Last updated: 9 October 2026
Quick answer: Under Article 34 of NIS2, essential entities face maximum fines of at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face at least EUR 7 million or 1.4%. National laws set the final amounts, and senior managers of essential entities can face temporary bans.
NIS2 fines and penalties get a lot of attention, and for good reason. The directive moved cybersecurity enforcement in the EU from a patchwork of modest sanctions to turnover-based fines that look much more like GDPR, plus direct accountability for management bodies.
But the headline numbers are only part of the picture. The real exposure depends on whether you are an essential or important entity, how your Member State transposed the directive, and which enforcement tools the authority reaches for first. This guide explains each layer, with a worked example and a practical checklist for compliance teams.
What are the NIS2 fines and penalties?
NIS2 sets minimum maximums for administrative fines, and Member States must make them available in national law. Article 34 of the NIS2 Directive (EU) 2022/2555 covers infringements of the cybersecurity risk-management measures in Article 21 and the reporting obligations in Article 23.
| Entity type | Maximum fine (at least) | Supervision | Temporary management ban |
|---|---|---|---|
| Essential entity | EUR 10 million or 2% of total worldwide annual turnover, whichever is higher | Ex ante and ex post (Article 32) | Yes, as a last resort (Article 32(5)) |
| Important entity | EUR 7 million or 1.4% of total worldwide annual turnover, whichever is higher | Ex post only (Article 33) | No |
“At least” matters. These are floors for the maximum, not caps: a Member State may set higher ceilings. Turnover is measured for the preceding financial year of the undertaking the entity belongs to, which can mean the group rather than the local subsidiary.
Article 34 also lets Member States use periodic penalty payments to compel an entity to stop an infringement, and leaves them to decide whether and how far public administration entities can be fined.
For infringements outside Articles 21 and 23, Article 36 requires Member States to lay down their own effective, proportionate and dissuasive penalties and to notify the Commission of them by 17 January 2025.
How are NIS2 fines calculated?
There is no formula in the directive. Authorities decide case by case, and Article 34 requires fines to be effective, proportionate and dissuasive, taking account of the factors in Article 32(7).
Those factors are:
- Seriousness of the infringement. The directive treats as serious: repeated violations, failure to notify or remedy significant incidents, failure to remedy deficiencies after binding instructions, obstructing audits or monitoring, and giving false or grossly inaccurate information.
- Duration of the infringement.
- Previous relevant infringements.
- Damage caused, including financial or economic losses, effects on other services and the number of users affected.
- Intent or negligence.
- Measures taken to prevent or mitigate the damage.
- Adherence to approved codes of conduct or certification mechanisms.
- Cooperation with the competent authority.
Worked example
Consider two hypothetical companies, using the directive’s minimum figures:
- An essential entity in a group with EUR 2 billion worldwide turnover. 2% is EUR 40 million, which is higher than EUR 10 million, so the maximum available fine is at least EUR 40 million.
- An important entity with EUR 300 million turnover. 1.4% is EUR 4.2 million, which is lower than EUR 7 million, so the maximum is at least EUR 7 million.
Neither figure is what an authority would impose. It is the ceiling within which the Article 32(7) factors are weighed.
In practice: the factors most within your control are the ones auditors and authorities see first: documented risk-management measures, timely incident reporting and honest cooperation. Evidence of all three is your best mitigation.
What other enforcement measures can authorities use?
Fines are one tool among many, and often not the first. For essential entities, Article 32(4) gives authorities the power to:
- issue warnings about infringements
- adopt binding instructions, including deadlines to remedy deficiencies
- order the entity to cease infringing conduct
- order compliance with Article 21 or Article 23 in a specified way and time
- order the entity to inform affected service recipients about a significant cyber threat
- order implementation of security audit recommendations
- designate a monitoring officer to oversee compliance for a set period
- order the entity to make aspects of the infringement public
- impose, or request the imposition of, an administrative fine
Important entities are subject to ex post supervision under Article 33, with a similar set of measures but no monitoring officer and no temporary suspension or management ban.
Common mistake: treating an order to publish an infringement as minor. Public disclosure can hurt customer trust and tenders far more than a modest fine.
Can managers be held personally liable under NIS2?
Yes. NIS2 makes cybersecurity a management responsibility, and national laws must allow individuals to be held liable.
- Article 20(1): management bodies must approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements of Article 21.
- Article 20(2): members of management bodies must follow training.
- Article 32(5): where earlier enforcement measures have not worked and a deadline passes, authorities can temporarily suspend a certification or authorisation for an essential entity’s services, and ask a court or relevant body to temporarily prohibit a person discharging managerial responsibilities at CEO or legal representative level from exercising managerial functions.
- Article 32(6): natural persons who represent or control an essential entity must be able to be held liable for breaching their duties to ensure compliance.
Temporary suspensions and bans apply only until the entity remedies the deficiencies, and they are subject to procedural safeguards. They do not apply to public administration entities.
A documented approval trail helps here. Board minutes that show the risk-management measures were approved, reviewed and resourced are evidence that management took its Article 20 duties seriously. A risk management module that links board decisions to specific risks and controls makes that trail easier to produce.
How do NIS2 fines compare with GDPR and DORA?
The three regimes overlap, and one incident can raise questions under all of them. This comparison shows the key differences.
| Regime | Top-tier fine | Who sets final amounts | Management accountability |
|---|---|---|---|
| NIS2 | At least EUR 10m or 2% (essential); EUR 7m or 1.4% (important) | Member States, via national law | Explicit (Articles 20 and 32) |
| GDPR | Up to EUR 20m or 4% of worldwide turnover (Article 83(5)) | Directly in the Regulation | Indirect |
| DORA | Member States set administrative penalties for financial entities; periodic penalty payments for critical ICT third-party providers | Member States and the ESAs | Management body responsible for ICT risk (Article 5) |
Article 35 of NIS2 prevents double fining for the same conduct in one important case. Where an infringement of Articles 21 or 23 involves a personal data breach and a data protection authority has already fined the entity under GDPR, the NIS2 authority may not impose an administrative fine for the same conduct. It can still use its other enforcement measures. NIS2 authorities must also inform the data protection authority without undue delay when an infringement may involve a notifiable personal data breach.
Because the same controls often satisfy all three, a cross-framework control map reduces both effort and exposure. Our article on managing the overlap between DORA, NIS2 and the EU AI Act explains the approach.
Do national NIS2 laws change the fines?
Yes. NIS2 is a directive, so the enforceable fines are the ones in each national law. Member States had to transpose it by 17 October 2024, but many were late.
On 7 May 2025 the European Commission sent reasoned opinions to 19 Member States for failing to notify full transposition. On 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice, asking for financial sanctions until they complete transposition. The Commission’s transposition status page tracks each country’s progress, and our NIS2 transposition tracker summarises it by Member State.
In January 2026 the Commission also proposed targeted amendments to NIS2, covering jurisdiction rules, ransomware reporting and cross-border supervision. Until they are adopted, the Article 34 fine levels described here remain the law.
Germany is a useful example. Its NIS2 implementation act was published in December 2025 and applies from the following day, with fines matching the directive’s figures: up to EUR 10 million or 2% for particularly important entities and EUR 7 million or 1.4% for important entities. Other Member States may set higher ceilings, different procedures or extra penalties for obligations such as registration.
If you operate in several Member States, check each national law for the fine levels, the competent authority and any registration deadlines. Multi-country groups often keep a single register of national obligations and track them alongside their controls. You can start your 14-day free trial to build that register from the frameworks library.
NIS2 penalty readiness checklist
- Confirm whether each group entity is essential, important or out of scope, in each Member State where it operates.
- Identify the competent authority and the national fine levels for each country.
- Record management body approval of Article 21 measures, and keep training records for board members.
- Test your 24-hour early warning, 72-hour notification and one-month final report process under Article 23.
- Link your NIS2 and GDPR breach processes so the incident and data breach workflow covers both authorities.
- Keep evidence of cooperation, corrective actions and audit follow-up, since these count as mitigating factors.
Key takeaways
- Essential entities face fines of at least EUR 10 million or 2% of worldwide turnover; important entities at least EUR 7 million or 1.4%.
- These are minimum ceilings; national laws set the final amounts and may go higher.
- Authorities weigh eight Article 32(7) factors, including cooperation and mitigation.
- Managers of essential entities can face temporary bans, and national law must allow personal liability.
- No NIS2 fine can be imposed where a GDPR fine has already been imposed for the same conduct.
Frequently asked questions
What is the maximum NIS2 fine?
The directive requires Member States to set a maximum of at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher, for essential entities, and at least EUR 7 million or 1.4% for important entities. Because these are minimum ceilings, some national laws may allow higher fines. Check the transposing law in each country where you operate.
Are NIS2 fines already being enforced?
Enforcement depends on national law. NIS2 fines only become available once a Member State has transposed the directive and designated its competent authorities. Several countries were late: the Commission sent reasoned opinions to 19 Member States in May 2025 and referred four to the Court of Justice in July 2026. Where national laws apply, authorities can already supervise and sanction in-scope entities.
Can a company be fined under both NIS2 and GDPR for the same incident?
Not with two fines for the same conduct. Article 35 of NIS2 says that where a data protection authority has imposed a GDPR fine for conduct arising from the same behaviour, the NIS2 authority must not impose an administrative fine. It can still use other enforcement measures, such as binding instructions or orders to remedy deficiencies.
Can CEOs be banned under NIS2?
For essential entities, yes, as a last resort. If earlier measures fail and a deadline passes, authorities can ask a court or relevant body to temporarily prohibit a person with managerial responsibility at CEO or legal representative level from exercising managerial functions. The ban lasts only until the entity remedies the deficiencies.
Do NIS2 fines apply to public administration entities?
Member States decide. Article 34 leaves it to each country to set rules on whether, and to what extent, administrative fines can be imposed on public administration entities. The temporary suspension and management ban powers in Article 32(5) do not apply to public administration entities at all.
Reducing your NIS2 enforcement exposure
NIS2 fines are large, but authorities have a wide toolkit and must weigh how seriously the entity took its obligations. The best protection is the same work that makes you secure: documented risk-management measures approved by management, reliable incident reporting and evidence of continuous improvement.
Enactia’s AI-powered GRC platform helps compliance teams map NIS2 obligations to their existing controls and track national requirements in one place. To discuss your NIS2 programme, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
