NIS 2 Directive: What are the penalties for non-compliance?

NIS 2 Sanzioni

The NIS 2 Directive requires EU Member States to establish and implement a system of sanctions for entities that do not comply with the established cybersecurity requirements. These sanctions are designed to be “effective, proportionate, and dissuasive” in order to ensure that organizations take their cybersecurity obligations seriously.

NIS 2 Directive: Administrative sanctions

The NIS2 establishes a minimum set of administrative sanctions that competent national authorities can impose on non-compliant entities:

  • Binding instructions: Competent authorities may issue binding instructions requiring entities to resolve identified security deficiencies or take specific actions to improve their cybersecurity posture. Such instructions may include deadlines for implementation and progress reporting.
  • Orders to implement audit recommendations: If a security audit reveals vulnerabilities or non-compliance, competent authorities may order the entity to implement the recommendations contained in the audit report.
  • Orders to align security measures with NIS2 requirements: Competent authorities may order entities to align their security measures with the specific requirements set out in the NIS2 Directive. This may include implementing additional security controls, updating policies and procedures, or enhancing incident response capabilities.
  • Administrative pecuniary sanctions: The NIS2 introduces a system of administrative sanctions that can be applied to entities that violate the provisions of the Directive. The amount of the sanctions varies based on the classification of the entity as essential or important:
    • Essential entities: For essential entities, Member States must establish maximum sanctions of at least €10,000,000 or 2% of the total worldwide annual turnover of the previous financial year, whichever is higher.
    • Important entities: For important entities, Member States must establish maximum sanctions of at least €7,000,000 or 1.4% of the total worldwide annual turnover of the previous financial year, whichever is higher.
🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

Periodic penalty payments

In addition to the sanctions listed above, Member States may impose periodic penalty payments to compel essential or important entities to cease a violation of the NIS2 Directive. Such payments will continue to accumulate until the entity demonstrates compliance with the competent authority’s decision.

Factors considered in determining sanctions

In determining the appropriate sanction for non-compliance, competent authorities must consider the specific circumstances of each case, including:

  • Gravity of the infringement: The severity of the violation, such as repeated violations, failure to notify or resolve significant incidents, or obstruction of audits or monitoring activities.
  • Duration of the infringement: The period of time during which the entity has been in violation of NIS2 requirements.
  • Previous violations: The entity’s history in terms of non-compliance with cybersecurity regulations.
  • Damages or losses caused: The extent of material or non-material damage caused by the non-compliance, including financial losses, service interruptions, and the number of users involved.
  • Intentional or negligent character of the infringement: Whether the non-compliance was deliberate or resulted from negligence on the part of the entity.
  • Measures taken to prevent or mitigate damages: Any action taken by the entity to address the non-compliance and minimize its impact.
  • Level of cooperation with competent authorities: The entity’s willingness to cooperate with competent authorities during investigations and enforcement actions.

NIS 2 Directive: Further enforcement measures

In addition to specific administrative sanctions, the NIS 2 Directive empowers competent authorities to take further enforcement measures if initial sanctions prove ineffective:

  • Setting a deadline for remediation: If an entity fails to comply with binding instructions or other enforcement measures, competent authorities may set a specific deadline for resolving the identified deficiencies.
  • Suspending or prohibiting activities: In the event of serious or persistent non-compliance, competent authorities have the power to temporarily suspend or prohibit the entity from carrying out activities that involve a cybersecurity risk. Such measures are subject to appropriate procedural safeguards and are applied only until the entity takes the necessary steps to achieve compliance.

Management responsibility

The NIS2 introduces provisions to hold senior management within essential and important entities accountable in the event of cybersecurity violations. This personal accountability aims to incentivize greater focus on cybersecurity at the highest levels of organizational governance. Although the Directive does not specify sanctions for individuals, Member States are required to implement measures that ensure effective accountability.

National law and judicial sanctions

In addition to the administrative sanctions provided for by the NIS 2 Directive, Member States may apply further sanctions provided for by their own national law in the event of a breach of cybersecurity regulations. This may include criminal sanctions for serious offenses or civil liability for damages caused by cybersecurity breaches.

It is important to note that specific sanctions and enforcement mechanisms vary from one Member State to another, as the NIS 2 Directive establishes minimum harmonization standards that Member States must transpose into their national legislation.

How to prepare to avoid NIS2 sanctions

For organizations falling within the scope of the Directive, the most effective way to avoid sanctions is to start a structured compliance path early. This means mapping existing security measures, identifying gaps relative to NIS2 requirements, and defining a remediation plan with realistic deadlines. Specialized support for NIS2 compliance can make the difference between a methodically managed process and prolonged exposure to sanction risk. For those who also need to verify their registration with the ACN list, it is useful to consult the deadlines and compliance procedures provided by the ACN.

In general, the NIS 2 Directive establishes a more robust and consistent enforcement framework for cybersecurity regulations across the EU. The Directive’s emphasis on dissuasive sanctions, clear enforcement powers for competent authorities, and management responsibility is aimed at creating a strong incentive for entities to prioritize cybersecurity and comply with the Directive’s requirements.

Frequently asked questions about NIS2 sanctions

  • What is the difference between the sanctions for essential entities and those for important entities?
  • Essential entities are subject to maximum sanctions of at least €10,000,000 or 2% of total worldwide annual turnover, whichever is higher. For important entities, the maximum drops to €7,000,000 or 1.4% of turnover. The distinction reflects the criticality level of the sector and the potential impact of an incident on society.
  • Can management be held personally liable in the event of a NIS2 violation?
  • Yes. The NIS2 Directive explicitly includes provisions for the accountability of senior management in essential and important entities. Member States are required to implement measures that make this accountability effective, although the concrete forms vary from country to country based on national transposition.
  • What happens if an entity does not comply after receiving binding instructions?
  • If the entity does not comply with binding instructions, competent authorities may impose periodic penalty payments, set stricter remediation deadlines, and, in the most serious cases, temporarily suspend or prohibit the performance of activities that involve a cybersecurity risk.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In