NIS2 Penalties Decoded: €10M Essential-Entity Fines, Article 32/33 Enforcement Menus, and 5 Factors That Reduce Your Exposure
Your national competent authority (NCA) did not just receive the power to fine your organisation €10 million. It received a toolkit of nine enforcement tools, and a fine is the last one it is designed to reach for. Understanding the structure of that toolkit — which articles authorise which powers, how escalation works, and what factors shape the final penalty — is the difference between a remediation order and a public disclosure that ends customer relationships.
This guide covers the full supervisory and enforcement framework of the NIS2 Directive: the Article 32 powers for essential entities, the Article 33 powers for important entities, the fine amounts in Article 34, and the eight factors in Article 32(7) that determine where on the penalty spectrum an enforcement action lands. It closes with five concrete steps your organisation can take now to shift those factors in your favour.
The Critical Distinction: Article 32/33 Are Not the Fine
The most persistent misconception in NIS2 commentary is that the fine lives in Article 32 or Article 33. It does not. Articles 32 and 33 are the supervisory and enforcement measures menu — the catalogue of actions NCAs can take. The fine amounts live in Article 34.
Article 32, paragraph 4 grants competent authorities nine enforcement powers. The ninth power, listed last, is: “impose administrative fines pursuant to Article 34.” That positioning matters. An NCA can exhaust the first eight powers — warnings, binding instructions, compliance orders, public disclosure, and more — without ever invoking Article 34. Whether a fine follows depends on the NCA’s assessment of the entity’s response to those earlier measures.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Understanding this structure reframes your compliance posture. The question is not only “what is the maximum fine?” The question is: “which of the nine enforcement powers will the NCA reach for, and what does my organisation need to demonstrate to keep the process in the earlier, cheaper phases?”
Essential Entity Supervision: Article 32’s Full Toolkit
Essential entities face proactive, ex ante supervision — meaning the NCA does not need a triggering incident or complaint to begin supervisory activity. This distinguishes essential from important entity treatment fundamentally.
Article 32 structures its powers in three phases:
| Phase | Article 32 Reference | Powers Available |
|---|---|---|
| Supervisory | Para 2 | On-site inspections; off-site supervision including random checks; regular and targeted security audits by independent body; ad hoc audits following significant incidents; security scans; information and documentation requests; access to data and systems; implementation evidence requests |
| Enforcement | Para 4 | Warnings; binding instructions with remediation timelines; cease-and-desist orders; compliance orders for Article 21 or Article 23; orders to notify affected users; orders to implement audit recommendations; designation of a monitoring officer at the entity’s expense; public disclosure of infringement aspects; administrative fines under Article 34 |
| Escalation | Para 5 | Temporary suspension of relevant certifications or authorisations; prohibition of responsible natural persons from exercising managerial functions (non-public entities only; applies only until the entity takes necessary action) |
Two elements in the enforcement phase deserve particular attention. First, the monitoring officer power in Article 32(4) is exclusive to essential entities — it does not appear in Article 33. The NCA designates an individual to oversee compliance; the entity pays for this oversight. Second, the public disclosure power in Article 32(4) means the entity is ordered to make the disclosure — it is not the NCA publishing a press release. The reputational damage is carried by the entity itself.
Before issuing any enforcement measure, the NCA must state the purpose of information requests (Article 32(3)) and, under Article 32(8), provide detailed reasoning and give the entity a reasonable opportunity to submit observations. This procedural right is your first practical mitigation lever.
Important Entity Supervision: Article 33’s Reactive Model
Important entities operate under a fundamentally different supervisory regime. Article 33 mandates ex post, reactive supervision — the NCA must have evidence, an indication, or information suggesting non-compliance before supervisory activity begins. Absent that trigger, the NCA has no general obligation to supervise important entities, and important entities have no obligation to systematically document compliance proactively.
In practice, triggers include: a significant incident reported under Article 23, a complaint from an affected third party, intelligence from another EU authority, or a security scan showing vulnerabilities. Once triggered, the supervisory and enforcement tools available to the NCA are substantively the same — with two structural differences:
| Dimension | Article 32 (Essential) | Article 33 (Important) |
|---|---|---|
| Supervision trigger | No trigger required — proactive, ex ante | Requires evidence or indication of non-compliance — reactive, ex post |
| Monitoring officer | Yes — Art.32(4) | No — not included in Art.33(4) |
| Temporary management ban | Yes — Art.32(5)(b), non-public entities only | No — Art.32(5) is not cross-referenced in Art.33 |
| Certification suspension | Yes — Art.32(5)(a) | No — Art.32(5) is not cross-referenced in Art.33 |
| Factor framework (Art.32(7)) | Applies directly | Applies mutatis mutandis via Art.33(5) |
| Procedural rights (Art.32(8)) | Applies directly | Applies mutatis mutandis via Art.33(5) |
| Administrative fines (Art.34) | Up to €10M or 2% global turnover | Up to €7M or 1.4% global turnover |
The practical implication: an important entity that avoids triggering supervisory attention — by meeting Article 21 requirements, reporting incidents promptly under Article 23, and maintaining a clean engagement record with its NCA — may never face a formal enforcement action. For important entities, the strongest compliance strategy is prevention of the trigger, not just preparation for the enforcement process.
For a detailed breakdown of which entity type applies to your organisation, see our guide on essential vs important entities.
Article 34 Fine Amounts: The “Whichever Is Higher” Mechanics
Article 34(4) sets the fine ceiling for essential entities at the higher of €10 million or 2% of total worldwide annual turnover in the preceding financial year. Article 34(5) sets the ceiling for important entities at the higher of €7 million or 1.4% of total worldwide annual turnover.
The “whichever is higher” structure means the percentage cap is the binding constraint for large organisations. A €5 billion-turnover essential entity does not face a maximum of €10 million — it faces a maximum of €100 million. The table below illustrates how the mechanics play out across different organisation sizes:
| Annual Turnover | Essential Entity Max Fine | Binding Constraint | Important Entity Max Fine | Binding Constraint |
|---|---|---|---|---|
| €50M | €10M | €10M floor applies | €7M | €7M floor applies |
| €500M | €10M | 2% = €10M — identical | €7M | 1.4% = €7M — identical |
| €1B | €20M | 2% exceeds €10M floor | €14M | 1.4% exceeds €7M floor |
| €5B | €100M | 2% governs entirely | €70M | 1.4% governs entirely |
Several additional mechanics apply. Fines may be imposed alongside other enforcement measures — a binding instruction plus a fine is not double jeopardy; both can run concurrently. Member states may also impose periodic penalty payments to compel compliance with a corrective order; these are separate instruments from the Article 34 fine and can accumulate daily until the required action is taken. For public administration entities, Article 34(7) explicitly permits member states to decide whether, and to what extent, administrative fines apply — national implementations vary considerably on this point.
The directive requires all fines to be “effective, proportionate and dissuasive, taking into account the circumstances of each individual case.” That proportionality requirement is the entry point for your organisation’s mitigation argument — and it is governed directly by the eight factors in Article 32(7).
The 8 Aggravating and Mitigating Factors (Article 32(7))
Article 32(7) requires competent authorities to account for the following eight factors when determining any enforcement measure, including the size of an Article 34 fine. Via Article 33(5), the same factors apply to important entities. Each factor functions as either an aggravator or a mitigator depending on the entity’s conduct.
| Factor | Article 32(7) | Aggravating Signals | Mitigating Signals |
|---|---|---|---|
| Seriousness of infringement | (a) | Repeated violations; failure to notify a significant incident; failure to remedy after a binding instruction; obstruction of audit/monitoring; providing false or inaccurate information | First-time, isolated breach; no obstruction; accurate and complete information provided |
| Duration | (b) | Prolonged non-compliance; ongoing vulnerability exploitation; delay in remediation | Brief exposure window; rapid detection and response |
| Previous infringements | (c) | Prior NIS or NIS2 enforcement history; repeat findings from earlier audits | Clean prior supervisory record; consistent engagement with NCA |
| Damage caused | (d) | Widespread service disruption; significant financial loss to users; large number of affected persons; cross-border impact | Contained impact; rapid service restoration; no material damage to third parties |
| Intent or negligence | (e) | Gross negligence; deliberate risk acceptance; known vulnerability left unpatched | Good-faith compliance effort; documented risk acceptance with board approval; unforeseeable attack vector |
| Preventive and mitigating action | (f) | No pre-existing controls; delayed remediation; no post-incident review | Pre-existing documented controls; active remediation before enforcement; post-incident review with root cause analysis |
| Codes of conduct or certification | (g) | No certification; no adherence to recognised frameworks | ISO 27001:2022 certification; ENISA-backed cybersecurity scheme; documented adherence to NCA-approved code of conduct |
| Cooperation with authority | (h) | Obstruction of inspections; delayed responses to evidence requests; incomplete disclosure | Proactive self-reporting; transparent and timely engagement; full cooperation with audit and investigation |
Factor (a) — seriousness — carries the most internal weight in practice. Its sub-elements include conduct that directly undermines the enforcement process itself: obstruction, false information, and failure to remedy after a binding instruction. An entity that triggers any of these sub-elements effectively converts a moderate compliance failure into a serious one. Conversely, factor (h) — cooperation — produces the largest positive swing when applied well. The investigation process typically follows a sequence aligned with Article 32(8): evidence gathering, a right-to-reply period where the entity can submit observations, and a final decision with documented rationale. An entity that engages transparently at every stage, provides complete evidence without prompting, and moves ahead of requests rather than responding to them is demonstrating factor (h) cooperation at every step.
Binding Instructions, Monitoring Officers, Management Bans, and Public Disclosure: How They Work
Four enforcement measures from Article 32(4) and 32(5) require practical understanding beyond the directive text.
Binding instructions are the primary corrective tool before fines become relevant. Under Article 32(4), the NCA issues a binding instruction specifying the deficiency and the remediation timeline. Article 32(8) requires the NCA to provide detailed reasoning for the measure and to notify the entity of its preliminary findings, giving “reasonable time to submit observations.” This procedural step is your organisation’s first formal mitigation opportunity: a well-prepared observations submission that demonstrates existing controls, active remediation, and a credible timeline can influence both the scope of the instruction and the NCA’s assessment of factor (e) intent. Failure to comply with a binding instruction without justification is itself listed under factor (a) — seriousness — as an aggravating element for any subsequent measure.
The monitoring officer (Article 32(4)) is a power exclusive to essential entities. The NCA designates an individual — either an internal officer or an external expert — to oversee compliance on an ongoing basis. This measure sits between enforcement and escalation: it is deployed when the NCA assesses that the entity cannot be trusted to self-govern compliance, but formal escalation (fine or ban) is not yet warranted. Avoiding the monitoring officer is a significant commercial incentive to respond proactively to Article 32(2) supervisory requests.
The temporary management ban (Article 32(5)(b)) applies only when earlier enforcement measures have proven ineffective, and only to natural persons who hold managerial functions and are “responsible for ensuring compliance.” Three constraints bound its application: it applies only to non-public administration entities, it applies only until the entity takes the necessary action (not a fixed-term ban), and it applies only to essential entities — Article 32(5) is not cross-referenced in Article 33, so important entity management cannot be prohibited under this mechanism. For board members at entities in scope, this provision transforms compliance into a personal career risk, not only an organisational one.
Public disclosure (Article 32(4)) is often mischaracterised as the NCA issuing a press release. The directive is more specific: the NCA orders the entity to publicly disclose the infringement. The entity makes the disclosure. This structure means the reputational consequences — customer notification, press coverage, partner reactions — are handled by the organisation itself, not managed by the regulator. The NCA retains discretion over whether to use this power; it is not automatic on breach confirmation. In practice, public disclosure is used where deterrence value is highest: systemic failures, repeated non-compliance, or failures affecting large numbers of users.
5 Steps That Shift the Article 32(7) Factors in Your Favour
Factors (e), (f), (g), and (h) from Article 32(7) are within your organisation’s direct control before any enforcement action begins. Factor (a) seriousness is partially within your control — the sub-elements you can avoid are obstruction, false information, and failure to remedy after binding instructions. The following five steps address these controllable factors.
1. Document your Article 21 controls before any supervisory contact. Factor (f) credits “measures taken to prevent or mitigate damage” and factor (e) assesses intent or negligence. Pre-existing documented controls are the primary evidence for both. A set of policies that predates the incident or inquiry demonstrates that the failure was not a product of organisational indifference. Documented controls created after an NCA inquiry begins carry significantly less weight.
2. Pursue ISO 27001:2022 certification or an ENISA-backed scheme. Article 32(7)(g) explicitly credits “adherence to approved codes of conduct or certification mechanisms.” ISO 27001:2022 is the dominant recognised framework for NIS2-in-scope entities; its Annex A controls map directly to the Article 21(2) measures. Certification does not guarantee immunity, but it provides a concrete, independently verified mitigating instrument the NCA must account for in its proportionality assessment.
3. Self-report incidents promptly under Article 23. Incident reporting under Article 23 is itself an Article 21 requirement — but its penalty-reduction value operates through the factor framework. Proactive early warning maximises factor (h) cooperation, while also limiting factor (a) seriousness by demonstrating that the entity did not conceal the incident.
4. Engage transparently with every NCA information request. Factor (h) — level of cooperation — is assessed across the entire supervisory interaction, not only at fine-setting stage. Complete, timely responses to Article 32(2) evidence requests signal cooperative intent and constrain the NCA’s ability to invoke factor (a) obstruction aggravators.
5. Maintain an active post-incident review process. Factor (f) credits measures taken after the incident to prevent recurrence. A documented root-cause analysis, a remediation log with completion dates, and a risk register update linked to the incident together constitute the evidence chain an NCA examines at the right-to-reply stage. Without these, the NCA has only the incident itself; with them, it has evidence of a functioning governance response.
Key Takeaways
- The fine amounts are in Article 34, not Articles 32 or 33. Understanding this distinction reframes the entire enforcement conversation: an NCA can complete a full enforcement cycle without ever imposing a fine.
- Essential entities face proactive supervision under Article 32; important entities face reactive supervision under Article 33 — only triggered by evidence of non-compliance.
- The temporary management ban and monitoring officer powers exist only for essential entities under Article 32(5) and Article 32(4).
- Fine ceilings for large organisations are governed by the percentage cap, not the absolute floor: a €1B-turnover essential entity faces up to €20M, not €10M.
- The eight Article 32(7) factors are the proportionality mechanism. The five controllable factors — (e) intent, (f) mitigation measures, (g) certification, (h) cooperation, and (a) non-obstruction — are your organisation’s primary tools for reducing penalty exposure before, during, and after enforcement contact.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Article 32 — Supervisory and enforcement measures in relation to essential entities. NIS-2-Directive.com (EUR-Lex primary text)
- Article 33 — Supervisory and enforcement measures in relation to important entities. NIS-2-Directive.com
- Article 34 — General rules on administrative fines. NIS-2-Directive.com
- Article 32 full text including paragraph 7 factors, NIS2Resources.eu
- How Are NIS 2 Fines Really Calculated?, ISMS.online
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
