Most coverage of NIS2 fines and penalties stops at two numbers: EUR 10 million and 2 percent. Those numbers are real, but they are the least interesting part of the enforcement regime, and treating them as the whole picture leads boards to the wrong conclusion. The financial ceiling is a floor set by the Directive, the non-financial sanctions bite faster, and the personal liability provisions are the part that changes behaviour. Much of the underlying measure set overlaps with certification, which we map in NIS2 vs ISO 27001. Two of the Article 21 measures have their own guides: access reviews and building a risk register. Article 21(d) supply chain security is worked through in vendor security questionnaires.
This page sets out what Directive (EU) 2022/2555 actually authorises, which failures trigger it, why your real exposure depends on your Member State rather than on the Directive, and what a supervisor asks for first.
- NIS2 penalties at a glance
- Essential or important: the classification that sets your ceiling
- What the fines actually are
- The non-financial sanctions people miss
- Personal liability for management bodies
- Which failures trigger a penalty
- The reporting clocks that create most exposure
- Why your real exposure depends on your Member State
- What supervisors ask for first
- Frequently asked questions
NIS2 penalties at a glance
| Essential entities | Important entities | |
|---|---|---|
| Maximum fine | At least EUR 10,000,000 or 2% of total worldwide annual turnover, whichever is higher | At least EUR 7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher |
| Supervision model | Ex ante and ex post: supervisors may act without a trigger | Ex post: action follows evidence of non-compliance |
| Suspension powers | Certification or authorisation may be suspended | Not available |
| Ban on managerial functions | A temporary ban on an individual exercising management functions is available | Not available |
| Management liability | Yes, the management body approves the measures and oversees implementation | Yes, same duty |

Essential or important: the classification that sets your ceiling
Everything in the enforcement regime keys off one question: are you an essential entity or an important entity? The Directive answers it from your sector and your size. Sectors listed in Annex I are the high-criticality ones such as energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex II covers other critical sectors including postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.
Size then does most of the sorting. Broadly, large entities in Annex I sectors are essential; medium-sized entities in Annex I and entities in Annex II are important. There are entities that qualify regardless of size, including certain digital infrastructure providers and entities that are the sole provider of a critical service in a Member State.
If you are not certain which side you fall on, work through what NIS2 is and who must comply first. The classification changes your fine ceiling, whether a supervisor may inspect you without cause, and whether the suspension powers apply to you at all.

What the fines actually are
For essential entities, Member States must provide for administrative fines with a maximum of at least EUR 10,000,000 or at least 2 percent of the total worldwide annual turnover of the undertaking in the preceding financial year, whichever is higher.
For important entities, the maximum is at least EUR 7,000,000 or at least 1.4 percent of total worldwide annual turnover, whichever is higher.
Read those two sentences carefully, because two words in them do a lot of work.
"At least" means these are minimum ceilings the Directive requires Member States to make available. A national legislature may set a higher maximum, and some have. The Directive does not cap your exposure; it floors it.
"Whichever is higher" means turnover-based calculation applies to large undertakings and the fixed sum applies to smaller ones. For a group with substantial worldwide turnover, the percentage is the operative figure and the EUR 10 million number is irrelevant.
Note also that the turnover measure is worldwide and refers to the undertaking, not to the revenue of the in-scope service or the local subsidiary. A modest European operation belonging to a large international group can face a ceiling calculated on the whole group's turnover.
The non-financial sanctions people miss
Fines get the headlines and arrive last. The measures that supervisors reach for earlier are administrative, and for an operating business several of them hurt more than a fine.
- Binding instructions and orders to comply. A supervisor can order you to remedy a deficiency in a specified way and within a specified time. This consumes engineering capacity you had allocated elsewhere.
- An order to inform affected customers. You can be required to notify the recipients of your services about a significant threat. This is a commercial event, not a compliance one.
- An order to make the infringement public. Publication of aspects of non-compliance, attributed to you.
- Security audits imposed on you. Binding instructions can include an audit carried out by an independent body, at your cost.
- Suspension of certification or authorisation. For essential entities, a competent authority may suspend a certification or authorisation concerning services or activities. If your right to operate depends on that authorisation, this is existential rather than expensive.
The ordering matters. A supervisor who finds a deficiency generally starts with warnings and binding instructions. Fines follow a failure to act on those. In practice, organisations are rarely fined for the original weakness; they are fined for ignoring the instruction to fix it.
Personal liability for management bodies
This is the provision that changed how NIS2 lands in boardrooms. Management bodies of in-scope entities must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for failures. Members of management bodies are also required to follow training, and are encouraged to offer similar training to staff.
Two consequences follow. First, "the security team is handling it" is not a defence, because the duty to approve and oversee is placed on the management body by name. Second, for essential entities, competent authorities may temporarily prohibit a person discharging managerial responsibilities at chief executive or legal representative level from exercising managerial functions in that entity.
The practical implication is documentary. If the board approved the measures, there must be a record of what was approved and when. If the board oversees implementation, there must be a record of what it was shown and what it asked for. An organisation that cannot produce those records has a governance failure that is visible immediately, before anyone examines a single technical control.

Which failures trigger a penalty
Two families of obligation carry the enforcement weight.
The risk-management measures in Article 21. These are the ten areas every in-scope entity must cover: risk analysis and information system security policies; incident handling; business continuity, including backup management and crisis management; supply chain security; security in acquisition, development and maintenance; policies to assess the effectiveness of measures; basic cyber hygiene and training; cryptography and encryption; human resources security, access control and asset management; and multi-factor authentication, secured communications and secured emergency communications. The measures must be appropriate and proportionate, and the entity must be able to show that they are.
The reporting obligations in Article 23. These are the ones most likely to be missed under pressure, because they run on clocks that start during an incident.
Supply chain security deserves a specific note. Article 21 requires you to account for the security of your suppliers and service providers, including the quality of their practices. A weakness introduced by a supplier is your compliance problem, which is why vendor assessment records are among the first things requested.
The reporting clocks that create most exposure
A significant incident triggers a staged notification. The clock starts when you become aware of the incident, not when you resolve it, and not when you finish deciding whether it counts.

- Within 24 hours: an early warning to the CSIRT or, where applicable, the competent authority, indicating whether the incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact.
- Within 72 hours: an incident notification updating the early warning with an initial assessment, including severity and impact, and indicators of compromise where available.
- Within one month: a final report with a detailed description, the type of threat or root cause, the mitigation measures applied and ongoing, and any cross-border impact.
The exposure is structural. Twenty-four hours is not long enough to run a classification decision through a committee, so the decision has to be pre-made: written criteria, a named decision-maker and an out-of-hours route. Organisations that discover this during their first incident tend to miss the first clock, and a missed statutory deadline is a clean, documented, indefensible finding. If you also fall under DORA, note that the two regimes classify and time incidents differently; DORA and NIS2 compared sets out which applies to you and where they diverge.
Why your real exposure depends on your Member State
NIS2 is a Directive, not a Regulation. It does not apply to you directly. It obliges each Member State to transpose it into national law, and the national law is what a supervisor enforces against you.
That has practical consequences. The fine ceilings above are minimums, and national maxima may be higher. The competent authority and the CSIRT you report to are national bodies with their own reporting portals and formats. Registration duties, deadlines and the exact scope of who is caught vary. Transposition has not moved at the same pace everywhere, so the enforcement picture differs by country.

For a group operating in several Member States, this is the difference between one compliance programme and several. The measures can be common; the registration, the reporting route and the local deviations cannot be assumed to be. Building your programme against the Directive alone leaves you compliant with a text that no supervisor enforces.
What supervisors ask for first
Across supervisory practice the opening requests are consistent, and none of them are technical.
- Evidence that the management body approved the measures. Minutes, dated, naming what was approved.
- Your risk analysis and information system security policy. Current, and version-controlled.
- Your incident handling process, and the record of incidents. Including the ones you decided were not significant, and why.
- Your supplier assessments. Which suppliers, assessed against what, and when.
- Evidence that measures are tested, not just written. Article 21 requires policies to assess the effectiveness of the measures. A policy nobody has tested is a document, not a control.
Every one of these is a documentation question. The most common cause of an adverse finding is not a missing control; it is a control that exists but cannot be evidenced on request.
Do this in Venvera
Venvera runs NIS2 as a maintained control set with the Article 21 measures, per-country transposition differences, incident classification with the Article 23 clocks running from the moment you classify, supplier assessments and a board view that records what the management body approved and when. Evidence attached once is reused by every other framework that asks for the same control, so an organisation running NIS2 alongside ISO 27001 or DORA does the work once. See the NIS2 workspace, or start with the free NIS2 compliance checklist if you want to find your gaps before committing to anything. Pricing is published and flat, from EUR 399 per month.
Frequently asked questions
What is the maximum NIS2 fine?
For essential entities, Member States must allow a maximum of at least EUR 10,000,000 or at least 2 percent of total worldwide annual turnover, whichever is higher. For important entities it is at least EUR 7,000,000 or at least 1.4 percent. These are minimum ceilings, so national law may set higher maxima.
Can directors be personally fined under NIS2?
Management bodies must approve the cybersecurity risk-management measures and oversee implementation, and can be held liable for failures. For essential entities, authorities may also temporarily prohibit an individual at chief executive or legal representative level from exercising managerial functions in that entity. The exact form of personal consequence is set by national transposition.
Does a missed reporting deadline automatically mean a fine?
Not automatically, but it is the cleanest possible finding: a statutory deadline either was or was not met, with no room for interpretation. In practice supervisors escalate to fines after binding instructions are ignored, so the risk is the pattern rather than the single miss.
Do NIS2 penalties apply if my Member State has not finished transposing?
Enforcement runs on national law, so the position depends on where you operate. Transposition status differs across the Union, which is why exposure has to be assessed per country rather than against the Directive alone.
We are an important entity. Are we really supervised less?
You are supervised differently. Important entities are subject to ex post supervision, meaning authorities act when they have evidence suggesting non-compliance, rather than proactively. The obligations under Article 21 and Article 23 are the same. The difference is when a supervisor arrives, not what they expect to find.





