NIS2 Recital 137

This Directive should aim to ensure a high level of responsibility for the cybersecurity risk-management measures and reporting obligations at the level of the essential and important entities. Therefore, the management bodies of the essential and important entities should approve the cybersecurity risk-management measures and oversee their implementation.

NIS2 is a Directive: the binding obligations live in each Member State's transposing national law, and this is the EU Directive text those laws implement.

Source text: EUR-Lex, Official Journal HTML (CELEX 32022L2555). The parser was validated against the anchor articles verified in REP-08.