Guides

NIS2 Guide · 8 min

NIS2 fines and penalties: how much, who is liable, and how to avoid them

NIS2 gives regulators real teeth: turnover-based fines, binding orders, and, for essential entities, the power to temporarily suspend a certification or ban a senior manager from their role. This guide explains what the penalties are, who is personally on the hook, how supervision differs for essential and important entities, and the practical way to stay out of trouble: implement the Article 21(2) measures and keep continuous, dated evidence that you do.

Key takeaways

  • Maximum fines are turnover-based: up to €10M or 2% of total worldwide annual turnover for essential entities, and €7M or 1.4% for important entities, whichever is higher.
  • The management body must approve and oversee the security measures (Art. 20) and can be held personally liable; for essential entities, regulators can temporarily ban a senior manager from their function (Art. 32(5)).
  • Fines are a last resort: the day-to-day exposure is binding orders, audits and the cost of proving diligence. Continuous, evidenced supply-chain monitoring is the cheapest insurance.

What NIS2 penalties cover

NIS2 (Directive (EU) 2022/2555) is transposed into national law by each member state, so the exact figures and procedures are set nationally, but the Directive fixes the floors for maximum administrative fines and the enforcement toolbox. Penalties attach to an entity's failure to meet its obligations: the Article 21(2) risk-management measures, the Article 23 incident-reporting duties, registration, and cooperation with the authorities.

Crucially, NIS2 is not only about money. Article 32 (essential entities) and Article 33 (important entities) give competent authorities a graduated set of powers, from warnings to binding instructions to, for essential entities, suspension and management bans. The fine is the headline; the operational measures are what most entities will actually encounter.

The maximum fines

Essential entities

Up to €10,000,000 or 2% of total worldwide annual turnover (preceding financial year), whichever is higher.

Larger operators in high-criticality sectors: energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space.

Important entities

Up to €7,000,000 or 1.4% of total worldwide annual turnover (preceding financial year), whichever is higher.

Other medium and large entities in the covered sectors, including postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.

These are maximum caps set by the Directive (Art. 34). Actual fines are decided nationally and must be effective, proportionate and dissuasive, taking into account the gravity, the duration and your cooperation. Confirm the exact rules in your country's transposition with qualified advice.

Personal and management liability

NIS2 deliberately puts cybersecurity on the board's desk. Under Article 20, the management body must approve the cyber risk-management measures, oversee their implementation, and can be held liable for failures. Members of management bodies must also follow training and are expected to offer similar training to their staff.

For essential entities, Article 32(5) goes further: where other enforcement has failed, competent authorities may temporarily suspend a certification or authorisation, and temporarily prohibit a person at CEO or legal-representative level from exercising managerial functions. That personal exposure is why NIS2 governance now reaches the top of the organisation.

See how your suppliers actually score

7-day free trial · no credit card · cancel anytime

The enforcement toolbox (beyond fines)

Before or alongside a fine, authorities can apply a range of binding measures (Art. 32 and 33). In practice, these are what you are most likely to face:

  • Warnings and binding instructions to remedy specific shortcomings within a deadline.
  • Orders to comply, to inform affected customers of a significant threat, or to implement audit recommendations.
  • Mandatory security audits and on-site inspections, at your own cost.
  • Designation of a monitoring officer to oversee your compliance for a set period.
  • Public disclosure of the infringement, and orders to make aspects of the breach public.
  • For essential entities only: temporary suspension of certification or authorisation, and a temporary management ban (Art. 32(5)).

Supervision differs by tier

Essential entities face proactive (ex-ante) and reactive (ex-post) supervision under Article 32: regular and targeted audits, on-site inspections, security scans and requests for information can happen whether or not there is any suspicion of a problem.

Important entities are supervised only ex-post under Article 33: authorities act when there is evidence or an indication of non-compliance, typically after an incident or a complaint. Either way, the burden is on you to demonstrate that appropriate measures were in place, which is far easier with continuous records than a once-a-year snapshot.

Sources: Directive (EU) 2022/2555 (NIS2), Articles 20, 32, 33 and 34 Maximum fine figures are set by the Directive; national transpositions set the exact rules and procedures. This guide is general information, not legal advice.

How norppa.io reduces your exposure

Most penalties trace back to two failures: inadequate Article 21(2) measures (especially supply-chain security), and an inability to prove diligence when asked. norppa.io addresses both by monitoring every supplier domain continuously and mapping each finding to the NIS2 article it informs.

Because every monitoring cycle is logged, you hold a continuous, dated audit trail, the evidence that supervision under Articles 32 and 33 asks for, rather than a point-in-time snapshot. That is what turns “we intended to” into “here is the record”, and it is the cheapest insurance against the fines and orders above.

Not ready to start? Get your country's NIS2 status

We'll send your country's NIS2 transposition status (authority, national law, key dates) plus a concise supplier due-diligence checklist. One email, then occasional NIS2 updates.

We never share your email. Unsubscribe in one click. Stored in the EU.

Prove your supply-chain diligence

See a sample supplier report (findings, evidence and NIS2 article mapping) in about two minutes.

7-day free trial · no credit card · cancel anytime

Last reviewed: 19 June 2026

This guide is general information about EU law, not legal advice. NIS2 takes effect through each EU Member State's national transposition law, which can differ in detail. Verify the obligations that apply to you with your competent authority or legal counsel.

Related guides

How to comply with NIS2: a step-by-step roadmap

The steps to NIS2 compliance in order: confirm scope, register, management accountability (Art. 20), the Article 21(2) measures, supply-chain security, incident reporting (Art. 23) and continuous, evidenced assurance.

Who is in scope for NIS2? Essential vs important entities, sectors and size thresholds

Determine whether NIS2 applies to you: the two tiers, the Annex I/II sectors, the size thresholds, size-independent exceptions, and how the supply chain pulls you in even if you're not designated.

NIS2 for suppliers: you're not designated, but your customers are

Most companies are never designated under NIS2, yet many must comply anyway. How a covered customer's Article 21(2)(d) supply-chain duty flows down to you, what they'll ask for, and how to respond credibly.

NIS2 and the supply chain requirement: what it means in practice

NIS2 requires essential and important entities to assess their supply chain cyber risks. Supplier tiering, 4th-party risk, Art. 23 notification, and what auditors look for.

Supplier cyber risk assessment: what automated NIS2 monitoring checks

All check categories explained: ransomware, dark web leaks, TLS/DNSSEC, cookie security, CVE/EPSS, sanctions, MX blacklists and SAQ. Finding lifecycle and NIS2 article mapping.

NIS2 Art. 21(2): supplier security checklist

Checklist for procurement and security teams: what to ask, what evidence to collect, and how to respond when a supplier falls short. Includes suggested evidence documents.

NIS2 supplier questionnaire (SAQ): what to ask, how to score it, and a free template

What to ask suppliers under Art. 21(2)(d), how to score answers and respond to gaps, why self-attestation needs verification, and a free copy-paste questionnaire template.

NIS2 incident reporting: the 24- and 72-hour deadlines explained

What counts as a significant incident, the Article 23 timeline (24-hour early warning, 72-hour notification, one-month final report), and when a supplier's incident becomes your obligation.

NIS2 and management responsibility: what boards and leadership must know

What NIS2 expects of the management body: approval and oversight duties, personal liability (Art. 20), training, board reporting KPIs, and the penalties under Art. 34.

ISO 27001 and NIS2: what your ISMS already covers, and the gaps it doesn't

If you hold ISO 27001, what carries over to NIS2 and what does not: statutory incident reporting, management liability, registration, and continuous supply-chain assurance: plus how to close the gap.

NIS2 vs DORA: how they differ, where they overlap, and which one applies to you

How the two EU regimes differ and overlap, why DORA is lex specialis for financial entities, which applies to you, and what both mean for third-party and supply-chain risk.

GDPR vs NIS2: how they overlap, where they differ, and when one incident triggers both

How GDPR and NIS2 differ and overlap, when one incident triggers both (GDPR Art. 33 72h to the DPA vs NIS2 Art. 23 24h/72h/1-month to the CSIRT), the Art. 35 cooperation and no-double-fine rule, and what both mean for supplier due diligence.

The EU Cyber Resilience Act (CRA): scope, timeline and what it means for your supply chain

What the CRA requires, its phased dates (in force 2024, reporting Sept 2026, full compliance Dec 2027), who is in scope and why pure SaaS often isn't, how it complements NIS2, and what it means for procurement and supplier due diligence.

The EU AI Act: risk tiers, the timeline, and what deployers must do (Article 26)

What the EU AI Act requires: the risk tiers, the phased dates (in force 2024, prohibited Feb 2025, GPAI Aug 2025, high-risk Aug 2026), the Article 26 deployer obligations, how it stacks with NIS2 and the GDPR, and what it means for AI procurement.