Abstract network of glowing blue nodes with red flares, representing cyberattacks of uncertain origin under the NIS2 all-hazards approach

NIS2 Has No Force Majeure Clause: What a State-Sponsored Attack Actually Changes Under Articles 21, 23, and 32

Search the full text of Directive (EU) 2022/2555 for “force majeure” and you get nothing. Search it for “state-sponsored”, “act of war”, or “armed conflict” and you get nothing either. Across all 144 recitals and 46 articles, the word “attribution” never appears once.

That silence answers the question boards ask after a nation-state intrusion: does it get us off the hook? It does not. But the reason is more useful than the answer — it tells you what a supervisory authority examines instead, and where the attacker’s identity genuinely does operate.

The Short Answer: Three Phrases That Never Appear in NIS2

NIS2 contains no exemption, defence, or suspension triggered by the nature of the adversary. No clause makes an obligation fall away because the attacker was sophisticated, well-resourced, or state-backed. Here is the full map.

Question Answer Provision
Does a state-backed attack excuse inadequate measures? No. The duty is defined by the risk to your systems, not by who threatens them. Art 21(1)-(2) [2]
Does it excuse a late or missed report? No. The significance test turns entirely on impact. Art 23(3) [3]
Does it lower the maximum fine? No. Ceilings are fixed by entity class, not incident cause. Art 34(4)-(5) [5]
Does it change what the authority weighs in a penalty? Indirectly — through your conduct, not the attacker’s. Art 32(7) [4]
Does it change the content of your reports? Yes. Two fields ask about malicious cause. Art 23(4)(a), (d)(ii) [3]
Is there a national-security route out? Only at entity or activity level, decided in advance — never per incident. Art 2(7)-(8) [1][6]

Why the All-Hazards Approach Makes the Attacker’s Identity Irrelevant

The design choice sits in the operative text of Article 21(2): measures “shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents” [2]. The obligation is written against what must be protected, not against who might attack it. Identify the threat actor and no element of the duty moves.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Recital 79 explains the intent behind that drafting — and recitals interpret, they do not create obligations. It opens by noting that threats “can have different origins”, then lists the events an all-hazards approach should cover: “theft, fire, flood, telecommunication or power failures, or unauthorised physical access” [1]. That list is deliberately mundane, and the point is easy to miss. The drafters set the floor at ordinary, non-adversarial events. A well-resourced state actor is not outside that floor; it sits far above it. Nothing here lets an entity argue a threat was too advanced for a framework whose stated baseline is a burst pipe.

Article 21 Sets a Standard of Care, Not a Guarantee — and Risk Management Documentation Is the Defence

NIS2 nowhere says “do not get breached”. Article 21(1) requires “appropriate and proportionate technical, operational and organisational measures to manage the risks”, judged against “the state-of-the-art”, “the cost of implementation”, and — for proportionality — “the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity” [2]. Being breached is not an infringement. Failing to have taken proportionate measures is.

Read on its own terms, that test cuts against the intuitive defence. Exposure shapes what “appropriate” means, so an entity in a sector that appears repeatedly in state-aligned targeting data has a higher degree of exposure — which raises the expected standard rather than lowering it. “We were targeted by a state actor” is, structurally, an argument that more was expected of you.

What answers the supervisor’s question is evidence: a risk assessment that identified the threat, a treatment decision, and a dated record of why any residual gap was accepted. Article 21(4) presumes you were looking — an entity that finds it does not comply must take corrective measures “without undue delay” [2]. Germany made the point explicit in transposition: BSIG (2025) § 30(1) closes with “Die Einhaltung der Verpflichtung nach Satz 1 ist durch die Einrichtungen zu dokumentieren” — compliance must be documented by the entities [10]. The Directive leaves that implicit; German law states it as a duty. For the ten measure categories in full, see our complete guide to Article 21.

The Three Places Where the Attacker’s Identity Does Matter

Attacker identity is not irrelevant to NIS2 — it is simply never exculpatory. It surfaces in three operational places, and each one creates work rather than relief.

1. The 24-hour early warning. Article 23(4)(a) requires an early warning within 24 hours of becoming aware of a significant incident, which “where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact” [3]. Note what it asks and what it does not: a binary suspicion of malicious cause, not attribution to a state. The Directive never asks you to name a country. See our breakdown of the 24-hour early warning requirement.

2. The final report. Within one month of the incident notification, the final report must include “the type of threat or root cause that is likely to have triggered the incident” [3]. “Likely to have” is calibrated language — your best assessment, not forensic certainty. Our guide to the final post-incident report covers the full field list.

3. Enforcement and fines. Article 34(3) routes fine-setting through the Article 32(7) factors [5], and this is where the most common misreading of the topic lives. Article 32(7)(e) directs authorities to weigh “any intent or negligence on the part of the perpetrator of the infringement” [4]. Read quickly, that looks like a hook for “the attacker was highly capable, so we weren’t negligent”. It is not. The infringement is your breach of the Directive; the perpetrator of the infringement is your organisation. The attacker commits a crime, not a NIS2 infringement, and never enters this factor.

Where incident severity does register is in the factors measuring your conduct: 32(7)(f), “any measures taken by the entity to prevent or mitigate the material or non-material damage”, and 32(7)(h), “the level of cooperation” with authorities [4]. Conversely, 32(7)(a)(ii) names “a failure to notify or remedy significant incidents” as a serious infringement in any event — so treating a nation-state attack as a reason to delay disclosure converts a survivable incident into an aggravating one. Article 23(1) offers a narrow comfort: “the mere act of notification shall not subject the notifying entity to increased liability” [3].

Exposure Ceiling under NIS2 Moved by a state-backed attacker?
Essential entity, infringing Art 21 or 23 Max of at least EUR 10,000,000 or at least 2% of total worldwide annual turnover, whichever is higher [5] No
Important entity, infringing Art 21 or 23 Max of at least EUR 7,000,000 or at least 1.4% of worldwide annual turnover, whichever is higher [5] No
Temporary management ban (essential entities) Art 32(5)(b), and only where earlier enforcement measures were ineffective and a remediation deadline was missed [4] No

Our NIS2 penalties overview sets out how member states implemented these ceilings.

The National Security Exclusion Is About Who You Are, Not What Hit You

This is where the force majeure instinct usually goes looking, and it is the wrong door. Article 2(6) preserves member states’ responsibility for safeguarding national security; Article 2(7) removes public administration entities operating in national security, public security, defence or law enforcement; Article 2(8) lets a member state exempt specific entities carrying out those activities from the Article 21 or 23 obligations “with regard to those activities or services” [1][6].

Each is scoped to an entity or category of activity and decided before anything happens. None is scoped to an incident, which is why “a foreign state attacked us” does not reach Article 2: the provision asks what you do, not what was done to you. Article 2(9) then claws the exemption back where an entity acts as a trust service provider [6]. We map every route out of scope in our guide to NIS2 exemptions under Article 2.

Your Insurer Has a State-Backed Exclusion. Your Regulator Does Not.

The insurance market is the sharpest way to see what NIS2 chose not to do. On 16 August 2022, Lloyd’s issued Market Bulletin Y5381 requiring that “all standalone cyber-attack policies falling within risk codes CY and CZ must include, unless agreed by Lloyd’s, a suitable clause excluding liability for losses arising from any state backed cyber-attack”, in addition to any war exclusion — effective from 31 March 2023 at inception or renewal [8]. The reasoning was systemic: state-backed attacks “may occur outside of a war involving physical force”, and such losses “have the potential to greatly exceed what the insurance market is able to absorb” [8]. So one incident can void your cover and trigger your heaviest reporting duty at the same moment.

There is a reason regulators avoided that dependency. ENISA is explicit that nexus association “is solely based on attribution done by national authorities globally, and imputation (aka technical attribution) achieved by trusted private vendors” [7] — judgements made by third parties, on their timelines. ENISA also records state-nexus intrusion sets compromising EU-based infrastructure to host command-and-control servers, tactics that “help obfuscate the true origin of traffic … and risk implicating EU countries in malicious activity purely on the basis of IP address attribution” [7]. Between July 2024 and July 2025, 7.2% of incidents against EU member states were identified as state-aligned, with Russia-nexus intrusion sets most active, followed by China-nexus and DPRK-nexus [7]. A duty switching on and off with attribution would be unadministrable.

Those disputes are also slow. Merck’s NotPetya coverage litigation ran roughly $1.4bn; a New Jersey appellate court held in May 2023 that insurers could not deny coverage under the war and “hostile or warlike action” exclusion as worded, and the parties settled in January 2024 on undisclosed terms [9]. Read on its terms, the Article 23(1) shield addresses the regulatory consequences of notifying — it is not a confidentiality guarantee and does not bind a private insurer in a coverage dispute, so coordinate incident statements with counsel. Our guide to cyber insurance and NIS2 covers the policy review.

What This Changes for Your Role

Role What a state-linked attacker changes Practical step
Compliance officer / legal Nothing about deadlines. Two report fields need a named owner and an agreed wording standard. Pre-draft the Article 23(4)(a) early warning so the malicious-acts field is filled by rule, not debated at hour 20.
CISO / IT security manager Your exposure argument runs the wrong way — higher targeting means a higher expected standard under Art 21(1). Record why the current measure set is proportionate for a sector appearing in state-aligned targeting data, and re-date it annually.
Board / management body No shield, and no change to the Art 34 ceilings. Art 32(7)(f) and (h) reward documented prevention and cooperation. Ensure residual-risk acceptances are signed and dated before an incident, not reconstructed after one. See our board governance obligations guide.

Frequently Asked Questions

Is a state-sponsored attack ever a defence to a NIS2 fine?
No. What can reduce exposure is evidence that your measures were proportionate under Article 21(1), that you reported on time, and that you cooperated — all Article 32(7) factors describing your conduct, not the attacker’s [2][4].

Do we have to name the suspected state in the 24-hour early warning?
No. Article 23(4)(a) asks, where applicable, whether the incident is suspected of being caused by unlawful or malicious acts — a binary flag. It does not ask for attribution to any actor or country [3].

If law enforcement asks us to hold back, does the reporting clock stop?
The Directive contains no express suspension of the Article 23(4) deadlines. Article 23(5) provides that where an incident is suspected to be of a criminal nature, the CSIRT or competent authority shall also give guidance on reporting it to law enforcement [3]. National procedures vary — raise it with your competent authority rather than assuming a pause.

The Practical Conclusion

The absence of a force majeure clause is not an oversight — it is the mechanism. A duty anchored to attribution would depend on third-party judgements made months after the fact, on evidence ENISA itself describes as imputation. So the Directive anchored the duty to impact and to your own diligence, both of which you control and can evidence. The work is therefore identical whether your next significant incident comes from a ransomware affiliate, a misconfigured backup, or a state-nexus intrusion set: proportionate measures you can prove you chose deliberately, reports filed on the clock, and a decision trail that reads as judgement rather than hindsight. The attacker’s identity will be a line in your final report. It will never be a line in your defence.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Directive (EU) 2022/2555 (NIS 2 Directive), full text — EUR-Lex, Official Journal (linked above). Recital 79; Article 2(6)-(9).
  2. NIS 2 Directive, Article 21: Cybersecurity risk-management measures.
  3. NIS 2 Directive, Article 23: Reporting obligations.
  4. NIS 2 Directive, Article 32: Supervisory and enforcement measures in relation to essential entities.
  5. NIS 2 Directive, Article 34: General conditions for imposing administrative fines.
  6. NIS 2 Directive, Article 2: Scope.
  7. ENISA Threat Landscape 2025 (v1.2, October 2025) — European Union Agency for Cybersecurity (linked above).
  8. Market Bulletin Y5381: State backed cyber-attack exclusions — Lloyd’s of London, 16 August 2022 (linked above).
  9. Merck reaches settlement in closely watched NotPetya insurance case — Cybersecurity Dive.
  10. BSIG (2025) § 30 — Risikomanagementmaßnahmen besonders wichtiger Einrichtungen und wichtiger Einrichtungen — gesetze-im-internet.de (linked above).
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: