What are the consequences for entities that do not comply with the NIS2 Directive?

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive establishes a series of consequences for “essential” and “important” entities that fail to comply with its provisions. These consequences are designed to ensure effective enforcement and serve as a deterrent against non-compliance. The severity of the consequences may vary based on several factors, including the nature and gravity of the infringement, the size of the entity, and the specific obligations violated. To understand how to structure a NIS2 compliance path before authorities intervene, it is useful to know the sanctioning framework in detail.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

Below is an overview:

General principles of enforcement

  • Effectiveness, proportionality, and dissuasiveness: The general principle for all enforcement measures provided by the NIS2 Directive is that they must be “effective, proportionate, and dissuasive,” considering the specific circumstances of each case. This principle underscores a risk-based approach, where the severity of the consequences is commensurate with the potential impact of the violation.
  • Differentiated supervisory regimes: The directive establishes distinct supervisory regimes for essential and important entities, recognizing their different roles and risk profiles. Essential entities, due to their systemic importance, are generally subject to more rigorous supervision and potentially more severe sanctions than important entities.

Specific enforcement measures

The NIS2 Directive empowers competent authorities to impose a range of measures against non-compliant entities. These measures may be applied cumulatively or independently, depending on the context.

1. Administrative sanctions:

  • Binding instructions: Authorities may issue binding instructions to rectify identified deficiencies or to address violations of the directive. These instructions provide specific guidance to the non-compliant entity, outlining the steps necessary to achieve compliance.
  • Security audit recommendations: Authorities may oblige entities to implement recommendations provided following a security audit within a reasonable timeframe. This ensures that identified vulnerabilities and security gaps are adequately addressed.
  • Alignment with NIS requirements: Competent authorities may force entities to bring their security measures into line with the requirements of the NIS2 Directive within a specified manner and timeframe. This provision underscores the mandatory nature of the security standards set by the directive.
  • Public disclosure of violations: In certain cases, authorities may require entities to publicly disclose certain aspects of their violations in a specific manner. Public disclosure aims to increase the transparency and accountability of cybersecurity practices.

2. Pecuniary sanctions:

  • Financial penalties: The NIS2 Directive introduces a system of administrative fines for violations of risk management and incident reporting obligations. The directive sets a minimum threshold for such sanctions, differentiated for essential and important entities.
    • Essential entities: May be subject to a maximum fine of at least €10,000,000 or 2% of the total annual global turnover of the preceding financial year, whichever is higher.
    • Important entities: May be subject to a maximum fine of at least €7,000,000 or 1.4% of the total annual global turnover of the preceding financial year, whichever is higher.
  • Periodic penalty payments: Member States may implement a system of periodic penalty payments to compel essential or important entities to cease ongoing violations following a previous decision by the competent authority. This provision incentivizes timely action to address and rectify non-compliance.

3. Additional enforcement measures for essential entities:

Recognizing the critical role of essential entities, the NIS2 Directive grants competent authorities additional enforcement tools specifically applicable to these entities when other measures prove insufficient.

  • Temporary suspension of certificate/authorization: Authorities may temporarily suspend or request the suspension of a certificate or authorization related to the services or activities of the essential entity. This measure directly impacts the entity’s ability to operate and provide services.
  • Temporary ban for senior management: Authorities may request a temporary ban, preventing individuals in senior management positions from exercising their functions within the essential entity. This measure aims to ensure individual accountability for non-compliance at the highest organizational levels.

4. Factors considered for the application of sanctions:

When determining appropriate enforcement measures, particularly administrative sanctions, competent authorities must consider the specific circumstances of each case. Factors taken into account include:

  • Gravity, duration, and intent of the violation: More serious or deliberate violations will result in more severe consequences.
  • Damage caused/losses suffered: The financial, economic, or operational impact resulting from non-compliance is taken into account.
  • Number of users involved: Violations affecting a larger number of users may lead to higher sanctions.
  • Previous violations: A history of non-compliance may lead to more severe sanctioning actions.
  • Level of cooperation: Entities that demonstrate a collaborative and proactive approach in resolving violations may benefit from more lenient treatment.

Jurisdictional aspects of enforcement

Determining the jurisdiction responsible for enforcing the NIS2 Directive depends on the specific type of entity involved. To learn more about how Italy has transposed these obligations and which subjects fall within the scope, it is useful to consult the ACN guidelines on the list of NIS2 subjects and compliance deadlines.

  • Establishment as a general rule: For most essential and important entities, jurisdiction generally lies with the Member State where they are established. If an entity operates in multiple Member States, each of them holds jurisdiction and must cooperate in supervisory activities.
  • Exceptions based on service provision or main location: However, there are exceptions for certain entities whose operations are inherently cross-border:
    • Providers of public electronic communications networks and services: Fall under the jurisdiction of the Member State where they provide their services.
    • Providers of domain name system services, TLD registries, cloud computing providers, data center providers, content delivery network (CDN) providers, managed service providers, managed security service providers, online marketplaces, search engines, and social networking platforms: Are subject to the jurisdiction of the Member State where their main establishment within the EU is located. This provision aims to prevent regulatory fragmentation for entities operating cross-border.

Sanctions for violations of national implementation measures

The NIS2 Directive requires Member States to establish their own national rules regarding sanctions for violations of the national measures adopted to implement the directive. These sanctions must adhere to the same principles of effectiveness, proportionality, and dissuasiveness that govern the directive’s enforcement mechanisms.

Collaboration with other regulatory frameworks

The NIS2 Directive emphasizes collaboration and information sharing between the competent authorities responsible for its enforcement and other relevant regulatory bodies, both at the national and EU levels. For a broader understanding of the regulatory context, it is useful to start from the main objective of the NIS2 Directive and how it fits into the European cybersecurity framework.

Frequently asked questions about the consequences of NIS2 non-compliance

  • What is the concrete difference between sanctions for essential entities and those for important entities?
  • Essential entities can be fined up to 10 million euros or 2% of total annual global turnover, while for important entities the maximum drops to 7 million euros or 1.4% of turnover. Beyond the amount, essential entities are exposed to additional measures such as the temporary suspension of certificates or authorizations and a temporary ban for senior management, tools not provided for important entities.
  • What happens if an entity does not resolve a violation after the first sanction?
  • The directive provides for the possibility of applying periodic penalty payments to compel the entity to cease ongoing violations. In practice, repeated non-compliance can result in increasing cumulative sanctions, as well as more invasive measures such as the suspension of operating authorizations.
  • Who is responsible for enforcing NIS2 sanctions in Italy?
  • In Italy, the National Cybersecurity Agency (ACN) is the competent authority designated for the supervision and enforcement of the NIS2 Directive. ACN also manages the list of NIS2 subjects and coordinates compliance verification activities for essential and important entities operating on national territory.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In