High-stakes

NIS2 Fines & Penalties 2026

NIS2 introduces some of the highest cybersecurity fines in EU history — up to 10 million EUR or 2% of global annual turnover, plus personal liability for management. Here's everything you need to know.

Fine structure at a glance

Essential Entities

EUR 10M

or 2% of global annual turnover — whichever is higher

Important Entities

EUR 7M

or 1.4% of global annual turnover — whichever is higher

How NIS2 fines are calculated

The headline numbers are maximums, not flat fees. For each band the authority applies the figure that is higher — the fixed euro ceiling or the percentage of turnover. The percentage is calculated on total worldwide annual turnover of the preceding financial year, and for a company that belongs to a group it is the group's turnover that counts — which is why the ceiling bites hardest on subsidiaries of large parents.

Within those limits, NIS2 Article 34 tells supervisory authorities to set each fine as effective, proportionate and dissuasive, weighing factors such as:

  • Nature, gravity and duration of the infringement
  • Whether it was intentional or merely negligent
  • Actual damage caused and number of users affected
  • Steps taken to prevent or mitigate the harm
  • Degree of cooperation with the authority
  • Any previous infringements by the entity

Crucially, administrative fines can be imposed in addition to other enforcement measures — binding instructions, security audits at the entity's expense, public disclosure of the breach, and, for essential entities, temporary management bans.

Has anyone actually been fined yet?

Short answer, as of this page's last review: no NIS2 fine has been published by a competent authority that we can verify against an official source. Anyone telling you otherwise should be able to name the decision.

Why the absence of published fines is not reassurance

Administrative fines are rarely announced. Competent authorities are not obliged to publish them, and companies do not volunteer them. "No reported fine" means the public record is empty, not that the regime is dormant.

The German BSIG is explicit about the sequence. Under § 61 Abs. 1 BSIG the BSI does not run audits itself, it orders them from independent bodies. And under § 61 Abs. 3 it may require evidence from other especially important entities only three years after the law entered into force. That is a deliberate ramp, not an amnesty: the registration and reporting duties bite immediately.

The first duty enforced in practice is the cheapest one to miss. Registration under § 33 Abs. 1 BSIG runs on a rolling three-month clock from the day an entity first falls in scope, through a portal operated jointly by the BSI and the BBK.

Two provisions people miss when they budget for risk

Directors are personally liable to their own company. § 38 Abs. 2 BSIG routes the management body's breach of its § 30 duties back through company law, so the exposure is not only the entity's fine. This is why NIS2 reaches the board agenda in Germany and not only the IT budget.

A GDPR fine blocks a second fine on the same conduct. § 65 Abs. 11 BSIG prevents cumulation where a supervisory authority has already fined the same behaviour under Article 58(2)(i) GDPR. An incident that is both a personal-data breach and a NIS2 reportable incident still carries both notification duties, but not two fines for one act.

Sources: BSIG §§ 33, 38, 61 and 65, as published in the Bundesgesetzblatt. Where this page states an amount or a deadline, it is quoted from the statute, not from secondary reporting.

NIS2 fines by country: who enforces them

The directive sets the ceilings; each EU member state transposes NIS2 into national law and names its own competent authority. The maximum amounts are harmonised, but the enforcement regime and procedure differ by country.

Germany — NIS2-Umsetzungsgesetz (NIS2UmsuCG)

Germany's transposition law (the NIS2UmsuCG, in force since December 2025) re-enacts the BSIG and is administered by the BSI (Bundesamt für Sicherheit in der Informationstechnik). German fines (Bußgelder) mirror the directive ceilings — up to EUR 10M or 2% of turnover for essential entities and EUR 7M or 1.4% for important entities — and there is no transitional grace period: obligations apply from entry into force, with an estimated ~29,500 entities now in scope.

Italy — Decreto Legislativo 138/2024

Italy transposed NIS2 with D.Lgs. 138/2024, enforced by the ACN (Agenzia per la Cybersicurezza Nazionale). The fine ceilings match the EU minimums (€10M/2% for soggetti essenziali, €7M/1.4% for soggetti importanti), with technical measures and notification timelines set progressively through ACN determinazioni.

France — Loi Résilience (in progress)

France's transposition is being finalised through the “Loi Résilience” bill, with ANSSI as the competent authority. The fine framework follows the same NIS2 ceilings; entities should track the final text and ANSSI guidance via MesServicesCyber.

Reglyze ships country-specific NIS2 transposition data and authority-formatted incident reports for Germany, France, Italy, Portugal, Belgium and more — so the fine framework you see matches your jurisdiction.

Full country guides: NIS2 in Germany, NIS2 in Italy and NIS2 in the Netherlands.

Personal liability for directors

NIS2 Article 20 holds management personally accountable.

Directors and senior management must approve cybersecurity risk management measures and oversee implementation. If they fail to do so, they can be:

  • Temporarily banned from holding management positions (Essential Entities)
  • Held personally liable for damages resulting from non-compliance
  • Fined individually in addition to organizational penalties

What triggers fines?

Failure to implement the 10 minimum security measures (NIS2 Article 21)

Missing the 24-hour early warning deadline for significant incidents

Missing the 72-hour incident notification deadline

Missing the 1-month final report deadline

Failure to register with the competent authority

Failure to report incidents affecting supply chain partners

Failure to train management on cybersecurity risks

Failure to conduct regular risk assessments

Failure to maintain business continuity and incident response plans

NIS2 fines — frequently asked questions

How much are NIS2 fines?

NIS2 sets maximum fines of up to EUR 10 million or 2% of total worldwide annual turnover (whichever is higher) for essential entities, and up to EUR 7 million or 1.4% of turnover for important entities. The exact amount in your country depends on national transposition — member states set their fine framework within these EU minimums.

Can company directors be personally fined under NIS2?

Yes. NIS2 Article 20 makes management bodies personally responsible for approving and overseeing cybersecurity risk-management measures. Supervisory authorities can hold directors personally liable for damages, and for essential entities they can temporarily ban an individual from holding a management role until the breach is remedied.

What is the difference between essential and important entity fines?

Essential entities face the higher ceiling — up to EUR 10M or 2% of global turnover — and proactive, ex-ante supervision (authorities can audit without prior suspicion). Important entities face up to EUR 7M or 1.4% and reactive, ex-post supervision (authorities act on evidence of a breach). Your category depends on your sector and company size.

Has anyone been fined under NIS2 yet?

Not that we can verify. No NIS2 fine has been confirmed by a competent authority against an official source, and we will not cite one we cannot name. That is weaker evidence than it looks: administrative fines are rarely announced, authorities are under no duty to publish them, and companies do not volunteer them. What is certain is that the duties are already live. Germany transposed NIS2 through the NIS2UmsuCG (in force since December 2025), administered by the BSI: registration runs on a rolling three-month clock (§ 33 Abs. 1 BSIG) and the 24-hour and 72-hour reporting deadlines apply from the day an entity falls in scope.

How can I avoid NIS2 fines?

Most penalties come from three failures: not implementing the 10 minimum security measures in NIS2 Article 21, missing the incident-reporting deadlines (24-hour early warning, 72-hour notification, one-month final report), and failing to register with your national authority. Run a scoping check, close your Article 21 gaps, and put an incident-reporting process in place before an incident — not after.

Want to estimate your own exposure? Try the NIS2 fine calculator.

Avoid fines — start compliant

Reglyze helps SMEs become NIS2 compliant in weeks, not months. Scoping, gap assessment, AI-generated policies, and incident reporting — start free, paid plans from EUR 490 per organisation per year.