Management approval + a record of employee notification (preferably electronic signature/log) is the standard. In the NIS2 world, the management body’s approval record has gained additional importance.
Under NIS2 the management body does more than sign off: it must approve the cybersecurity risk measures, oversee their implementation, and undergo training — and it can be held personally liable for failing to. So the approval record should show engagement, not just a signature, and reach the board itself wherever the entity is in scope. The wider frame is ISO/IEC 27001, under which the ISMS policy is expected to be owned by top management and reviewed at regular intervals. Separate acceptance texts for role-based undertakings — IT, HR, supplier access — make it clear where responsibility sits, and are far easier to evidence when an auditor asks.
Shall we apply this matter to your situation?
Tell us your specific situation in a few sentences; we'll assess it with the right team.