Outcome · Not the person left holding it

Not being the person personally on the hook when the supervisor asks

Art. 5(1) DORA, Art. 20 NIS2 and Art. 5(2) GDPR put accountability for compliance on the management body — and NIS2 lets member states hold managers personally liable. The protection is not a binder of policies but a record: what was checked, against which article, by whom, when, and what was decided about the gaps. Audomate produces that record as a by-product of the work you do anyway.

01

Accountability is written into the rules

Art. 5 DORA: the management body “bears the ultimate responsibility”. Art. 20 NIS2: management approves the measures, oversees them and can be held liable. Art. 5(2) GDPR: the controller has to be able to demonstrate compliance.

02

“We had a policy” is not a defence

The supervisor asks what was assessed, when, and what the board did about the findings. A dated audit trail answers that; a folder of PDFs does not.

03

The decisions about gaps matter most

Accepting a risk is allowed; being unaware of it is not. Audomate records who accepted what, and with which compensating control.

04

Readable by the board, ready for the supervisor

One report per regulation: status, open items, decisions, dates. Ten minutes to read; defensible in an inspection.

What the supervisor will ask

  • When did you last assess ICT risk / your processing activities / your security measures? Against which requirements?
  • What did the assessment show, and what did the board decide about each finding?
  • Who was responsible for each remediation action, and when was completion verified?
  • How do you know the assessment reflects the current version of the rules?
  • Where is the evidence?

What the record in Audomate contains

ElementHow it is produced
Assessment date and framework versionEvery audit run is stamped with the version of the regulation it checked against
Findings with citationsAn article and a page for each; ungrounded findings marked “for review”, never asserted
Decisions about gapsFix, accept with a compensating control, or out of scope — each with a person and a date
Remediation trailDrafts accepted, documents re-audited, requirement re-verified
Board reportGenerated per regulation; the same document, redacted if needed, for the supervisor
Verification page (coming soon)A public statement of scope, date and validity

For the person who signs

Whether you are the CEO of a software house, the DPO at a SaaS company or the board member responsible for ICT at an insurer, the question is the same: can you show, as at a given date, that you knew where you stood and acted reasonably? Audomate is built so that the answer is a report you already have, rather than a reconstruction after the letter arrives.

See the board report in a pilot

Questions we get most often

Art. 20(1) NIS2 requires management bodies to approve and oversee cybersecurity risk management measures and to “be held liable” for infringements, and Art. 32(6) lets authorities request a temporary ban on management functions at essential entities. The detail is set by national transposition; in Poland, by the amended KSC act.
It is a contemporaneous record, dated, with citations to documents and to the version of the regulation — the kind supervisors and auditors ask for. It is not a legal opinion; it shows what was done and when.
You need a record. The report is one page and generates itself; whether you call it a board report or a founder's note makes no difference to a supervisor — the date and the content do.

Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.

Reach this outcome in four weeks

One regulation, your real documents, a cited gap list and remediation drafts — plus a verified mark if you pass.