Directive NIS2 European Union
Art. 20, 32 & 34 · Directive (EU) 2022/2555

Penalties and management liability


The fines are large. The provision that changed behaviour in boardrooms is not the fine — it is the possibility of being banned from management.

Administrative fines


Art. 34(4)

Essential entities

10 M€

or 2% of total worldwide annual turnover of the preceding financial year — whichever is higher.

Art. 34(5)

Important entities

7 M€

or 1.4% of total worldwide annual turnover of the preceding financial year — whichever is higher.

« Whichever is higher » matters: for any group with turnover above €500 million, the percentage — not the fixed ceiling — is the real exposure.

Calculate your exposure →

Other supervisory powers

Fines are the last resort, not the first. Article 32 gives competent authorities a graduated toolkit for essential entities, and article 33 a narrower one for important entities:

  • on-site inspections and off-site supervision, including random checks
  • regular and targeted security audits, including at the entity's expense
  • security scans and requests for information and evidence
  • binding instructions and orders to remedy identified deficiencies
  • orders to inform the natural or legal persons affected by a threat
  • orders to make aspects of non-compliance public

The provision that changed boardrooms

Article 32(6) allows the competent authority, where other enforcement has failed, to request the temporary prohibition of any natural person exercising managerial responsibilities at chief executive officer or legal representative level from exercising those functions in that entity. It can also suspend a certification or authorisation the entity holds.

These apply to essential entities. Combined with article 20, they turn cybersecurity from a budget line into a personal exposure for named individuals.

Article 20: what management bodies must actually do

The obligation is specific, and each part is auditable:

  • Approve the cybersecurity risk-management measures — a documented decision, not an informal nod.
  • Oversee their implementation — recurring reporting to the management body, with evidence it was read and acted on.
  • Follow training — and offer similar training to employees, so they can identify and assess risks.

Member states must ensure management bodies can be held liable for infringements. What that liability looks like in practice is national law, and it varies.

Where entities get caught

Not on the technical measures — on the paperwork proving management approved them. A board that has never formally approved a risk assessment is in breach of article 20 even if the security itself is excellent.

Common questions

Can a director personally be fined under NIS2?
The administrative fines in article 34 are addressed to the entity, not to individuals. What article 20 adds is that member states must ensure management bodies can be held liable for infringements — the form that liability takes is national law and varies between member states. Separately, article 32(6) allows a competent authority to request a temporary prohibition on a named individual exercising managerial functions at CEO or legal representative level in an essential entity. That is a personal consequence, even though it is not a personal fine.
Is the fine 2% of group turnover or of the entity turnover?
Article 34 refers to the total worldwide annual turnover of the undertaking to which the essential or important entity belongs, for the preceding financial year. In other words the group figure, not the local subsidiary figure. For large groups this makes the percentage, rather than the EUR 10 million ceiling, the operative number.
Will authorities actually fine, or is this theoretical?
Article 32 sets out a graduated set of powers — warnings, binding instructions, orders to remedy, mandatory audits at the entity's expense, orders to publish aspects of non-compliance — and fines sit at the end of that escalation. Expect supervision and remediation orders first. The powers that bite earliest in practice are the mandatory audit at your own cost and the order to make non-compliance public.
We are an important entity. Does the management ban apply to us?
No. The temporary management prohibition and certification suspension in article 32(6) apply to essential entities. Important entities are supervised under article 33, which provides for ex post supervision and a narrower set of enforcement measures. The article 20 obligations on management bodies apply to both.
Does good security protect us from a fine?
Not on its own. A large share of enforcement risk sits in provable governance rather than in technical controls: registration with your national authority, management body approval of the measures, training records, and meeting the article 23 reporting deadlines. An organisation with excellent security and no documented board approval is in breach of article 20.
Art. 20

Board & Management Accountability Pack

Article 20 makes management bodies personally accountable and requires them to follow training. This pack is what you put in front of them.

  • Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
  • Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
  • Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
  • Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
  • Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
  • NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
  • Article 20 management record (CSV): the five obligations of the management body, each with the evidence a supervisor expects — approval decision, oversight reporting, board training, employee training, allocation of accountability
  • Regenerated from our data hub, so it carries the same review date as the site
49 € excl. VAT

Instant download · 30-day money-back guarantee

Cart 0