Directive NIS2 European Union
Cart 0
Art. 20, 32 & 34 · Directive (EU) 2022/2555

Penalties and management liability


The fines are large. The provision that changed behaviour in boardrooms is not the fine — it is the possibility of being banned from management.

Administrative fines


Art. 34(4)

Essential entities

10 M€

or 2% of total worldwide annual turnover of the preceding financial year — whichever is higher.

Art. 34(5)

Important entities

7 M€

or 1.4% of total worldwide annual turnover of the preceding financial year — whichever is higher.

« Whichever is higher » matters: for any group with turnover above €500 million, the percentage — not the fixed ceiling — is the real exposure.

Calculate your exposure →

Other supervisory powers

Fines are the last resort, not the first. Article 32 gives competent authorities a graduated toolkit for essential entities, and article 33 a narrower one for important entities:

  • on-site inspections and off-site supervision, including random checks
  • regular and targeted security audits, including at the entity's expense
  • security scans and requests for information and evidence
  • binding instructions and orders to remedy identified deficiencies
  • orders to inform the natural or legal persons affected by a threat
  • orders to make aspects of non-compliance public

The provision that changed boardrooms

Article 32(6) allows the competent authority, where other enforcement has failed, to request the temporary prohibition of any natural person exercising managerial responsibilities at chief executive officer or legal representative level from exercising those functions in that entity. It can also suspend a certification or authorisation the entity holds.

These apply to essential entities. Combined with article 20, they turn cybersecurity from a budget line into a personal exposure for named individuals.

Article 20: what management bodies must actually do

The obligation is specific, and each part is auditable:

  • Approve the cybersecurity risk-management measures — a documented decision, not an informal nod.
  • Oversee their implementation — recurring reporting to the management body, with evidence it was read and acted on.
  • Follow training — and offer similar training to employees, so they can identify and assess risks.

Member states must ensure management bodies can be held liable for infringements. What that liability looks like in practice is national law, and it varies.

Where entities get caught

Not on the technical measures — on the paperwork proving management approved them. A board that has never formally approved a risk assessment is in breach of article 20 even if the security itself is excellent.

Common questions

Can a director personally be fined under NIS2?
The administrative fines in article 34 are addressed to the entity, not to individuals. What article 20 adds is that member states must ensure management bodies can be held liable for infringements — the form that liability takes is national law and varies between member states. Separately, article 32(6) allows a competent authority to request a temporary prohibition on a named individual exercising managerial functions at CEO or legal representative level in an essential entity. That is a personal consequence, even though it is not a personal fine.
Is the fine 2% of group turnover or of the entity turnover?
Article 34 refers to the total worldwide annual turnover of the undertaking to which the essential or important entity belongs, for the preceding financial year. In other words the group figure, not the local subsidiary figure. For large groups this makes the percentage, rather than the EUR 10 million ceiling, the operative number.
Will authorities actually fine, or is this theoretical?
Article 32 sets out a graduated set of powers — warnings, binding instructions, orders to remedy, mandatory audits at the entity's expense, orders to publish aspects of non-compliance — and fines sit at the end of that escalation. Expect supervision and remediation orders first. The powers that bite earliest in practice are the mandatory audit at your own cost and the order to make non-compliance public.
We are an important entity. Does the management ban apply to us?
No. The temporary management prohibition and certification suspension in article 32(6) apply to essential entities. Important entities are supervised under article 33, which provides for ex post supervision and a narrower set of enforcement measures. The article 20 obligations on management bodies apply to both.
Does good security protect us from a fine?
Not on its own. A large share of enforcement risk sits in provable governance rather than in technical controls: registration with your national authority, management body approval of the measures, training records, and meeting the article 23 reporting deadlines. An organisation with excellent security and no documented board approval is in breach of article 20.
Art. 20

Board & Management Accountability Pack

Article 20 makes management bodies personally accountable and requires them to follow training. This pack is what you put in front of them.

  • Board briefing deck (PowerPoint, 22 slides)
  • Management body approval resolution template (Word)
  • Article 20 training record and attendance register
  • Quarterly cybersecurity reporting template for the board
  • Personal liability briefing note, including article 32(6) management bans
49 € excl. VAT

Instant download · 30-day money-back guarantee

Cart 0