NIS2 Risk of Non-Compliance: Pricing the Wait-and-See Decision When No Fine Data Exists
Every NIS2 business case rests on a number nobody can source. In September 2026 I checked the enforcement trackers ranking for this topic. The one listing specific penalties gave five figures across five member states and cited no regulator decision, press release or case reference for any of them. A second stated plainly that no NIS2 fine has been published by a competent authority it can verify against an official source. The fine is the one input you cannot ground, so the model has to be built so it does not depend on it.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
The Fine Everyone Quotes, and the Enforcement Record Nobody Can Show You
The ceilings are not in doubt. Article 34(4) requires Member States to provide for administrative fines against essential entities of “a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover”, whichever is higher; Article 34(5) sets the equivalent floor for important entities at EUR 7 000 000 or 1.4% [1]. Those are statutory maxima that national law may exceed but not undercut. They are ceilings, not forecasts.
Missing is the other half of the arithmetic. To turn a ceiling into an expected cost you need a base rate: how often authorities fine, and at what fraction of the maximum. Under GDPR that base rate exists, because supervisory authorities publish decisions. Under NIS2 it does not exist in any form you can put in a board paper and defend under questioning.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
A CFO handed “EUR 10 million” next to a EUR 400,000 programme budget reads it as a probability claim, and the probability it silently asserts is one. When the supporting enforcement statistics then turn out to be uncited, the whole paper loses credibility, including the parts that were sound. Say openly that the fine term is unresolvable today, bound it rather than estimate it, and let the terms you can evidence carry the decision. Our breakdown of the Article 32, 33 and 34 penalty mechanics covers the sanction structure itself.
Audit Probability Tracks Your Regulator’s Capacity, Not Your Criticality
In plain terms: whether you get looked at is set by your entity class in law; when you get looked at is set by how ready your supervisor is to look. Only the first appears in most guidance.
The legal split is clean. For essential entities, Article 32(2)(b) empowers competent authorities to apply “regular and targeted security audits carried out by an independent body or a competent authority”, alongside on-site inspections, random checks and security scans [2]. Regular means recurring, with no trigger required. For important entities, Article 33(1) starts elsewhere: authorities act “when provided with evidence, indication or information that an important entity allegedly does not comply”, and then “where necessary, through ex post supervisory measures” [3]. Article 33(2)(b) gives them targeted security audits, but the word regular is absent. The full essential-versus-important power split follows from that one word.
Capacity is where the ENISA evidence earns its place. The third edition of ENISA’s NIS360, published on 28 May 2026, assesses whole sector ecosystems rather than individual firms, and is explicit about supervisors as well as entities. For public administrations it records that cybersecurity responsibilities “are often assigned to horizontal national authorities, which need time to manage a wide range of entities and at the same time have limited resources and experience in supervising a new sector”. For ICT service management it notes that “many national authorities remain relatively new to overseeing the sector, often lacking the sector-specific and cybersecurity expertise that would enable them to do so effectively” [4].
Set those findings beside the maturity data and an inversion appears: the sectors with the weakest internal practice are often the ones whose supervisors are least equipped to examine them. NIS360 places health, railway, maritime, ICT service management, space, public administrations and drinking and waste water in its risk zone, defined as sectors whose criticality exceeds their maturity [4][5]. That is exactly the population for which waiting feels safest and is worst justified, because the supervisory gap is temporary and the exposure is not.
| Sector (NIS360 2026) | Entities running security assessments at regular intervals across all critical systems | What it implies for your audit-timing input |
|---|---|---|
| Banking | 90% | Examination is a calendar item, not a probability. |
| Aviation | 80% | Newly high-maturity. Assume scrutiny arrives on schedule. |
| Financial market infrastructures | 75% | DORA supervision runs in parallel. Little room to defer. |
| Road transport | 65% | Timing depends heavily on the national authority. |
| Energy (electricity, gas, oil) | 35% regular, 65% ad hoc | Ad hoc practice is hard to evidence under Article 32(2)(g). |
| Railway and maritime | 35% regular, 50% ad hoc | Risk zone. Low scrutiny now, rising political attention. |
| Drinking and waste water | One in three have never conducted a risk assessment | Risk zone, no EU-level sector body. Widest exposure-readiness gap. |
| Public administrations | About half have limited or no formal policies | Supervisors resource-constrained. Deferral looks free and is not. |
Percentages are ENISA NIS360 survey findings describing sector populations, not your entity [4]. The water figure measures risk assessments and the others security assessments, so the two are not directly comparable. Use the column as a prior, then correct it with what you actually know: your entity class, and your own five-year history of reportable incidents and customer escalations — the thing that triggers Article 33 supervision.
The Three Costs That Do Not Need the Fine Number
Drop the fine term and the model still works: three other costs are better evidenced, and two arrive without any regulator forming a view about you.
The audit you pay for. Routinely missed, and written into the text. Article 32(2)(b) provides that “the costs of such targeted security audit carried out by an independent body shall be paid by the audited entity, except in duly substantiated cases when the competent authority decides otherwise” [2]. Article 33 carries the same rule for important entities [3]. The first financial consequence of being examined while unprepared is therefore not a fine. It is an independent audit invoice, plus the remediation Article 32(4)(f) lets an authority order, on their timetable. This term needs no enforcement base rate, only your own view of how likely an examination is.
The breach you were going to have anyway. IBM’s Cost of a Data Breach Report 2026 puts the global average at USD 4.99 million, “a 12% increase over last year and a record high”, and attributes USD 1.93 million of cost savings to extensive use of AI and automation in security [7]. Use it carefully: IBM measures the cost of breaches that happened, not how much more likely a breach becomes if you skip NIS2. It is evidence about severity and about the size of the maturity discount, not a probability multiplier. If a slide claims non-compliant firms are breached X% more often, ask which study measured that, because IBM did not.
The contract you lose. Article 21(2)(d) requires measures covering “supply chain security … concerning the relationships between each entity and its direct suppliers or service providers” [8]. That pushes the obligation downward, so your customers’ obligations become your qualification criteria. Once a tender asks the question there is no probability discount worth applying, because the loss is binary and immediate. For many mid-sized suppliers this is the largest of the three. Our three-scenario NIS2 ROI model works the benefit side through in full.
The honest expected annual loss is therefore: P(examination) × (audit cost + ordered remediation) + P(breach) × breach cost × (1 − maturity discount) + P(contract loss) × revenue at risk + [fine term: bounded by Article 34, base rate unknown]. Keeping the fine as a visible bracket rather than a fabricated figure is what makes the rest of the paper survive scrutiny.
Pricing the Wait: What 12, 24 and 36 Months of Deferral Actually Add
Deferral is not a pause. It accrues cost four ways at once, and only one is regulatory.
Start with a cost anchor rather than a guess. ENISA’s NIS Investments 2025 study surveyed 1,080 EU organisations in NIS2 high-criticality sectors and found cybersecurity budgets running at 9% of total IT spend on average, with a median ratio of 6.7% and a median absolute spend of EUR 1.5 million [6]. Compliance drove investment for 70% of them, but benefits ran past compliance: 41% cited stronger risk management, 35% faster detection, 26% better response. That matters for break-even — a NIS2 programme is not a pure regulatory cost, and part of it buys loss reduction you would want regardless.
The same study measures the population already waiting: 30% had not conducted a cybersecurity assessment in the previous 12 months, and 28% take more than three months to patch critical vulnerabilities [6]. Deferral is common — a fact about prevalence, not about safety.
| What accrues while you wait | 12 months | 24 months | 36 months |
|---|---|---|---|
| Expected loss (the three evidenced terms) | 1 × EAL | 2 × EAL | 3 × EAL, rising as supervisors staff up |
| Article 32(7) posture: duration, remedial action | Arguable as transition | Harder to argue | Reads as a decision, not a delay |
| Contract exposure under Article 21(2)(d) | Occasional questionnaires | Routine tender criterion | Disqualifying in regulated supply chains |
| Programme cost when you start | Baseline | Plus compressed-timeline premium | Plus a scarcer talent market (76% already struggle to recruit [6]) |
Break-even is where cumulative expected loss overtakes cumulative programme cost. Because programme cost is front-loaded and expected loss accrues yearly, the comparison is only honest over a multi-year window: a one-year view almost always favours waiting, a three-year view usually does not. Run three years, use your own numbers, and record which assumption is doing the work. If the answer flips when you move P(examination) by ten percentage points, that assumption is the paper and belongs on the first page. For the cost side, our NIS2 compliance budget breakdown sets out the line items.
When Deferral Is a Defensible Risk Treatment Decision, and When It Is Not
Accepting a risk is a legitimate treatment option. Accepting it without saying so is not. The difference is documentation, and it lands differently on each reader of your analysis.
| Role | What this model gives you | The trap to avoid |
|---|---|---|
| Board / C-suite | A defensible expected-loss range with the weak input labelled, instead of a EUR 10M headline that invites a probability argument you will lose | Approving a delay verbally. Article 20 duties do not pause because the item was deferred — see our Article 20 management liability guide |
| Compliance officer | A dated record of what was known, decided and by whom — what Article 32(7) rewards | Presenting an unsourced enforcement statistic and having the whole file discounted with it |
| SME owner | A sequence: cheap high-value controls now, expensive ones deferred explicitly | Treating “too small to be noticed” as a plan. Start with the low-cost controls that close the widest gaps |
Three questions settle most cases. Are you in scope? Establish that first with a proper NIS2 scope test. If you are, and you are classed essential, Article 32(2)(b) regular audits make deferral a timing bet against a scheduled event. If you are classed important, Article 33’s trigger model puts the variable in your hands: can you keep your incident and complaint history clean for the length of the delay? And is any material customer itself in scope — because then the contract term dominates the fine term, and the regulatory analysis should not be deciding this.
Waiting holds up as a short, bounded deferral of one expensive control, with a named owner, a date, a documented residual-risk acceptance, and the cheap controls already in place. It does not hold up as an open-ended deferral of the whole programme justified by the absence of published fines. That absence is a fact about the 2026 enforcement record, not about your exposure.
Frequently Asked Questions
Has any EU regulator actually fined an organisation under NIS2? None verifiable against a published competent-authority decision as of September 2026. Trackers list amounts, but those I checked cite no decision reference, press release or case number, and one states directly that it cannot verify a published fine. Treat any figure as unsourced until a regulator publishes the decision.
If nobody has been fined, why not wait? The fine is the smallest and least certain of the four costs. The Article 32(2)(b) audit invoice, the breach you were exposed to anyway, and the contracts your in-scope customers condition on Article 21(2)(d) all arrive without a fine ever being issued.
What probability of examination should I use? There is no published base rate, so this is a judgement, not a lookup. Anchor it on your entity class (Article 32 regular audits versus Article 33 trigger-based supervision), then adjust for your national authority’s demonstrated activity and your own incident history. State the number and its basis so it can be challenged.
Does a documented decision to defer reduce our exposure? It cannot make a non-compliance compliant. Article 32(7) does require authorities to weigh the duration of an infringement and any remedial action taken, so a dated, approved record with a remediation plan sits better than an undocumented gap — a difference in posture, not a safe harbour. The model is supporting documentation for a proportionality judgement, never a compliance conclusion.
Sources
- Directive (EU) 2022/2555, Article 34 — General conditions for imposing administrative fines on essential and important entities.
- Directive (EU) 2022/2555, Article 32 — Supervisory and enforcement measures in relation to essential entities.
- Directive (EU) 2022/2555, Article 33 — Supervisory and enforcement measures in relation to important entities.
- ENISA, NIS360: latest insights in the cybersecurity maturity and criticality of NIS sectors of high criticality, third edition, May 2026 (PDF).
- ENISA, “NIS360: the bigger picture on maturity and criticality of NIS critical sectors”, announcement of the third edition, 28 May 2026 (linked above).
- ENISA, NIS Investments 2025 — Main report, sixth edition, December 2025, survey of 1,080 EU organisations (linked above).
- IBM, Cost of a Data Breach Report 2026 (linked above).
- Directive (EU) 2022/2555, Article 21 — Cybersecurity risk-management measures.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
