What non-compliance costs: administrative fines up to EUR 10M or 2% of worldwide turnover for essential entities (EUR 7M / 1.4% for important), other penalties, and the national transposition deadline that made these rules applicable law.
NIS2 establishes a mandatory minimum ceiling for administrative fines, structured by entity classification. For essential entities, where they infringe Article 21 (risk-management measures) or Article 23 (incident reporting), Member States must ensure administrative fines of a maximum of at least EUR 10 000 000, or of a maximum of at least 2 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher 32022L2555 Article 34@2022-12-27.
For important entities committing the same category of infringement, the ceiling is lower: a maximum of at least EUR 7 000 000, or at least 1.4 % of total worldwide annual turnover, whichever is higher 32022L2555 Article 34@2022-12-27.
The "whichever is higher" formula has practical weight. A subsidiary of a large multinational that fails incident reporting may face the percentage-based ceiling rather than the flat cap — producing a materially larger fine than the headline EUR 10 M or EUR 7 M figures suggest. The relevant turnover belongs to the undertaking as a whole, not the entity in isolation.
Administrative fines must be effective, proportionate and dissuasive, with due account taken of the circumstances of each individual case 32022L2555 Article 34@2022-12-27. When deciding whether to impose a fine and at what level, authorities must give due regard at minimum to the factors set out in Article 32(7) 32022L2555 Article 34@2022-12-27. The Directive does not mandate a fixed tariff: national competent authorities retain discretion within the ceiling floor.
Fines are imposed in addition to supervisory measures — not as an alternative to them 32022L2555 Article 34@2022-12-27.
Member States may also provide for periodic penalty payments to compel an entity to cease a continuing infringement, following a prior decision of the competent authority 32022L2555 Article 34@2022-12-27. This is a separate instrument from a one-time administrative fine; its purpose is to maintain enforcement pressure until compliance is restored.
Member States retain discretion over whether administrative fines apply to public administration entities and to what extent 32022L2555 Article 34@2022-12-27. Where a Member State's legal system does not provide for administrative fines, the Directive requires that the fine mechanism be adapted so that the competent authority initiates the fine and national courts impose it, while ensuring that those legal remedies are effective and have an equivalent effect to the administrative fines imposed by the competent authorities; in any event, the fines imposed must be effective, proportionate and dissuasive 32022L2555 Article 34@2022-12-27.
Beyond fines, Member States must lay down rules on penalties applicable to infringements of national transposition measures, and must take all measures necessary to ensure those rules are implemented 32022L2555 Article 36@2022-12-27. The same three-part standard applies: penalties must be effective, proportionate and dissuasive 32022L2555 Article 36@2022-12-27. Member States were required to notify the Commission of their penalty rules by 17 January 2025 32022L2555 Article 36@2022-12-27.
The critical operational date is 17 October 2024: by that date, Member States were required to adopt and publish the national measures necessary to comply with NIS2 32022L2555 Article 41@2022-12-27. Application of those measures began on 18 October 2024 32022L2555 Article 41@2022-12-27. National laws adopted under the transposition must carry a reference to the Directive in their text or official publication 32022L2555 Article 41@2022-12-27.
The consequence for in-scope organisations is direct: since 18 October 2024, failure to implement risk-management measures under Article 21 or to report incidents under Article 23 constitutes an active legal exposure subject to nationally-enacted administrative sanctions backed by the ceilings above — not a future risk, but a present one.
This block connects to your organisation's own information-security policies (ISMS). In the full product it shows, cited to your policy set, how YOUR organisation implements the obligation above — private to your organisation. (Demo placeholder.)
The cases below are labeled illustrative context, not regulatory authority. They are provided to anchor the lesson in current domain activity and do not constitute legal interpretation.
Air traffic management as an in-scope essential sector CASE-1: Research on purpose-built large language models for air traffic management cybersecurity highlights that ATM systems face an increasingly exposed attack surface as civil aviation modernises CASE-1. Air traffic management is a canonical essential-entity domain under NIS2 transport sector coverage. Organisations operating in this space that fail to implement the risk-management or incident-reporting obligations of Articles 21 and 23 face the full EUR 10 M / 2 % fine ceiling. The research also illustrates a broader tension: deploying advanced tooling (LLMs for threat detection) may satisfy the spirit of Article 21's technical-measures requirement, but the obligation is legal, not technical — supervisors will assess documented processes and governance, not tool sophistication alone CASE-1.
1. What is the fine ceiling for an essential entity that infringes the incident-reporting obligation under Article 23?
NIS2 sets the mandatory minimum ceiling for essential entities at EUR 10 000 000 or 2 % of total worldwide annual turnover, whichever is higher — the EUR 7 000 000 / 1.4 % figures apply only to important entities. 32022L2555 Article 34@2022-12-27
2. When calculating the percentage-based fine for a subsidiary that is an essential entity, which turnover figure is used?
The Directive explicitly attributes the relevant turnover to the undertaking as a whole, not the entity in isolation, meaning a small subsidiary can face a fine calculated on the parent group's global revenue. 32022L2555 Article 34@2022-12-27
3. How does a competent authority's power to impose administrative fines relate to its supervisory measures?
The Directive is unambiguous that fines supplement rather than replace supervisory measures, preventing authorities from treating a fine as a substitute for ongoing oversight. 32022L2555 Article 34@2022-12-27
4. Under what condition may a competent authority impose a periodic penalty payment?
Periodic penalty payments require a prior decision of the competent authority and exist specifically to maintain enforcement pressure until a continuing infringement stops — they are a separate instrument from a one-time fine. 32022L2555 Article 34@2022-12-27
5. By which date were Member States required to adopt and publish the national measures transposing NIS2, and when did application of those measures begin?
The Directive sets the transposition deadline as 17 October 2024 for adoption and publication, with application commencing the following day on 18 October 2024, making NIS2 obligations an active legal exposure from that date. 32022L2555 Article 41@2022-12-27