
NIS2 Is No Longer a Warning: First Fines Are Landing — Is Your Organization Next?
NIS2 fines are here. Belgium, Italy, and Hungary have already sanctioned organizations. Find out what regulators are checking and whether your business is prepared.
The regulators did not send another warning. They sent an invoice.
As of mid-2026, 23 of 27 EU Member States have fully transposed NIS2, and the first fines have landed in Belgium (€185,000), Italy (€450,000), and Hungary (€78,000).
These are not symbolic enforcement actions. They are proof that supervisory authorities have moved from awareness campaigns to active sanctioning, and the organizations caught off guard were not outliers. They were simply the first ones auditors reached.
If your organization operates in or sells into the EU and you are still treating NIS2 as a 2027 problem, the enforcement data tells you otherwise. The question executives should be asking is not whether their sector is in scope. The question is whether they have a senior security leader who can map their obligations, own the board reporting, and stand in front of an auditor with documented evidence of governance. A compliance checklist does not do that. A Fractional CISO does.
The Enforcement Numbers You Cannot Ignore
National CSIRTs have launched systematic audit programmes targeting essential entities in energy, health, and digital infrastructure. NIS2 covers approximately 160,000 entities EU-wide, with maximum fines of €10 million or 2% of global turnover for essential entities and personal liability for management bodies under Article 20.
The financial exposure is GDPR-grade.
Essential entities face fines of up to €10 million or 2% of global annual turnover, whichever is higher. Important entities face fines of up to €7 million or 1.4% of global annual turnover.
Those numbers applied to cybersecurity posture, not just data breaches, represent a category shift in risk for any CFO modeling EU operational exposure.
Germany's BSI has issued 47 formal notices, and France's ANSSI has issued 23 remediation orders. The enforcement pattern mirrors early GDPR enforcement in 2018 and 2019, where significant fines followed an initial period of warnings and corrective measures. Financial penalties are expected to increase substantially through 2026 and 2027.
Organizations that read the GDPR enforcement arc correctly moved early and gained competitive advantages. Those that waited paid for it. NIS2 is following the same trajectory, with one critical difference: the liability does not stop at the corporate entity.
"NIS2 Article 20 shifts the question from whether the organization is compliant to whether leadership can demonstrate they fulfilled their personal oversight responsibilities. Those are not the same question, and the second one is significantly harder to answer."
NIS2 Article 20 places explicit responsibility on management bodies to approve, oversee, and be accountable for cybersecurity risk management measures. Management must approve cybersecurity measures, oversee their implementation, and undergo cybersecurity training sufficient to assess risks and their impact. Personal liability can be imposed on individual executives for non-compliance, including temporary bans from managerial functions. Board-level cybersecurity governance is no longer optional; it is a legal obligation for all essential and important entities across the EU.
The management body cannot delegate away its NIS2 accountability. While the board may delegate operational cybersecurity to the CISO or a risk committee, the legal obligation to approve, oversee, and be trained remains with the management body itself. Delegation of tasks does not equal delegation of liability.
Where Organizations Are Failing: A Comparative View
The Netherlands conducted compliance assessments of 120 essential entities in digital infrastructure during H2 2025. Published anonymised findings showed that 38% had not implemented adequate incident reporting procedures and 52% lacked management body-approved cybersecurity policies.
These failures are not technical shortcomings. They are governance failures that land directly at the board level.
The table below maps the most common NIS2 compliance gaps against the specific Article obligations and the evidence regulators will demand during an audit.
| NIS2 Obligation | Common Gap | Auditor Evidence Requirement |
|---|
| Article 20: Board Approval | Cybersecurity policy not formally approved by management body | Board minutes showing explicit approval of risk management measures |
| Article 20: Board Training | No documented cybersecurity training for executives | Training records with dates, provider, and content scope |
| Article 21: Risk Management | Controls exist but are not mapped to the 10 mandatory measures | Gap analysis against Article 21(2) with control owners assigned |
| Article 23: Incident Reporting | No tested 24/72-hour reporting workflow | Tabletop exercise records and notification runbooks |
| Article 21: Supply Chain Security | Third-party risk assessments absent or undocumented | Supplier security questionnaires and contractual security clauses |
| Article 20: Oversight Evidence | Cybersecurity treated as an IT agenda item only | Regular board reporting packs on cyber risk posture |
Across in-scope organizations, 84% admit they are not ready.
That statistic, combined with active audit programmes in 14 member states, defines an organization's probability of regulatory contact in the next 18 months.
The Incident Reporting Window Is Brutally Short
Article 23 of the NIS2 Directive introduces the most structured incident reporting framework in EU cybersecurity regulation. Unlike the single-notification model under GDPR, NIS2 incident reporting follows a strict three-stage process: a 24-hour early warning, a 72-hour incident notification, and a one-month final report.
The window is aggressive enough that manual workflows typically miss the 24-hour mark, which is why automated detection-to-notification triggers are now considered table stakes.
Most incident response plans in existence today were not designed for this cadence. They were designed for IT recovery, not regulatory notification.
What often triggers regulatory scrutiny, and ultimately penalties, are not technical oversights but late, missing, or mismatched notifications.
A missed reporting deadline is independently finable, regardless of how well the underlying incident was handled technically.
The proposed amendments make this more complex, not simpler.
The Proposed Amendments: More Scope, More Obligations
The European Commission's proposed NIS2 amendments seek to clarify scope, ransomware reporting, cross-border supervision, and the role of ENISA. The proposal, published on January 20, 2026, remains subject to approval by the European Parliament and the Council of the EU.
Under the proposal, companies would be required to report additional facts for incidents arising from ransomware attacks, including whether they detected an attack, the attack vector, and whether mitigation measures have been implemented. The proposal also gives national authorities the power to request additional information when a reported significant incident is caused by ransomware.
If asked by NIS2 regulatory bodies or authorities, entities must reveal if they received a ransom demand, who made it, and whether they paid, sharing the amount, payment method, and recipient details.
This creates an entirely new category of disclosure obligation that most general counsel offices and incident response retainers are not yet structured to handle.
In practice, these granular reporting requirements may be challenging for any business impacted by a ransomware incident, and affected entities should update their incident response plans to cover how they will handle requests for ransomware information.
Organizations that believed they were outside NIS2's scope should also revisit that assumption.
Under the new proposal, operators of submarine data transmission infrastructure will be brought within scope, while entities involved in the distribution of chemicals are removed.
Scope changes mid-enforcement cycle create invisible exposure for organizations whose legal teams have not tracked the legislative calendar.
Framework Alignment: What Auditors Accept as Evidence
NIS2 does not mandate a specific certification, but it does require demonstrable control implementation.
Mapping existing controls to NIST CSF 2.0 and ISO 27001 is recommended. National regulators in Italy, Belgium, Slovenia, and others accept these as primary compliance evidence.
The CIS Controls framework provides a complementary implementation pathway, particularly for supply chain security and asset management obligations under Article 21. Organizations already certified to ISO 27001 have a meaningful head start, but certification alone does not satisfy NIS2's governance and reporting obligations. The management body approval and oversight requirements under Article 20 demand documented board engagement that an ISO audit scope does not automatically capture.
ENISA's Technical Implementation Guidance provides explicit mappings between Article 21's ten mandatory measures and established control frameworks. Using that mapping to build a board-level evidence file, with control owners, testing records, and risk acceptance decisions documented, is what separates organizations that pass audits from those that receive remediation orders.
Emerging Enforcement Trends
Cross-Border Complexity Is Creating Hidden Gaps
Organizations with operations across multiple EU member states face divergent national transpositions. A company compliant in Belgium may carry material exposure in Italy or Germany.
In Hungary, service providers and organizations operating in high-risk sectors must sign an agreement with a certified external auditor company to undergo bi-annual audits.
Germany's BSI Act establishes direct personal liability for management body members and adds a restriction with no equivalent in the directive: shareholders cannot release directors from NIS2 liability through a corporate waiver.
Italy's national cyber agency explicitly targets individual organ members rather than treating the management body as a collective.
Without a senior security strategist who understands these national-level variations, multi-jurisdictional exposure is invisible until an auditor finds it.
The GDPR Dual-Notification Trap
A single data breach at a NIS2 entity can trigger dual notification requirements. Organizations must report to their data protection authority for the personal data impact and to the national cybersecurity authority for the network security impact. Both authorities can impose fines for the same incident, though the law requires that sanctions remain proportionate.
Running two parallel notification tracks, each with its own deadlines and content requirements, in real time during an active incident is an execution problem that only pre-built playbooks and practiced teams can reliably solve.
Supply Chain Cascade Effects
NIS2's supply chain security requirements under Article 21 extend compliance obligations upstream and downstream. Your organization's classification as an essential or important entity automatically makes your cybersecurity posture a contractual matter for every customer who is also subject to the directive. Weak supply chain security evidence becomes a commercial disqualifier, not just a regulatory risk.
NIS2 Audit Readiness: A 90-Day Executive Action Plan
The following checklist gives boards and C-suite executives a structured path to audit readiness. It prioritizes the items auditors examine first.
How I Help
The Fractional CISO (vCISO) engagement is the right-fit solution for organizations that need senior security leadership without the cost or timeline of a full-time hire. Over a focused 90-day NIS2 Exposure Assessment, I map your cross-border obligations across every member state where you operate, determine which national transpositions govern your entity classification, identify the governance gaps auditors will find before they do, and build the board-level reporting framework that satisfies Article 20 requirements. The deliverable is not a checklist; it is an evidence file that stands up to regulatory scrutiny and gives your management body a defensible position when supervisory authorities come knocking. With 20+ years of experience in regulatory environments, I translate complex, multi-jurisdictional obligations into clear executive decisions.
For organizations working through overlapping compliance frameworks such as ISO 27001, SOC 2, or DORA alongside NIS2, I structure programmes that produce shared evidence across all requirements, reducing duplication and cost. My board advisory practice supports directors who need to demonstrate documented cybersecurity oversight as required by Article 20. I also offer security architecture reviews that align your technical controls to Article 21's ten mandatory measures. For organizations managing AI systems within scope of NIS2 or the EU AI Act, Secure AI Deployment addresses the intersection of both regulatory frameworks.
Adil Karam
Security & AI Governance Advisor
Helping organizations navigate security leadership and AI governance challenges.
Related Articles
The EU Cyber Resilience Act's First Deadline Just Hit: Is Your Product Security Program Ready?
CIRCIA Is Almost Law: What Critical Infrastructure CEOs Must Do Before the Final Rule Drops
The CIRCIA Deadline Is Here: What Every Executive Needs to Do Before the Final Rule Hits
Ready to Put These Insights Into Action?
Whether you need secure AI deployment, security leadership, or compliance guidance, we can apply these strategies to your organization.