Abstract network-node scale of justice representing legal liability exposure under NIS2 and national tort law

NIS2 Liability: Why EU Law Won’t Let Breach Victims Sue You Directly — But German, French, and Dutch Courts Might

What “NIS2 Liability” Actually Means — Two Separate Tracks

Ask five compliance officers what happens if their company gets breached and fails NIS2, and you’ll get five different answers — usually some blend of “we’ll get fined” and “we could get sued.” Those are two different legal events, governed by two different bodies of law, and conflating them is the single most common mistake in NIS2 commentary. NIS2 itself — Directive (EU) 2022/2555 — creates a regulatory enforcement track: a competent authority investigates, and if it finds a breach of Articles 21 or 23, it can impose an administrative fine under Article 34. That track never puts a euro in an injured customer’s pocket. Separately, and entirely outside NIS2’s text, a customer, business partner, or shareholder who suffers real damage from your breach can try to sue you under ordinary national tort law — the same civil-liability rules that predate NIS2 by decades. Whether that second claim succeeds depends on statutes NIS2 never mentions: Germany’s Bürgerliches Gesetzbuch, France’s Code civil, the Netherlands’ Burgerlijk Wetboek.

The distinction matters because the two tracks have different triggers, different claimants, and different defences. Regulatory fines apply the moment a competent authority finds non-compliance — no third-party damage required. Civil claims require the opposite: a specific claimant, a specific loss, and (as the rest of this article shows) a specific legal hook that NIS2 doesn’t supply on its own.

Entity size (Recommendation 2003/361/EC thresholds) NIS2 category Track 1 — Regulatory (Art. 32-34) Track 2 — Civil (national tort law)
Large: 250+ staff or >€50M turnover, in an Annex I sector — plus specifically listed entities regardless of size Essential entity Applies — ex-ante and ex-post supervision Possible, if national statute qualifies
Medium: 50-249 staff or €10M-€50M turnover, in Annex I or II Important entity Applies — ex-post supervision only Possible, if national statute qualifies
Below medium-enterprise ceilings, not specifically listed Generally out of scope Does not apply directly Ordinary tort law still applies regardless of NIS2 status

The scope thresholds themselves are covered in full on our essential vs. important entity breakdown and scope guide — this piece assumes you already know which bucket you’re in and picks up from there.

The Regulatory Track: What Articles 32-34 Actually Let a Regulator Do

Articles 32 and 33 give competent authorities their supervisory toolkit — and it’s worth reading what that toolkit is, because it’s narrower than most summaries suggest. For essential entities, Article 32 grants proactive powers: on-site inspections, off-site supervision including random checks, regular and targeted security audits, ad hoc audits (typically triggered by a significant incident), and risk-based security scans [1]. For important entities, Article 33 restricts authorities to ex-post supervision — they can only act once there’s “evidence, indication or information” of alleged non-compliance, particularly with Articles 21 or 23 [2]. That asymmetry is deliberate: essential entities get audited proactively; important entities get investigated reactively.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

And every fine described above is per entity, per jurisdiction — a group with subsidiaries in three member states is running three separate exposure calculations, not one.

What both articles share is Article 34’s fine ceiling, which sits at the end of any enforcement action: for essential entities, at least €10,000,000 or 2% of total worldwide annual turnover, whichever is higher; for important entities, at least €7,000,000 or 1.4% of turnover, whichever is higher — for breaches of Articles 21 or 23 [3]. Read that provision closely and one thing stands out by its absence: there is no mechanism anywhere in Articles 32-34 for a third party to claim compensation. The fine is paid to the state (or its designated authority), not to whoever was harmed by the breach that triggered it. Article 32 does confirm that “natural persons responsible for or acting as legal representative” of an entity can be held personally liable for failing to ensure compliance [1] — but that liability, too, runs to the regulator, not to a customer standing in a data-breach class action.

Article 20 Governance Liability: A Related but Different Question

If you’ve read anything about NIS2 and personal liability, it was probably Article 20 — management bodies must approve and oversee Article 21 measures, and the directive states plainly that they “can be held liable for infringements by the entities of that Article” [4]. We’ve covered that mechanic in depth elsewhere: the personal-fine calculation and where D&O insurance does and doesn’t cover it, why CEO liability can’t be delegated to a CISO, and the approve-oversee-accept framework behind it. What it doesn’t do is answer this article’s question: its liability runs to the state or the entity, via the same Art. 32-34 chain — not to an external customer or supplier who lost money. For that, you need a different body of law.

The Civil Liability Track: Can a Breach Victim Actually Sue You?

Here’s the honest answer, calibrated to what the primary text actually supports: NIS2 does not create a private right of action. Nothing in Directive 2022/2555 — not the recitals, not Articles 32-34, not Article 20 — gives an injured customer, supplier, or shareholder a cause of action grounded directly in the directive. A breach victim cannot walk into a German, French, or Dutch court and sue “under NIS2.” What they can do — and what a growing number of law firms are flagging as a live risk — is sue under their own country’s general tort law, using the fact that you violated a cybersecurity statute as evidence that you were at fault.

Every EU civil-law system tested here uses some version of the same gate to decide whether that works: does the specific rule you broke exist to protect people like this claimant, from harm like this harm? German lawyers call it the Schutzgesetz test. Dutch lawyers call it the relativiteitsvereiste. French courts fold it into the ordinary faute analysis. None of the three jurisdictions has decided this question specifically for NIS2-implementing law yet — which is exactly why getting the doctrinal name right, jurisdiction by jurisdiction, matters more than a generic “you could get sued” warning.

Germany: §823 BGB and the Schutzgesetz Question

Plain-language summary: in Germany, a breach victim’s best civil route isn’t a lawsuit “under NIS2” or even under the national NIS2-implementing law (the BSIG amendments) directly — it’s a claim under §823 of the Bürgerliches Gesetzbuch (BGB), using the regulatory breach as proof of fault.

German commentary draws a sharp line between two directions. Internally, management owes a duty to its own company — if the company suffers loss because management failed to implement or oversee Article 21 measures, the company can claim damages from its own managers under existing company law (§93(2) AktG, §43(2) GmbHG, §34(2) GenG) [5]. That claim never reaches an outside customer. Externally is where a breach victim’s claim would sit: law-firm analysis states management can face “external liability… under tort law pursuant to section 823(2)… i.e. liability not to the company but to external third parties” [5]. Section 823(2) BGB requires the broken rule to be a “protective law” (Schutzgesetz) intended for the specific class harmed, not the public at large — and whether courts will classify the BSIG’s cybersecurity obligations that way is, per the same analysis, an unsettled case-by-case question [5].

The backdrop moved fast in 2025-2026: Germany’s NIS2 Implementation Act took effect on 6 December 2025, and the BSI’s registration portal went live shortly after, with roughly 29,500 companies and federal-administration bodies now in scope [9][10]. More registered, audited entities means more documented Article 21 gaps for a future §823(2) claimant to point to.

France: Article 1240 Code Civil and the Faute Standard

Plain-language summary: France doesn’t need a special “cyber-Schutzgesetz” doctrine at all — its general tort article is broad enough to absorb a cybersecurity-failure claim on its own.

Article 1240 of the Code civil states, in its entirety: “Tout fait quelconque de l’homme, qui cause à autrui un dommage, oblige celui par la faute duquel il est arrivé à le réparer” — any act that causes damage to another obliges the person at fault to make reparation [6]. Fault, damage, causal link — that’s the whole rule. French courts have long treated violation of a regulatory obligation as fault (faute) in itself, so a company shown to have skipped a mandatory Article 21 measure hands a claimant much of the fault argument for free. What still sinks most of these cases is causation: a vague “your security was generally weak” claim doesn’t survive French scrutiny, but a documented, specific gap tied to a specific incident does.

Netherlands: Article 6:162/6:163 BW and the Relativiteitsvereiste

Plain-language summary: Dutch law has the clearest, most explicit version of the same gate that Germany applies informally through Schutzgesetz doctrine.

Article 6:162 BW defines onrechtmatige daad (unlawful act) to include a rights violation, an act or omission in breach of a statutory duty, or conduct contrary to what is proper in society, absent a justification [7]. Failing a mandatory NIS2-implementing security obligation looks like a clean fit for that “breach of statutory duty” branch. But Article 6:163 BW adds a filter: the relativiteitsvereiste — “the violated norm must be intended to protect against the damage as it occurred” [8]. In three parts: was the claimant among the people the norm was meant to protect, was their type of loss the type it was meant to prevent, and did the harm arise in the manner it was meant to guard against [8]. A cybersecurity obligation aimed at critical-infrastructure resilience may or may not be read as protecting one customer’s specific financial loss from downstream fraud — untested against NIS2-implementing law in a reported Dutch judgment so far.

Side-by-Side: One Underlying Test, Three Names

Strip the national vocabulary away and all three jurisdictions run the same question through different doctrinal doors — call it the protective-purpose test: a regulatory breach only becomes a paying civil claim if the broken rule was meant to protect this claimant from this exact harm.

Jurisdiction Governing provision Doctrinal gate What a claimant must additionally prove
Germany §823(2) BGB (external), §823(1) BGB (rights violations) Schutzgesetz — is the broken rule a “protective law” for this class of victim? Courts have not yet ruled whether BSIG/NIS2 obligations qualify [5]
France Article 1240, Code civil Faute — was there fault, and does it causally link to this exact loss? A specific, documented causal chain from the gap to the damage [6]
Netherlands Art. 6:162 + 6:163 BW Relativiteitsvereiste — did the norm exist to protect this claimant from this type of loss? The norm’s protective scope must extend to the claimant’s specific loss [7][8]

As of mid-2026, no reported court decision in any of the three jurisdictions has yet tested a civil claim explicitly grounded in NIS2-implementing legislation — this entire analysis rests on how each doctrine has been applied to comparable regulatory-breach claims in the past, not on a decided NIS2 case. That will change; Germany alone now has roughly 29,500 registered entities generating documented compliance gaps for future claimants to cite [9].

What Actually Reduces Your Exposure on Both Tracks

The same paper trail helps in both forums: documented Article 21 measures are what an auditor checks, and what a defence lawyer uses to argue reasonable care — cutting against Schutzgesetz, faute, and relativiteitsvereiste claims alike. A gap register with no remediation date does the opposite in both places at once.

  • Close Article 21(2) gaps with dates attached — an open finding with no remediation plan reads as documented negligence in a deposition, not just a regulatory note.
  • Keep the incident-reporting clock defensible — the 24-hour/72-hour/30-day Article 23 timeline is evidence of diligence if followed, and of the opposite if missed. See our Article 23 notification breakdown.
  • Keep one gap register per legal entity, not one blended group-wide file — both Article 34 fines and tort claims are assessed per entity and per jurisdiction.
  • Brief the board on this distinction, not just Article 20 — “no private right of action under NIS2” is not the same as “no lawsuit risk.”

Frequently Asked Questions

Does NIS2 give breach victims a direct right to sue under EU law?
No. Articles 32-34 set up regulatory enforcement with fines paid to the state, not injured third parties. A civil suit has to run through national tort law instead [1][3].

If my board fails Article 20 oversight, can an outside customer sue the board directly?
Article 20 liability runs to the entity or the regulator, not an external customer [4]. That customer’s claim would still need its own national tort-law hook, same as any claim in this article.

Does implementing Article 21 measures protect me from a civil claim?
No immunity, but it undercuts the fault element every jurisdiction here requires — Schutzgesetz, faute, and relativiteitsvereiste claims all hinge on showing you fell short of a standard of care, and documented Article 21 compliance is the evidence that you didn’t.

Which country has the clearest civil-liability exposure right now?
None has a decided NIS2 case yet, but the Netherlands’ explicit relativiteitsvereiste and Germany’s active Schutzgesetz debate give the most concrete doctrinal language; France’s broader Article 1240 standard is easier to invoke but harder to predict, since it turns on case-specific causation [5][6][8].

Is D&O insurance enough to cover this risk?
D&O policies are underwritten around management liability, not necessarily a company’s own tort exposure to external claimants — check the third-party and cyber-endorsement sections, and see our D&O coverage breakdown.

Key Takeaways

NIS2 splits into two tracks most coverage still blends together. The regulatory track (Articles 32-34) is real and caps at €10M or 2% of turnover — but it pays the state, not your customers. The civil track doesn’t come from NIS2 at all; it comes from ordinary national tort law, gated everywhere examined here by the same protective-purpose question. Get your Article 21 documentation right and one paper trail manages both exposures — get it wrong, and that same trail becomes the evidence used against you in whichever court a claimant picks.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: