NIS2
NIS2 Penalties and Management Liability
Under the 2016 NIS Directive, penalties were left almost entirely to national discretion and enforcement was uneven. NIS2 changes that in two ways: it harmonises minimum fine ceilings across the Union, and — unusually for cybersecurity law — it puts named obligations on management bodies personally, backed by the power to suspend executives from their roles.
Administrative fines (Article 34)
| Entity category | Maximum fine | Basis |
|---|---|---|
| Essential entities | €10,000,000 or 2% of total worldwide annual turnover — whichever is higher | Turnover of the preceding financial year, calculated for the undertaking as a whole |
| Important entities | €7,000,000 or 1.4% of total worldwide annual turnover — whichever is higher | Turnover of the preceding financial year, calculated for the undertaking as a whole |
Fines must be effective, proportionate and dissuasive. Authorities weigh the seriousness and duration of the breach, any previous infringements, the damage caused, whether the breach was deliberate or negligent, what you did to mitigate it, and the degree of cooperation with the authority. Fines are the last rung of an enforcement ladder that starts with warnings, binding instructions, orders to remedy and mandatory security audits.
Management accountability (Article 20)
Article 20 makes cybersecurity a board-level duty rather than an IT-department task. The management bodies of essential and important entities must:
- Approve the cybersecurity risk-management measures taken under Article 21 — a documented decision, not a silent delegation.
- Oversee their implementation, which in practice means recurring reporting to the board on risks, incidents and control effectiveness.
- Follow training themselves, regularly, so they can identify risks and assess management practices — and offer similar training to employees.
Member states must ensure that management bodies can be held liable for infringements of the entity's security obligations. For essential entities, supervisory authorities can also apply to temporarily prohibit a CEO or legal representative from exercising managerial functions until the breach is remedied — an exposure that no fine cap expresses.
Additional national sanctions
Because NIS2 is a directive, national transpositions add their own instruments: temporary management bans, suspension of a certification or authorisation needed to operate, periodic penalty payments that accrue daily until a breach is fixed, and in a few member states criminal liability for gross negligence. Check the national implementing act in every country where you provide services.