Licensed by the Estonian FIU · FIU000117Operating since 2014Punane 6, Tallinn

info@micaconsult.com+372 5089565

LexorCorp Global

Guide

What happens without NIS2 compliance

Supervision of essential and important entities, administrative fines, periodic penalties, and the personal responsibility of the management body.

LexorCorp Global OÜ · published 30 September 2026

NIS2 was written to be enforced. The first NIS Directive left sanctions largely to the Member States, and enforcement was uneven. Directive (EU) 2022/2555 sets out the supervisory powers of the authorities, minimum levels for the maximum fines, and — for the first time in EU cybersecurity law — the personal responsibility of the people who run the company. This guide explains what an entity in scope risks if it does not comply, article by article.

The guide is general information, not legal advice. The exact powers, procedures and amounts are set by the national transposition law of each Member State.

Who supervises

Each Member State designates one or more competent authorities and a single point of contact (Article 8), and one or more CSIRTs that receive incident reports (Article 10). In Estonia, the Information System Authority (RIA) is the competent authority under the Cybersecurity Act. Supervision is organised differently for the two categories of entity.

Essential entities: proactive supervision (Article 32)

The authority does not wait for a problem. It can carry out on-site inspections and off-site supervision, including random checks; regular and targeted security audits by an independent body or the authority; ad hoc audits after a significant incident or an infringement; security scans; requests for information, for access to data and documents, and for evidence of implementation of cybersecurity policies such as audit results.

Where it finds infringements, it can issue warnings and binding instructions, order the entity to bring its measures into compliance within a deadline, to stop conduct that infringes the rules, to inform the persons affected by a cyber threat, to implement audit recommendations, to designate a monitoring officer for a defined period, and to make aspects of the infringement public (Article 32(4)). If these measures are ineffective, it can request the suspension of a certification or authorisation for the entity's services and request that a person discharging managerial responsibilities at chief executive officer or legal representative level be temporarily prohibited from exercising managerial functions in that entity (Article 32(5)).

Important entities: reactive supervision (Article 33)

For important entities the authority acts ex post — when it receives evidence, an indication or information that the entity does not comply, for example after an incident or a complaint from a customer. The toolbox is similar (inspections, targeted audits, scans, information requests, warnings, binding instructions), but the temporary prohibition of managers under Article 32(5) does not apply.

Administrative fines (Article 34)

For infringements of Article 21 (risk-management measures) or Article 23 (incident reporting), Member States must provide for administrative fines with a maximum of at least:

  • essential entities: EUR 10 million or 2% of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, whichever is higher (Article 34(4));
  • important entities: EUR 7 million or 1.4% of that turnover, whichever is higher (Article 34(5)).

These are minimum maximums: a Member State may set higher ceilings. The turnover is that of the undertaking, which in competition law terms usually means the whole group. When setting the fine, the authority must take into account, among other things, the seriousness and duration of the infringement, previous infringements, the damage caused, intentional or negligent character, the measures taken to prevent or mitigate the damage, and the degree of cooperation with the authority (Article 34(3), referring to Article 32(7)). Member States may also impose periodic penalty payments to compel an entity to stop an infringement (Article 34(6)). Where a data protection authority has already fined the same conduct under the GDPR, the NIS2 authority may not impose a fine under Article 34 for it (Article 35(2)).

Personal liability of management (Articles 20 and 32(6))

Article 20(1) requires the management body to approve the cybersecurity risk-management measures, oversee their implementation, and makes it liable for infringements by the entity of Article 21. Member States must also ensure that any natural person responsible for or acting as a legal representative of an essential entity can be held liable for breach of their duties to ensure compliance (Article 32(6)). The national company law rules on directors' liability apply alongside: in Estonia, for example, a management board member who breaches the duty of care of a diligent manager is liable to the company for the resulting damage.

Management body members must also follow training (Article 20(2)). A board that has never approved a cybersecurity policy, never received a report on incidents and never been trained will find it difficult to show that it discharged its duties.

Consequences outside the authority's file

  • Customers. NIS2-regulated customers must assess their suppliers (Article 21(2)(d)); a supplier without evidence loses tenders. See NIS2 supply chain requirements for suppliers.
  • Publicity. The authority can require the entity to make aspects of the infringement public.
  • Civil claims and insurance. An incident that the required measures would have prevented weakens the company's position towards injured parties and its cyber insurer.

Where to start

The authority will usually ask first for documents: the risk management policy, the incident handling procedure, the continuity plan, the supply chain policy and the record of management approval and training. These documents are the minimum a company must be able to show; the measures they describe must then be applied in practice. Company-specific documentation built on the national transposition law of 24 EU countries is available on nis2europe.eu, operated by AIPOS OÜ; current prices are on nis2europe.eu/pricing. For the scope rules see Who does NIS2 apply to?, and for the full overview the page NIS2 compliance documentation.

Ready to start? See the obligations and the documentation on nis2europe.eu before the authority asks. NIS2 compliance documentation.

Frequently asked questions

How high are NIS2 fines?

Member States must provide for maximum fines of at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher, for essential entities, and at least EUR 7 million or 1.4% for important entities (Article 34(4) and (5)).

Can managers be personally liable under NIS2?

Yes. The management body approves the risk-management measures, oversees them and can be held liable for infringements (Article 20(1)); for essential entities a person with managerial responsibility can be temporarily prohibited from exercising such functions (Article 32(5)(b)).

Who supervises NIS2 compliance?

The competent authority designated under national law, for example the Information System Authority (RIA) in Estonia. Essential entities are supervised proactively (Article 32), important entities after evidence or indication of non-compliance (Article 33).

Related guides

More on this topic: NIS2 compliance documentation.

Start with the documentation

See the obligations and the documentation on nis2europe.eu before the authority asks.

NIS2 compliance documentation Go to nis2europe.eu