Essential entities
Up to €10M
or 2% of worldwide annual turnover
Whichever amount is higher. Backed by proactive supervision and mandatory audits.
Penalties & liability
NIS2 pairs GDPR-scale fines with something new: direct accountability for management bodies, who must approve and oversee cybersecurity measures — and can be held personally liable.
Essential entities
Up to €10M
or 2% of worldwide annual turnover
Whichever amount is higher. Backed by proactive supervision and mandatory audits.
Important entities
Up to €7M
or 1.4% of worldwide annual turnover
Whichever amount is higher. Enforced reactively when non-compliance surfaces.
Authorities can order specific remediation and set deadlines to comply.
Executives can face temporary bans from management functions for serious breaches.
Certifications or authorisations may be suspended until compliance is restored.
For essential entities, up to €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, up to €7 million or 1.4%, whichever is higher. Member states set the exact regime, and some add periodic penalty payments.
Management bodies must approve the risk-management measures, oversee their implementation, and can be held liable for infringements. Members of management must also follow cybersecurity training and are expected to offer similar training to their staff.
Beyond fines, authorities can issue binding instructions and deadlines, order an entity to cease non-compliant conduct, and require public disclosure of the infringement. For essential entities, they may also suspend a certification or authorisation for relevant services and impose a temporary ban on individuals exercising management functions — for example the CEO or a legal representative — until the breach is remedied.
Essential entities face ex-ante supervision: regular audits, inspections and security scans. Important entities face ex-post supervision: authorities act when evidence of non-compliance emerges.
Follow the roadmap to build — and evidence — the controls a supervisor will look for.
See the roadmap →