Essential entities

Up to €10M

or 2% of worldwide annual turnover

Whichever amount is higher. Backed by proactive supervision and mandatory audits.

Important entities

Up to €7M

or 1.4% of worldwide annual turnover

Whichever amount is higher. Enforced reactively when non-compliance surfaces.

Binding instructions

Authorities can order specific remediation and set deadlines to comply.

Management liability

Executives can face temporary bans from management functions for serious breaches.

Suspension

Certifications or authorisations may be suspended until compliance is restored.

Administrative fines

For essential entities, up to €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, up to €7 million or 1.4%, whichever is higher. Member states set the exact regime, and some add periodic penalty payments.

Management accountability (Article 20)

Management bodies must approve the risk-management measures, oversee their implementation, and can be held liable for infringements. Members of management must also follow cybersecurity training and are expected to offer similar training to their staff.

Non-monetary enforcement

Beyond fines, authorities can issue binding instructions and deadlines, order an entity to cease non-compliant conduct, and require public disclosure of the infringement. For essential entities, they may also suspend a certification or authorisation for relevant services and impose a temporary ban on individuals exercising management functions — for example the CEO or a legal representative — until the breach is remedied.

Supervision differs by tier

Essential entities face ex-ante supervision: regular audits, inspections and security scans. Important entities face ex-post supervision: authorities act when evidence of non-compliance emerges.

Make compliance defensible

Follow the roadmap to build — and evidence — the controls a supervisor will look for.

See the roadmap →