NIS2 Non-Compliance Costs: Why the €10M Fine Is the Least Likely Bill — and the Three That Aren’t
Almost every article on NIS2 penalties prices one thing: the Article 34 fine. That fine is real, and for a large essential entity it is enormous. It is also, for most organisations, the least likely of the four costs on this page to actually arrive — because the Directive puts more conditions between you and a fine than between you and any of the other three.
The other three do not wait for a regulator. One of them lands even if your organisation was never in scope at all.
First: which cost model applies to you?
NIS2 splits supervision into two regimes, and the split changes your exposure profile more than your sector does. Essential entities are supervised proactively. Important entities are supervised reactively — Article 33(1) says competent authorities act “when provided with evidence, indication or information” of non-compliance, “through ex post supervisory measures” [3].
That single word — ex post — is why the two columns below diverge so sharply.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
| Exposure | Essential entity | Important entity |
|---|---|---|
| Maximum fine (Art 34) | At least €10,000,000 or 2% of worldwide turnover, whichever is higher [1] | At least €7,000,000 or 1.4% of worldwide turnover, whichever is higher [1] |
| Routine supervision | Proactive: random checks, regular and ad hoc audits (Art 32(2)) [2] | Ex post only, on evidence or indication (Art 33(1)) [3] |
| Certification suspension | Available (Art 32(5)(a)) [2] | Not available — Art 33(5) does not import Art 32(5) [3] |
| Temporary ban on the CEO | Available (Art 32(5)(b)) [2] | Not available [3] |
| Personal liability of the legal representative | Yes (Art 32(6)) [2] | Yes — Art 33(5) imports Art 32(6) [3] |
| Forced public disclosure of the infringement | Yes (Art 32(4)(h)) [2] | Yes (Art 33(4)(g)) [3] |
| Supply-chain scrutiny from customers | Yes | Yes — and also for out-of-scope suppliers |
If you are unsure which side you sit on, our guides to the essential entity definition and the important entity definition work through the size and sector tests in detail.
Pillar 1: the fine — and the ladder standing in front of it
Start with the number everyone quotes, then read the sentence it comes from. Article 34(4) requires Member States to ensure essential entities are subject to fines “of a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover” [1].
“A maximum of at least” is a minimum maximum. It is a floor on the ceiling that national law must provide, not a cap on what you can be fined. A Member State may legislate a higher maximum, and for any group with turnover above €500 million the 2% limb already exceeds €10 million on its own.
So the headline understates the worst case. It also badly overstates the expected case, because Article 34 sits at the end of a sequence. Article 34(2) says fines are imposed “in addition to” the measures in Article 32(4), 32(5) and 33(4) — not instead of them [1]. And Article 32(5) only unlocks the severe powers “where enforcement measures adopted pursuant to paragraph 4, points (a) to (d) and (f), are ineffective”, and then only after the authority has set a deadline that passes without action [2].
Read as a chain, a maximum fine requires all of this in order: you are assessed; the assessment finds a material infringement; the authority issues a binding instruction; you fail to remedy it within the deadline. Each link has a probability below one, and multiplying four of them makes the product small.
What the first real deadline actually showed
Germany offers the cleanest natural experiment so far. The BSI states that around 29,500 German companies and federal bodies fell under new statutory duties when the NIS2 implementation act took effect [10]. Registration under § 33 BSIG was due by 6 March 2026. On 7 March, German trade press reported BSI figures showing 11,500 entities registered — 38.5%, leaving roughly 18,350 in open breach of a hard, binary statutory duty [11].
The regulator’s public response was not an enforcement wave: a BSI spokesperson said the recent surge in registrations suggested many more would follow shortly [11]. Registration is the easiest infringement in the Directive to prove — you either filed or you did not — and it did not produce mass fines.
Capacity is also still being built. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposition measures due by 17 October 2024, asking for a lump sum and daily penalties [9]. In those four Member States the machinery that would issue an Article 34 fine was not yet fully in national law.
Two honest counterweights, because none of this argues for ignoring Article 21. Article 32(7)(a)(ii) makes “a failure to notify or remedy significant incidents” a serious infringement in any event [2] — the incident route skips much of the discount above. And Article 32(7)(b) makes the duration of the infringement an aggravating factor [2], so time spent non-compliant is priced even when nobody is watching yet. Our full guide to NIS2 penalties works through all eight Article 32(7) factors.
Pillar 2: personal liability, and the asymmetry nobody flags
NIS2 creates two separate routes to a named individual, and they do not reach the same people.
Article 20(1) is the governance route: management bodies must approve the Article 21 measures, oversee implementation, and “can be held liable for infringements by the entities of that Article” [4]. Article 32(6) is the representative route: any natural person acting as legal representative “has the power to ensure its compliance with this Directive”, and Member States must ensure “it is possible to hold such natural persons liable for breach of their duties to ensure compliance” [2].
Here is the part that matters for exposure planning. Article 33(5) imports Article 32(6), (7) and (8) into the important-entity regime — but it does not import Article 32(5) [3]. On the text of Article 33(5), which enumerates exactly three imported paragraphs, the consequence is precise: a director of an important entity carries personal liability under Article 32(6), while the temporary ban on exercising managerial functions sits in Article 32(5)(b) and is not among the powers extended [2][3].
Both routes are conditional on national law. NIS2 obliges Member States to make personal liability possible; the form, forum and quantum are set by each transposition, which is why the practical answer differs by jurisdiction. How this reaches a named director is covered in our articles on Article 20 board liability and management liability under Article 20.
For a board, the useful reframe is that the defensible artefacts are dated ones. Of the eight Article 32(7) factors, only two can be banked in advance: (f) measures taken to prevent or mitigate damage, and (g) adherence to approved codes of conduct or certification mechanisms [2]. Both are evidenced by documents created before the incident, not after.
Pillar 3: lost contracts — the cost with no probability discount
This is the pillar the market ignores, and the only one that recurs on a fixed schedule whether or not anything ever goes wrong: your customers’ procurement calendar.
The legal engine is Article 21(2)(d), which requires entities to address “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers” [5]. Article 21(3) sharpens it: when deciding what is appropriate, entities must “take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers” [5].
Read that from your customer’s side of the table. Every NIS2-scope organisation you sell to has a legal duty to assess you specifically, because your security posture is an input to their compliance — so their auditor’s questions become their buyer’s questions.
ENISA has measured the behaviour this produces. In the 2025 NIS Investments study of 1,080 professionals across high-criticality NIS sectors, 90% of organisations reported implementing specific third-party and supply-chain controls: requiring suppliers to comply with security standards and maintain certifications (63%), conducting supplier risk assessments or audits (54%), and including cybersecurity requirements in supplier contracts (48%) [7].
The same study ranked what drives cybersecurity spending. Regulatory compliance came first at 70%. “Customers’ security requirements” came second at 42% — ahead of proactive risk mitigation (29%) and response to past incidents (26%), and far ahead of executive or board requests (7%) and insurance conditions (5%) [7].
That ordering is the whole argument: across NIS2 sectors, customer demands already move more security budget than incidents, boards and insurers combined. And unlike a fine, this cost carries no probability discount. It is assessed at every tender, renewal and onboarding questionnaire, and the failure mode is silent — a bid that scores lower, a renewal that does not happen, with no infringement notice to appeal.
It also reaches further than the Directive does. Article 21(3) obliges the in-scope entity to assess its suppliers regardless of whether those suppliers are themselves in scope [5]. A 30-person software vendor well below the NIS2 size thresholds still has to answer its regulated customer’s questionnaire. Pillar 3 is the only one of the four that bills organisations NIS2 never applied to. Our guide to supplier due diligence covers what those assessments actually ask for.
Pillar 4: disclosure on the regulator’s timetable, not yours
“Reputational damage” is usually hand-waved. Under NIS2 it has specific legal triggers, and the common feature is that you do not control them.
Article 32(4)(h) empowers authorities to “order the entities concerned to make public aspects of infringements of this Directive in a specified manner”, with the equivalent power against important entities in Article 33(4)(g) [2][3]. This is not a regulator publishing a register entry — it is an order compelling you to publish, in a manner the authority specifies.
Article 23(7) goes further. Where public awareness is necessary, or disclosure is otherwise in the public interest, the CSIRT or competent authority may, “after consulting the entity concerned, inform the public about the significant incident or require the entity to do so” [6].
“After consulting” is not “with the consent of”. You are entitled to be asked, not to decide. That is the difference between a breach you disclose on your own terms — sequencing customers, staff and press — and one where timing and framing are set for you.
A third channel bypasses the press entirely: Articles 32(4)(e) and 33(4)(e) let an authority order you to inform the recipients of your services about a significant cyber threat [2][3]. That is a message from the regulator to your customer list, delivered under your name — which is how Pillar 4 feeds straight back into Pillar 3. Our analysis of what NIS2 cyber insurance actually covers explains why this category is among the hardest to transfer to an insurer.
Putting a number on all four
A defensible board paper prices each pillar by its own trigger and frequency instead of quoting one statutory maximum. The structure below is our framework; the percentages are illustrative planning assumptions, not measured enforcement rates, and no public dataset yet supports precise probabilities.
| Pillar | Trigger | Frequency | Annualised exposure |
|---|---|---|---|
| 1. Regulatory fine | Assessment → finding → binding instruction → failure to remedy | Rare; ex post only for important entities | P(assessed) × P(finding) × P(unremedied) × fine size |
| 2. Personal liability | National-law action against a named individual | Rare, but survives your departure | P(action) × (defence costs + indemnity gap) |
| 3. Lost contracts | Customer’s own Art 21(3) duty | Every tender and renewal | Revenue at renewal × win-rate delta × margin |
| 4. Forced disclosure | Art 32(4)(h) / 33(4)(g) order, or Art 23(7) | Per significant incident | P(incident) × (churn + extended sales cycles) |
Work a mid-sized important entity: €40m turnover, statutory maximum €7m. Suppose a 5% annual chance of assessment, a 50% chance of a material finding, and a 20% chance of failing to remedy after a binding instruction. The fine branch contributes 0.5% of €7m — around €35,000 a year in expected terms. Now Pillar 3: assume €12m of revenue reaches renewal or tender annually, security scoring shifts win rates by three percentage points, and gross margin is 30%. That is roughly €108,000 — three times the fine branch, arriving as quiet losses rather than a notice.
Change the assumptions and the numbers move, but the ranking is stubborn, because Pillar 3’s frequency multiplier is one per sales cycle while Pillar 1’s is a chain of conditional probabilities. This page prices what non-compliance costs; if the question in front of your board is the opposite one — how much to spend, and how to defend that figure — our NIS2 ROI model in three scenarios runs the investment side, and our NIS2 compliance cost and budget tiers and NIS2 investment case cover the spend and the CFO narrative.
Two consequences follow. For a CISO, the evidence that wins tenders — certifications, a completed supplier questionnaire, a dated risk register — is the same evidence that satisfies Article 32(7)(f) and (g). For an SME owner outside NIS2 scope, Pillars 1, 2 and 4 are zero and Pillar 3 is not, so the proportionate response is a credible answer to a customer questionnaire, not a full compliance programme. Our guide to minimum viable NIS2 compliance sets out where that floor sits.
Frequently asked questions
Has anyone actually been fined under NIS2 yet?
There is no centralised EU register of NIS2 fines, and enforcement data sits with national authorities that mostly do not publish it. Several specific “first fine” figures circulate online; we could not trace any of them to a competent authority or official source, so we do not repeat them. What is documented: as of 8 July 2026 four Member States had not notified full transposition and were referred to the Court of Justice [9].
Can the €10 million figure ever be exceeded?
Yes, on two routes. Article 34(4) sets “a maximum of at least” €10 million, so national law may provide a higher ceiling; and the 2% turnover limb applies whenever it is higher, which it is for any group above €500 million in worldwide turnover [1].
Can our CEO personally be banned from managing the company?
Only in an essential entity, and only as an escalation. Article 32(5)(b) requires that the Article 32(4) measures have proven ineffective and a remediation deadline has passed; the prohibition then lasts only until the deficiencies are remedied [2]. Article 33(5) does not extend this power to important entities [3].
We are too small for NIS2. Does any of this reach us?
Pillar 3 does. Article 21(3) requires in-scope entities to take into account the vulnerabilities and cybersecurity practices of each direct supplier, with no carve-out for suppliers below the size thresholds [5]. If you sell to regulated customers, their duty becomes your questionnaire.
Does cyber insurance cover these costs?
Coverage varies by policy and jurisdiction, and administrative fines are frequently excluded or uninsurable under national law. Insurance conditions were also the weakest driver of security investment in ENISA’s 2025 study, cited by 5% of organisations [7]. Treat cover as a question for your broker on the specific wording, not an assumption.
The bottom line
Price all four pillars, not the one with the biggest number. The Article 34 fine is real and uncapped at the top, but it is guarded by a chain of conditions that makes it the least probable of the four for most organisations. Personal liability is rare but personal. Forced disclosure runs on the regulator’s clock. And lost contracts — driven by your customers’ own Article 21(3) duty, already the second-largest driver of security spending across NIS2 sectors — bill you every sales cycle, whether or not the Directive ever applied to you.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Directive (EU) 2022/2555, Article 34 — General conditions for imposing administrative fines
- Directive (EU) 2022/2555, Article 32 — Supervisory and enforcement measures in relation to essential entities
- Directive (EU) 2022/2555, Article 33 — Supervisory and enforcement measures in relation to important entities
- Directive (EU) 2022/2555, Article 20 — Governance
- Directive (EU) 2022/2555, Article 21 — Cybersecurity risk-management measures
- Directive (EU) 2022/2555, Article 23 — Reporting obligations
- ENISA, NIS Investments 2025 (survey of 1,080 professionals across high-criticality NIS sectors)
- ENISA, NIS360 — Cybersecurity maturity and criticality of NIS sectors of high criticality, May 2026 (ISBN 978-92-9204-792-4)
- European Commission, referral of Ireland, Spain, France and the Netherlands to the Court of Justice (IP/26/1499, 8 July 2026)
- BSI, Zweiter Schritt zur NIS-2-Registrierung: BSI-Portal ab sofort freigeschaltet
- Security-Insider, NIS-2: Nur 38,5 % der Unternehmen im BSI-Portal registriert (BSI figures via dpa)
- Directive (EU) 2022/2555 (NIS2) — official text, EUR-Lex
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
