Penalties and management liability
The fines are large. The provision that changed behaviour in boardrooms is not the fine — it is the possibility of being banned from management.
Administrative fines
Essential entities
or 2% of total worldwide annual turnover of the preceding financial year — whichever is higher.
Important entities
or 1.4% of total worldwide annual turnover of the preceding financial year — whichever is higher.
« Whichever is higher » matters: for any group with turnover above €500 million, the percentage — not the fixed ceiling — is the real exposure.
Other supervisory powers
Fines are the last resort, not the first. Article 32 gives competent authorities a graduated toolkit for essential entities, and article 33 a narrower one for important entities:
- on-site inspections and off-site supervision, including random checks
- regular and targeted security audits, including at the entity's expense
- security scans and requests for information and evidence
- binding instructions and orders to remedy identified deficiencies
- orders to inform the natural or legal persons affected by a threat
- orders to make aspects of non-compliance public
The provision that changed boardrooms
Article 32(6) allows the competent authority, where other enforcement has failed, to request the temporary prohibition of any natural person exercising managerial responsibilities at chief executive officer or legal representative level from exercising those functions in that entity. It can also suspend a certification or authorisation the entity holds.
These apply to essential entities. Combined with article 20, they turn cybersecurity from a budget line into a personal exposure for named individuals.
Article 20: what management bodies must actually do
The obligation is specific, and each part is auditable:
- Approve the cybersecurity risk-management measures — a documented decision, not an informal nod.
- Oversee their implementation — recurring reporting to the management body, with evidence it was read and acted on.
- Follow training — and offer similar training to employees, so they can identify and assess risks.
Member states must ensure management bodies can be held liable for infringements. What that liability looks like in practice is national law, and it varies.
Where entities get caught
Not on the technical measures — on the paperwork proving management approved them. A board that has never formally approved a risk assessment is in breach of article 20 even if the security itself is excellent.
Common questions
Can a director personally be fined under NIS2?
Is the fine 2% of group turnover or of the entity turnover?
Will authorities actually fine, or is this theoretical?
We are an important entity. Does the management ban apply to us?
Does good security protect us from a fine?
Board & Management Accountability Pack
Article 20 makes management bodies personally accountable and requires them to follow training. This pack is what you put in front of them.
- Measure brief (Markdown): exactly which points of article 21(2) this covers, and what each requires
- Transposition table for all 27 member states (CSV): transposition status, competent authority, the national article carrying the measures, how many measures national law contains, the applicable assessment framework and its owner
- Implementation worksheet (CSV): per measure, the five questions a supervisor invariably asks, with columns for status, the artefact that proves it, owner and target date
- Framework mapping (CSV): each covered measure of article 21(2) against all eight frameworks in our data hub — the six national assessment frameworks plus ISO/IEC 27001 and NIST SP 800-53 — with the units that carry it, the level the mapping is made at, and the stated limit of that mapping
- Mapping legend (CSV): every framework unit cited, with its meaning — the 22 NIST CSF 2.0 categories used by CyFun, the 10 IT-Grundschutz layers, the 10 C2M2 domains, the 93 ISO/IEC 27001 Annex A controls and the 20 NIST SP 800-53 families
- NIS2-to-enterprise crosswalk (CSV): one row per measure, one column per framework — the national frameworks a supervisor reads, then ISO/IEC 27001 Annex A controls and NIST SP 800-53 families, so you can see what you already hold before building anything new
- Article 20 management record (CSV): the five obligations of the management body, each with the evidence a supervisor expects — approval decision, oversight reporting, board training, employee training, allocation of accountability
- Regenerated from our data hub, so it carries the same review date as the site
Instant download · 30-day money-back guarantee