How large a fine the authority can impose for NIS2 failures, the escalation ladder an investigation follows, and the personal liability of the management body.
Most conversations about NIS2 start with the fines, and that is understandable: the sanctions regime is considerably stricter than its predecessor. It is important to see, however, that the authority does not start with a fine. The process follows a logic, and knowing it helps you decide what to spend on first.
The law distinguishes two categories, with different upper limits.
| Category | Upper limit |
|---|---|
| Essential entities (Annex I) | EUR 10 million or 2 percent of annual worldwide turnover, whichever is higher |
| Important entities (Annex II) | EUR 7 million or 1.4 percent of annual worldwide turnover, whichever is higher |
Two points deserve emphasis. First, the "whichever is higher" formula means the turnover-based calculation dominates for large enterprises. Second, worldwide turnover is the reference, not domestic, so for the Hungarian subsidiary of an international group the exposure is far greater than local accounts would suggest.
In Hungarian practice the amounts imposed so far remain well below the ceiling. The authority weighs the gravity, duration and intent of the breach, along with the organisation's cooperation.
This is the part most organisations do not know. The supervisory toolkit is graduated, and the fine sits at the end of the chain.
The worst strategy therefore is silence. An organisation that fails to answer an information request, or answers incompletely, moves up the ladder quickly. One that can present a documented gap analysis and an action plan with deadlines is in a far better position even if compliance is not yet complete.
One of the biggest changes NIS2 brings is that liability does not stop at the organisation. The management body:
In cases of serious and repeated failure the authority may temporarily ban the senior officer from exercising management functions. This sanction attaches to the person, not the company, and cannot be delegated to the IT manager.
The practical consequence: management approval and management training must be documented. A signed board resolution and an attendance record are two pieces of paper that count disproportionately during an inspection.
The authority exercises discretion, and the criteria are predictable.
Mitigating:
Aggravating:
Failure to report deserves separate mention. Missing the 24-hour early warning or the 72-hour incident notification is a breach in its own right, regardless of whether the incident itself was avoidable. This is the one point where a single unsent email carries direct sanction exposure.
If budget is limited, work in this order. Each step is defensible during an inspection on its own.
These five points do not make the organisation compliant, but they demonstrate that the process has started. The authority weighs intent and progress, and the graduated procedure means the road to a fine is long.
Many treat NIS2 as primarily a legal and documentation exercise that can be discharged by buying a policy pack. Supervisory practice shows the opposite: inspections look at operation. Is restoration from backup tested, is the asset inventory real, has management been trained, does MFA apply without exception.
Paper alone protects you from neither the attack nor the fine. The good news is that the same work which reduces fine exposure also reduces actual cyber risk. This is one of the rare areas where compliance and security point in the same direction.
If you want to assess where you stand, our NIS2 service starts with a structured gap analysis and ends with a prioritised action plan. Our NIS2 checklist walks through the full requirement set.
Full NIS2 directive compliance readiness: gap analysis, implementation roadmap, documentation and audit…
Regulatory Compliance (OT-specific service. NIS2, IEC 62443, ISO 27019) verifiable compliance instead of risk.
A practical NIS2 checklist: determining whether you are in scope, the ten mandatory measures, incident…
Our specialists are happy to discuss what this means in your organisation's environment.