
Frequently asked questions
How often should we run a tabletop exercise?
The directive does not set a fixed exercise interval. Article 20 requires management training on a regular basis without defining one. In practice, at least one serious exercise per year has become the norm, plus a further run after major changes: new systems, restructuring, a new crisis team. What matters most is that every exercise is documented.
Who should take part?
The core is your crisis team: the management body, IT and security, legal, communications and the affected business units. Because of Article 20, the management body belongs at the table, as decision-makers, not spectators. Verdus separates controller and participant views so a facilitator can steer the pressure deliberately.
Is a PowerPoint training session enough evidence?
A slide deck with an attendance list may formally count as training, but it is weak evidence: it proves presence, not capability. A documented exercise with timestamps and a decision log shows that the management body can actually assess risks: which is what Article 20 asks of it.
What do we need to document?
Scenario and assumptions, participants and roles, the timeline with timestamps, decisions taken with their rationale, gaps found and the measures derived from them. Verdus generates this package automatically in the debrief: a timeline with decision timestamps, findings and an action list.
Does DORA apply to us?
Only if you are a financial entity or a critical ICT third-party provider: DORA (EU) 2022/2554 is finance-only and has applied since 17 January 2025. Everyone else falls under NIS2 and its national transpositions. If in doubt, we clarify the classification in the first call.
What does a NIS2 tabletop exercise cost?
Honest answer: it depends on format and depth, self-moderated, specialist-led or through the partner programme. The three delivery models are on our pricing page; we give you a realistic range in the first call, not after three workshops.
See pricingMake your NIS2 duties exercise-proof.
In thirty minutes we will show you what a NIS2-ready exercise looks like for your organisation: scenario, reporting chain, debrief evidence.