NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
NIS2 Fines and Penalties: What You Actually Risk
Learn

NIS2 Fines and Penalties: What You Actually Risk

·Alexander Sverdlov

Most coverage of NIS2 fines and penalties stops at two numbers: EUR 10 million and 2 percent. Those numbers are real, but they are the least interesting part of the enforcement regime, and treating them as the whole picture leads boards to the wrong conclusion. The financial ceiling is a floor set by the Directive, the non-financial sanctions bite faster, and the personal liability provisions are the part that changes behaviour. Much of the underlying measure set overlaps with certification, which we map in NIS2 vs ISO 27001. Two of the Article 21 measures have their own guides: access reviews and building a risk register. Article 21(d) supply chain security is worked through in vendor security questionnaires.

This page sets out what Directive (EU) 2022/2555 actually authorises, which failures trigger it, why your real exposure depends on your Member State rather than on the Directive, and what a supervisor asks for first.

On this page
  1. NIS2 penalties at a glance
  2. Essential or important: the classification that sets your ceiling
  3. What the fines actually are
  4. The non-financial sanctions people miss
  5. Personal liability for management bodies
  6. Which failures trigger a penalty
  7. The reporting clocks that create most exposure
  8. Why your real exposure depends on your Member State
  9. What supervisors ask for first
  10. Frequently asked questions

NIS2 penalties at a glance

Essential entities Important entities
Maximum fineAt least EUR 10,000,000 or 2% of total worldwide annual turnover, whichever is higherAt least EUR 7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher
Supervision modelEx ante and ex post: supervisors may act without a triggerEx post: action follows evidence of non-compliance
Suspension powersCertification or authorisation may be suspendedNot available
Ban on managerial functionsA temporary ban on an individual exercising management functions is availableNot available
Management liabilityYes, the management body approves the measures and oversees implementationYes, same duty
NIS2 fine ceilings: EUR 10 million or 2 percent for essential entities, EUR 7 million or 1.4 percent for important entities
The Directive sets minimum ceilings. Member States are free to legislate higher ones.

Essential or important: the classification that sets your ceiling

Everything in the enforcement regime keys off one question: are you an essential entity or an important entity? The Directive answers it from your sector and your size. Sectors listed in Annex I are the high-criticality ones such as energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex II covers other critical sectors including postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.

Size then does most of the sorting. Broadly, large entities in Annex I sectors are essential; medium-sized entities in Annex I and entities in Annex II are important. There are entities that qualify regardless of size, including certain digital infrastructure providers and entities that are the sole provider of a critical service in a Member State.

If you are not certain which side you fall on, work through what NIS2 is and who must comply first. The classification changes your fine ceiling, whether a supervisor may inspect you without cause, and whether the suspension powers apply to you at all.

Essential and important entities under NIS2 compared by supervision model and available sanctions
The gap between essential and important is supervisory posture, not just the size of the fine.

What the fines actually are

For essential entities, Member States must provide for administrative fines with a maximum of at least EUR 10,000,000 or at least 2 percent of the total worldwide annual turnover of the undertaking in the preceding financial year, whichever is higher.

For important entities, the maximum is at least EUR 7,000,000 or at least 1.4 percent of total worldwide annual turnover, whichever is higher.

Read those two sentences carefully, because two words in them do a lot of work.

"At least" means these are minimum ceilings the Directive requires Member States to make available. A national legislature may set a higher maximum, and some have. The Directive does not cap your exposure; it floors it.

"Whichever is higher" means turnover-based calculation applies to large undertakings and the fixed sum applies to smaller ones. For a group with substantial worldwide turnover, the percentage is the operative figure and the EUR 10 million number is irrelevant.

Note also that the turnover measure is worldwide and refers to the undertaking, not to the revenue of the in-scope service or the local subsidiary. A modest European operation belonging to a large international group can face a ceiling calculated on the whole group's turnover.

The non-financial sanctions people miss

Fines get the headlines and arrive last. The measures that supervisors reach for earlier are administrative, and for an operating business several of them hurt more than a fine.

  • Binding instructions and orders to comply. A supervisor can order you to remedy a deficiency in a specified way and within a specified time. This consumes engineering capacity you had allocated elsewhere.
  • An order to inform affected customers. You can be required to notify the recipients of your services about a significant threat. This is a commercial event, not a compliance one.
  • An order to make the infringement public. Publication of aspects of non-compliance, attributed to you.
  • Security audits imposed on you. Binding instructions can include an audit carried out by an independent body, at your cost.
  • Suspension of certification or authorisation. For essential entities, a competent authority may suspend a certification or authorisation concerning services or activities. If your right to operate depends on that authorisation, this is existential rather than expensive.

The ordering matters. A supervisor who finds a deficiency generally starts with warnings and binding instructions. Fines follow a failure to act on those. In practice, organisations are rarely fined for the original weakness; they are fined for ignoring the instruction to fix it.

Personal liability for management bodies

This is the provision that changed how NIS2 lands in boardrooms. Management bodies of in-scope entities must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for failures. Members of management bodies are also required to follow training, and are encouraged to offer similar training to staff.

Two consequences follow. First, "the security team is handling it" is not a defence, because the duty to approve and oversee is placed on the management body by name. Second, for essential entities, competent authorities may temporarily prohibit a person discharging managerial responsibilities at chief executive or legal representative level from exercising managerial functions in that entity.

The practical implication is documentary. If the board approved the measures, there must be a record of what was approved and when. If the board oversees implementation, there must be a record of what it was shown and what it asked for. An organisation that cannot produce those records has a governance failure that is visible immediately, before anyone examines a single technical control.

NIS2 gap assessment scoring Article 21 measures with prioritised remediation
Supervisors examine whether the management body approved and oversaw the measures. That has to be evidenced, not asserted.

Which failures trigger a penalty

Two families of obligation carry the enforcement weight.

The risk-management measures in Article 21. These are the ten areas every in-scope entity must cover: risk analysis and information system security policies; incident handling; business continuity, including backup management and crisis management; supply chain security; security in acquisition, development and maintenance; policies to assess the effectiveness of measures; basic cyber hygiene and training; cryptography and encryption; human resources security, access control and asset management; and multi-factor authentication, secured communications and secured emergency communications. The measures must be appropriate and proportionate, and the entity must be able to show that they are.

The reporting obligations in Article 23. These are the ones most likely to be missed under pressure, because they run on clocks that start during an incident.

Supply chain security deserves a specific note. Article 21 requires you to account for the security of your suppliers and service providers, including the quality of their practices. A weakness introduced by a supplier is your compliance problem, which is why vendor assessment records are among the first things requested.

The reporting clocks that create most exposure

A significant incident triggers a staged notification. The clock starts when you become aware of the incident, not when you resolve it, and not when you finish deciding whether it counts.

NIS2 Article 23 reporting timeline: 24 hour early warning, 72 hour notification, one month final report
The clock starts at awareness. Deciding whether an incident is significant is itself inside the 24 hour window.
  • Within 24 hours: an early warning to the CSIRT or, where applicable, the competent authority, indicating whether the incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact.
  • Within 72 hours: an incident notification updating the early warning with an initial assessment, including severity and impact, and indicators of compromise where available.
  • Within one month: a final report with a detailed description, the type of threat or root cause, the mitigation measures applied and ongoing, and any cross-border impact.

The exposure is structural. Twenty-four hours is not long enough to run a classification decision through a committee, so the decision has to be pre-made: written criteria, a named decision-maker and an out-of-hours route. Organisations that discover this during their first incident tend to miss the first clock, and a missed statutory deadline is a clean, documented, indefensible finding. If you also fall under DORA, note that the two regimes classify and time incidents differently; DORA and NIS2 compared sets out which applies to you and where they diverge.

Why your real exposure depends on your Member State

NIS2 is a Directive, not a Regulation. It does not apply to you directly. It obliges each Member State to transpose it into national law, and the national law is what a supervisor enforces against you.

That has practical consequences. The fine ceilings above are minimums, and national maxima may be higher. The competent authority and the CSIRT you report to are national bodies with their own reporting portals and formats. Registration duties, deadlines and the exact scope of who is caught vary. Transposition has not moved at the same pace everywhere, so the enforcement picture differs by country.

Per-country NIS2 transposition tracking with national deviations from the Directive
The Directive sets the floor. The national transposition sets what you are actually held to.

For a group operating in several Member States, this is the difference between one compliance programme and several. The measures can be common; the registration, the reporting route and the local deviations cannot be assumed to be. Building your programme against the Directive alone leaves you compliant with a text that no supervisor enforces.

What supervisors ask for first

Across supervisory practice the opening requests are consistent, and none of them are technical.

  1. Evidence that the management body approved the measures. Minutes, dated, naming what was approved.
  2. Your risk analysis and information system security policy. Current, and version-controlled.
  3. Your incident handling process, and the record of incidents. Including the ones you decided were not significant, and why.
  4. Your supplier assessments. Which suppliers, assessed against what, and when.
  5. Evidence that measures are tested, not just written. Article 21 requires policies to assess the effectiveness of the measures. A policy nobody has tested is a document, not a control.

Every one of these is a documentation question. The most common cause of an adverse finding is not a missing control; it is a control that exists but cannot be evidenced on request.

Do this in Venvera

Venvera runs NIS2 as a maintained control set with the Article 21 measures, per-country transposition differences, incident classification with the Article 23 clocks running from the moment you classify, supplier assessments and a board view that records what the management body approved and when. Evidence attached once is reused by every other framework that asks for the same control, so an organisation running NIS2 alongside ISO 27001 or DORA does the work once. See the NIS2 workspace, or start with the free NIS2 compliance checklist if you want to find your gaps before committing to anything. Pricing is published and flat, from EUR 399 per month.

Frequently asked questions

What is the maximum NIS2 fine?

For essential entities, Member States must allow a maximum of at least EUR 10,000,000 or at least 2 percent of total worldwide annual turnover, whichever is higher. For important entities it is at least EUR 7,000,000 or at least 1.4 percent. These are minimum ceilings, so national law may set higher maxima.

Can directors be personally fined under NIS2?

Management bodies must approve the cybersecurity risk-management measures and oversee implementation, and can be held liable for failures. For essential entities, authorities may also temporarily prohibit an individual at chief executive or legal representative level from exercising managerial functions in that entity. The exact form of personal consequence is set by national transposition.

Does a missed reporting deadline automatically mean a fine?

Not automatically, but it is the cleanest possible finding: a statutory deadline either was or was not met, with no room for interpretation. In practice supervisors escalate to fines after binding instructions are ignored, so the risk is the pattern rather than the single miss.

Do NIS2 penalties apply if my Member State has not finished transposing?

Enforcement runs on national law, so the position depends on where you operate. Transposition status differs across the Union, which is why exposure has to be assessed per country rather than against the Directive alone.

We are an important entity. Are we really supervised less?

You are supervised differently. Important entities are subject to ex post supervision, meaning authorities act when they have evidence suggesting non-compliance, rather than proactively. The obligations under Article 21 and Article 23 are the same. The difference is when a supervisor arrives, not what they expect to find.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

CONTINUE READING