NIS2 Fines and Sanctions: What to Expect

How large a fine the authority can impose for NIS2 failures, the escalation ladder an investigation follows, and the personal liability of the management body.

Most conversations about NIS2 start with the fines, and that is understandable: the sanctions regime is considerably stricter than its predecessor. It is important to see, however, that the authority does not start with a fine. The process follows a logic, and knowing it helps you decide what to spend on first.

The scale of sanctions

The law distinguishes two categories, with different upper limits.

Category Upper limit
Essential entities (Annex I) EUR 10 million or 2 percent of annual worldwide turnover, whichever is higher
Important entities (Annex II) EUR 7 million or 1.4 percent of annual worldwide turnover, whichever is higher

Two points deserve emphasis. First, the "whichever is higher" formula means the turnover-based calculation dominates for large enterprises. Second, worldwide turnover is the reference, not domestic, so for the Hungarian subsidiary of an international group the exposure is far greater than local accounts would suggest.

In Hungarian practice the amounts imposed so far remain well below the ceiling. The authority weighs the gravity, duration and intent of the breach, along with the organisation's cooperation.

It does not start with a fine

This is the part most organisations do not know. The supervisory toolkit is graduated, and the fine sits at the end of the chain.

  1. Request for information. The authority asks for documentation: risk analysis, policies, evidence of management approval.
  2. On-site or remote inspection. Not only the paperwork but the operation: is restoration tested, is the asset inventory real.
  3. Ordering a security audit, potentially at the organisation's expense.
  4. Warning and binding instruction. With specific deadlines and specific measures.
  5. Fine, if the instruction is not fulfilled.
  6. In serious cases: temporary ban on the senior officer from exercising management functions, or suspension of the activity.

The worst strategy therefore is silence. An organisation that fails to answer an information request, or answers incompletely, moves up the ladder quickly. One that can present a documented gap analysis and an action plan with deadlines is in a far better position even if compliance is not yet complete.

Management liability is a separate exposure

One of the biggest changes NIS2 brings is that liability does not stop at the organisation. The management body:

  • approves the cybersecurity measures,
  • oversees their implementation,
  • is liable for failures to comply,
  • must attend regular training.

In cases of serious and repeated failure the authority may temporarily ban the senior officer from exercising management functions. This sanction attaches to the person, not the company, and cannot be delegated to the IT manager.

The practical consequence: management approval and management training must be documented. A signed board resolution and an attendance record are two pieces of paper that count disproportionately during an inspection.

What an inspection asks for first: the written scope analysis, the risk assessment, the incident handling procedure, evidence of management approval and the training register. These five documents can be produced in a few weeks and materially improve your position on their own.

What counts as mitigating and aggravating

The authority exercises discretion, and the criteria are predictable.

Mitigating:

  • a documented gap analysis and an action plan in progress with a schedule,
  • voluntary disclosure and cooperation during proceedings,
  • rapid detection and appropriate handling of the incident,
  • the size and resources of the organisation (proportionality).

Aggravating:

  • failure or delay in incident reporting,
  • repeated breach,
  • intent or gross negligence,
  • disregard of an earlier binding instruction,
  • the extent of actual damage caused.

Failure to report deserves separate mention. Missing the 24-hour early warning or the 72-hour incident notification is a breach in its own right, regardless of whether the incident itself was avoidable. This is the one point where a single unsent email carries direct sanction exposure.

What reduces risk most cheaply

If budget is limited, work in this order. Each step is defensible during an inspection on its own.

  1. Written scope analysis. If you are out of scope, document that too. A few days of work.
  2. Appoint a cybersecurity contact and register with the authority.
  3. Incident reporting template and procedure. Who decides, who reports, in what form, by when. A single page beats nothing.
  4. Management training and approval, minuted.
  5. Gap analysis against the ten measures, plus an action plan with deadlines.

These five points do not make the organisation compliant, but they demonstrate that the process has started. The authority weighs intent and progress, and the graduated procedure means the road to a fine is long.

The common misconception

Many treat NIS2 as primarily a legal and documentation exercise that can be discharged by buying a policy pack. Supervisory practice shows the opposite: inspections look at operation. Is restoration from backup tested, is the asset inventory real, has management been trained, does MFA apply without exception.

Paper alone protects you from neither the attack nor the fine. The good news is that the same work which reduces fine exposure also reduces actual cyber risk. This is one of the rare areas where compliance and security point in the same direction.

If you want to assess where you stand, our NIS2 service starts with a structured gap analysis and ends with a prioritised action plan. Our NIS2 checklist walks through the full requirement set.

Back to Insights
Related content

Related content

Questions on this topic?

Our specialists are happy to discuss what this means in your organisation's environment.