Guide Compliance

NIS2 Enforcement: Early Penalties, What the First Cases Reveal, and What to Do Now

NIS2 transposition deadlines passed in October 2024. Most EU member states have enforcement authorities in place and active supervisory programmes running. The first enforcement actions and formal investigations are now public.

Key Takeaways
  • NIS2 enforcement is active. Proactive supervision of essential entities began in early 2025, and formal penalty actions with public findings have been appearing since mid-2025.
  • Essential entities face fines up to €10M or 2% of global annual turnover. Important entities face up to €7M or 1.4%. Actual fines depend heavily on whether the organisation can demonstrate a documented security programme.
  • Article 20 personal liability provisions are enacted in Belgium and the Netherlands. CEOs, CISOs, and board members can face individual fines and temporary management prohibitions.
  • The 24-hour early warning is the most consistently missed NIS2 obligation. The failure is almost always organisational: IT response teams remediate without triggering the notification chain.
  • Supply chain security obligations are being actively tested in audits. Authorities are looking for evidence of actual assessments and contractual requirements, not just policy documents that reference supply chain security.
  • Organisations that suffered incidents but had documented risk programmes, tested response plans, and notified on time fare far better than those that could not demonstrate any of these.

How NIS2 enforcement works

NIS2 gives national supervisory authorities two tracks. Proactive supervision involves audits, security assessments, and inspections that authorities can initiate without a triggering event. Reactive enforcement is triggered by a reported incident, a complaint, or information received from another authority. Both tracks can result in corrective orders and financial penalties.

The classification of your organisation determines how intensive the supervision is. Essential entities in energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space face the most rigorous regime: ex ante supervision that does not require an incident to trigger. Important entities face ex post supervision, primarily triggered by incidents or complaints, but are still subject to the same penalty framework.

Supervisory authority varies by country. In the Netherlands, NCSC-NL coordinates with sector regulators: De Nederlandsche Bank for banking, ACM for telecommunications, the NVWA for food supply. In Germany it is the BSI (Bundesamt für Sicherheit in der Informationstechnik). In Belgium it is the CCB (Centre for Cybersecurity Belgium). In France, ANSSI. For UK organisations: NIS2 does not apply directly post-Brexit, but the UK NIS Regulations 2018 cover similar ground, and the forthcoming Cyber Security and Resilience Bill will extend obligations further.

What triggers an investigation

A notified incident is the most common trigger. Under NIS2, entities must submit an early warning to their authority within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report within one month. Failure to notify on time, inadequate incident response visible in the notification, or discrepancies between the entity's account and information the authority has from other sources all trigger follow-up investigations. Authorities also initiate investigations based on intelligence shared through the EU-CyCLONe network and through sector-specific information sharing arrangements, meaning an incident at a peer organisation in your sector can prompt a check on yours.

The penalty framework

€10M
or 2% of global annual turnover, whichever is higher: maximum penalty for essential entities
€7M
or 1.4% of global annual turnover, whichever is higher: maximum for important entities
24h
to submit an early warning after becoming aware of a significant incident (the timeline most organisations miss)

Maximum fines are exactly that: maxima. Actual penalties depend on aggravating and mitigating factors: the severity and duration of the breach, whether it was the result of negligence or deliberate misconduct, the organisation's cooperation with the authority, whether the breach was self-reported or discovered by the authority, and whether the organisation had a demonstrable security programme in place. An organisation that suffered a sophisticated attack but can show a documented risk management programme, tested incident response, and timely notification will be treated very differently from one that cannot demonstrate any of these.

Personal liability under Article 20 is the most significant departure from the GDPR model. Member states may hold individual members of management bodies (CEOs, board members, CISOs) personally liable for NIS2 breaches. Belgium and the Netherlands have both enacted personal liability provisions in their national implementing legislation. This can take the form of personal fines, temporary prohibitions on holding management roles, or mandatory public disclosure of findings. Article 20 also requires that management bodies approve cybersecurity risk management measures and that their members undergo cybersecurity training. These are enforceable obligations, not recommendations.

What the early enforcement actions reveal

Incident reporting gaps are the primary trigger

Failure to meet notification timelines is the most common basis for early enforcement action. The most common pattern: an organisation experiences an incident, manages the response internally, and assesses the incident as below the "significant" threshold without consulting legal or regulatory counsel. The authority later disagrees with that assessment. The 24-hour early warning is the most frequently missed requirement, often because IT response teams begin remediation without triggering the notification chain. By the time compliance functions are looped in, the window has already closed. The result is a technical breach of NIS2 notification obligations layered on top of whatever security incident triggered the situation.

Supply chain obligations are actively tested

NIS2 requires organisations to assess and manage the cybersecurity risks posed by their suppliers and service providers. Early audit findings reveal a consistent pattern: supplier risk management policies exist on paper, but no actual assessments were conducted, supplier agreements carry no security requirements, and no one monitors critical supplier security posture. Authorities are distinguishing between policy documentation and evidence of implementation, and finding the latter absent in many cases. This gap is particularly pronounced for critical software providers, cloud infrastructure operators, and managed service providers who have significant access to the regulated entity's systems and data.

Governance documentation is scrutinised

NIS2 requires board-level oversight of cybersecurity risk management. In early enforcement cases, boards that approved an information security policy on paper but kept no risk register, no minutes of security discussions, and no training records, fail this test. The documentation of governance is treated as evidence of governance. Absence of documentation is absence of compliance. Authorities are specifically requesting board minutes and risk register entries as part of supervisory questionnaires, and the absence of these records is itself a finding regardless of the underlying security posture.

Basic technical controls are a minimum floor

Authorities are checking for fundamental hygiene controls: multi-factor authentication on administrative accounts and remote access, encryption of data at rest and in transit, documented patch management processes with evidence of implementation, and business continuity and disaster recovery plans that have been tested. Organisations that lack these controls and then suffer an incident face substantially larger penalties than those with a demonstrable programme that faced a sophisticated attack beyond their reasonable control. The principle NIS2 applies is proportionality: the question is whether the organisation implemented measures appropriate to the risks it faced, not whether it achieved zero incidents.

Key lesson from early enforcement

Regulators are not looking for perfect security. They are looking for evidence of a proportionate risk management programme: a documented risk assessment, implemented controls appropriate to those risks, a tested incident response process, and a board that can demonstrate it has engaged with cybersecurity risk. Organisations that can produce this evidence, including those that suffered significant incidents, fare far better than those who cannot.

The incident reporting trap

The 24-hour early warning is the most commonly missed requirement. The problem is organisational, not technical: IT teams detect and respond to incidents without notifying legal and compliance functions who carry the notification obligation. By the time the question of regulatory reporting is raised internally, the 24-hour window has already closed.

The definition of a significant incident under NIS2 is broad. Regulators have interpreted it to include: ransomware attacks that encrypt production systems, even if restored within hours; data exfiltration affecting personal, commercial, or operational data, regardless of whether service availability was impacted; prolonged service unavailability measured in hours; and incidents where the entity's systems are used to attack other organisations.

Notify early and update. An early warning does not need to be comprehensive. Article 23 requires only that it establishes the occurrence of the incident and its nature. Supplemental detail follows in the 72-hour full notification and the one-month final report. Over-notifying carries essentially no regulatory risk. Failing to notify because of uncertainty about significance carries very significant risk.

Common mistake

Organisations that manage incident response correctly but fail to loop in legal and compliance are creating regulatory exposure. The incident response plan must wire directly to the notification process: at the point a P1 or P2 incident is declared, legal and compliance must be notified within the first two hours, while there is still time to make the 24-hour early warning. Building this into the runbook is not optional.

What compliance teams should prioritise now

The window to build a NIS2 programme before enforcement is closed. Regulators now ask whether you can demonstrate proportionate security risk management. That answer determines whether you receive a corrective order or a material fine.

  1. Confirm your classification in each relevant member state: verify whether you are classified as an essential or important entity under the national implementing legislation in every EU country where you operate. Classification determines both the depth of your obligations and the applicable penalty ceiling. Self-registration requirements vary by jurisdiction: the Netherlands required registration by mid-2025; Germany and Belgium have their own timetables. If you have not yet confirmed your classification, start here.
  2. Map and test your notification chain: identify the individual responsible for making the 24-hour early warning in each jurisdiction. Ensure your incident response plan triggers the compliance notification chain automatically when a major incident is declared, not after the technical response is complete. Run a tabletop scenario specifically testing whether the chain fires in time: declare a simulated P1 incident and measure how long it takes before legal and compliance are aware and the notification decision is being made.
  3. Document your risk assessment: NIS2 requires proportionate security measures based on a formal risk assessment. If you do not have a documented risk assessment that maps identified risks to implemented controls, this is the highest-priority gap in your programme. The risk assessment does not need to be exhaustive, but it must exist, be current, and demonstrably inform the controls you have in place. Authorities are asking for it in initial supervisory questionnaires.
  4. Evidence your supply chain security: review supplier contracts for cybersecurity requirements. Conduct or commission supplier security assessments for your critical and high-risk vendors. Retain evidence of both. A policy that references supply chain security without evidence of implementation is a finding in supervisory audits. At a minimum, your contracts with critical suppliers should include security requirements, incident notification obligations, and audit rights.
  5. Document board training and engagement: Article 20 requires that management body members receive cybersecurity training. A 90-minute briefing delivered by an independent consultant, with signed attendance records and documented content, satisfies this obligation for most authorities. Schedule and document it. This is one of the fastest gaps to close, and it directly addresses the personal liability exposure that makes NIS2 a board-level concern rather than just a compliance team responsibility.
  6. Test your incident response plan: an undocumented or untested plan is not a plan in the eyes of a supervisory authority. Run a tabletop exercise that includes IT, legal, compliance, communications, and at least one senior executive. Document the exercise, the findings, and the actions taken as a result. This evidence is specifically requested in supervisory questionnaires. The exercise itself demonstrates the governance engagement that Article 20 requires.
  7. Establish a regulatory monitoring process: NIS2 implementing legislation, sector guidance, and supervisory authority publications continue to evolve. Assign a named individual to track updates and ensure your programme reflects current obligations. What satisfied the authority in 2025 may not satisfy it in 2026 as supervisory expectations mature. National authorities are publishing sector-specific guidance and enforcement summaries that reveal exactly where they are focusing their attention.
Ryland Deakin
About the author
Lead Consultant, Cyvra · CISM · CompTIA Security+ · MCP

Ryland has delivered cybersecurity, compliance, and IT management programmes for regulated organisations across the UK and the Netherlands for over 20 years, including senior roles at Microsoft, ING, IPsoft, PPHE and more. View full profile

Common questions

When did NIS2 enforcement start?

NIS2 required EU member states to transpose the directive into national law by 17 October 2024. Most did so on schedule or within weeks. Enforcement authorities were simultaneously empowered to begin supervisory activity. Proactive supervision of essential entities began in early 2025 across the major EU economies. Formal enforcement actions with financial penalties began appearing publicly from mid-2025. If you have not started building your NIS2 programme, you are already in the enforcement window.

Does NIS2 apply to UK companies?

NIS2 itself does not apply to UK organisations post-Brexit. UK entities are subject to the UK NIS Regulations 2018, which the government is updating via the Cyber Security and Resilience Bill. However, UK companies with EU subsidiaries that operate essential or important services must comply in those jurisdictions. Additionally, NIS2's supply chain requirements extend to non-EU suppliers: if you supply critical services to EU-regulated entities, your customers' NIS2 obligations will flow downstream to you via contractual requirements.

What counts as a significant incident under NIS2?

NIS2 defines a significant incident as one that causes or is capable of causing substantial operational disruption or financial loss, or that affects other natural or legal persons. Regulators have applied this broadly: ransomware that encrypts production systems is significant even if restored quickly; data exfiltration is significant regardless of service availability impact; prolonged unavailability measured in hours qualifies. The safe assumption is to notify and let the authority assess significance, rather than making that determination unilaterally and risking a missed notification finding.

Can individual executives be personally fined under NIS2?

Yes, in member states that have enacted Article 20 personal liability provisions, which include Belgium and the Netherlands. Personal liability can take the form of individual fines, temporary prohibition from holding management roles, or mandatory public disclosure. The practical implication: the CEO, CISO, or board members who can be shown to have been aware of cybersecurity obligations and failed to act face personal consequences, not just organisational ones. This makes NIS2 compliance a personal interest for senior leadership, not just a compliance team responsibility.

NIS2 Compliance Assessment

Find out where your NIS2 programme has gaps

We assess your NIS2 obligations, review your risk management programme against supervisory expectations we're seeing in current enforcement actions, and give you a prioritised remediation plan.