Penalties and management liability
The fines are large. The provision that changed behaviour in boardrooms is not the fine — it is the possibility of being banned from management.
Administrative fines
Essential entities
or 2% of total worldwide annual turnover of the preceding financial year — whichever is higher.
Important entities
or 1.4% of total worldwide annual turnover of the preceding financial year — whichever is higher.
« Whichever is higher » matters: for any group with turnover above €500 million, the percentage — not the fixed ceiling — is the real exposure.
Other supervisory powers
Fines are the last resort, not the first. Article 32 gives competent authorities a graduated toolkit for essential entities, and article 33 a narrower one for important entities:
- on-site inspections and off-site supervision, including random checks
- regular and targeted security audits, including at the entity's expense
- security scans and requests for information and evidence
- binding instructions and orders to remedy identified deficiencies
- orders to inform the natural or legal persons affected by a threat
- orders to make aspects of non-compliance public
The provision that changed boardrooms
Article 32(6) allows the competent authority, where other enforcement has failed, to request the temporary prohibition of any natural person exercising managerial responsibilities at chief executive officer or legal representative level from exercising those functions in that entity. It can also suspend a certification or authorisation the entity holds.
These apply to essential entities. Combined with article 20, they turn cybersecurity from a budget line into a personal exposure for named individuals.
Article 20: what management bodies must actually do
The obligation is specific, and each part is auditable:
- Approve the cybersecurity risk-management measures — a documented decision, not an informal nod.
- Oversee their implementation — recurring reporting to the management body, with evidence it was read and acted on.
- Follow training — and offer similar training to employees, so they can identify and assess risks.
Member states must ensure management bodies can be held liable for infringements. What that liability looks like in practice is national law, and it varies.
Where entities get caught
Not on the technical measures — on the paperwork proving management approved them. A board that has never formally approved a risk assessment is in breach of article 20 even if the security itself is excellent.
Common questions
Can a director personally be fined under NIS2?
Is the fine 2% of group turnover or of the entity turnover?
Will authorities actually fine, or is this theoretical?
We are an important entity. Does the management ban apply to us?
Does good security protect us from a fine?
Board & Management Accountability Pack
Article 20 makes management bodies personally accountable and requires them to follow training. This pack is what you put in front of them.
- Board briefing deck (PowerPoint, 22 slides)
- Management body approval resolution template (Word)
- Article 20 training record and attendance register
- Quarterly cybersecurity reporting template for the board
- Personal liability briefing note, including article 32(6) management bans
Instant download · 30-day money-back guarantee