NIS2 guide
NIS2 fines and supervision
NIS2 sets minimum ceilings for fines and a catalogue of supervisory powers. The actual amounts, procedures and responsible authorities are set by each Member State. Essential entities face proactive supervision, important entities supervision after the fact.
Last updated: October 2026 · Legal basis: Directive (EU) 2022/2555 (NIS2); details depend on national law
The fine ceilings
Article 34 obliges Member States to ensure that infringements of Article 21 (risk-management measures) and Article 23 (reporting obligations) can be punished with administrative fines up to at least the following maximum amounts:
| Category | Maximum fine at least | Source |
|---|---|---|
| Essential entity | €10,000,000 or 2% of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher | Art. 34(4) |
| Important entity | €7,000,000 or 1.4% of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher | Art. 34(5) |
Two points are often misunderstood. First, these are minimum ceilings: national law may set higher maximum amounts, but not lower ones. Second, the turnover-based amount refers to the undertaking to which the entity belongs, which in a group can mean the turnover of the whole group. For a group with €1 billion in turnover, 2% is €20 million, so the higher amount applies.
The ceiling is not the fine. When deciding whether to impose a fine and how much, authorities consider the circumstances of each case, including the seriousness and duration of the infringement, previous infringements, the damage caused, intent or negligence, measures taken to prevent or mitigate the damage, adherence to codes of conduct and cooperation with the authorities (Art. 32(7) and 33(5)). National laws often define lower tiers for less serious infringements, such as late registration. Member States may also provide for periodic penalty payments to compel an entity to stop an infringement (Art. 34(6)).
Supervision of essential entities
Essential entities are subject to supervision without a specific reason (Art. 32(2)). Authorities have the power to carry out:
- on-site inspections and off-site supervision, including random checks,
- regular and targeted security audits by an independent body or the authority,
- ad hoc audits, for example after a significant incident,
- security scans based on objective, non-discriminatory, fair and transparent risk assessment criteria,
- requests for information and access to data, documents and evidence of the implementation of policies.
Enforcement powers include warnings, binding instructions, orders to remedy deficiencies or stop conduct, orders to inform recipients of services, the appointment of a monitoring officer, orders to make aspects of an infringement public and administrative fines (Art. 32(4)). As a last resort, an authority can request the suspension of a certification or authorisation, or a temporary ban for persons with managerial responsibility (Art. 32(5)). Details are on the page about management duties.
Supervision of important entities
Important entities are supervised after the fact (Art. 33(1)). Authorities act when they receive evidence, indications or information that an entity does not comply, for example after an incident, a complaint or a tip-off. They then have similar powers to inspect, audit and request evidence as for essential entities, with the exception of regular audits without a specific reason (Art. 33(2)). The enforcement measures are largely the same, but the temporary bans of Article 32(5) are not part of the minimum regime.
In practice this means: an important entity may not see an authority for years, until an incident happens. Then the authority will ask for the risk assessment, the approved measures, training records and the incident reports. If these do not exist, the incident turns into an enforcement case.
National differences
Who supervises and fines depends on the Member State. Some countries have a single national cybersecurity authority for all sectors. Others split supervision among sector ministries or regulators, with a separate body for finance or telecoms. Procedures differ too: in some countries fines are imposed by the authority directly, in others by a separate body or a court. The transposition overview lists the authorities of the countries with a national law.
Where an infringement of NIS2 also involves a personal data breach, the data protection authority may act under the GDPR. If it imposes a fine for the same conduct, the NIS2 authority may not impose an additional fine under Article 34 for that conduct (Art. 35(2)).
How to reduce the risk
- Register on time. A missing registration is easy to detect and hard to explain. See the page on registration.
- Keep evidence. Authorities assess what you can show: resolutions, risk assessment, policies, training records, test reports.
- Practise reporting. Missing the 24-hour deadline is an infringement of Article 23 in its own right.
- Track findings. Unresolved findings from earlier audits weigh heavily when a fine is set.
- Cooperate. Cooperation with the authority is one of the factors in setting the fine.
The NIS2 scoring shows which gaps carry the highest legal risk and puts them at the top of your action plan.
Frequently asked questions
What is the maximum NIS2 fine?
The directive sets minimum ceilings: at least €10 million or 2% of worldwide annual turnover for essential entities and at least €7 million or 1.4% for important entities, whichever is higher (Art. 34(4) and (5)). National law may set higher amounts.
Does group turnover count?
Yes. The percentage refers to the total worldwide annual turnover of the undertaking to which the entity belongs in the preceding financial year.
Can there be both a GDPR fine and a NIS2 fine?
Not for the same conduct. If the data protection authority fines under the GDPR, the NIS2 authority may not add a fine under Article 34 for that conduct (Art. 35(2)), but may use other enforcement measures.
Will an authority inspect an important entity without reason?
Normally not. Important entities are supervised after the fact, when there is evidence of non-compliance (Art. 33(1)). Essential entities can be inspected at any time.