NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Weiterführende Seiten

  • Blog
  • FAQ
  • Glossar
  • Use Cases
  • Branchen
  • Preisgestaltung

Offizielle Quellen

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Ihr Navigator durch die NIS2-Compliance

Rechtliches

  • Datenschutzerklärung
  • Allgemeine Geschäftsbedingungen
  • Cookie-Richtlinie
  • Impressum

Ressourcen

  • Blog
  • Use Cases
  • Branchen
  • Preise
  • FAQ
  • Glossar

Kontakt

Kontakt

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. Alle Rechte vorbehalten.

Entwickelt in DeutschlandAllianz für Cyber-Sicherheit — Teilnehmer
Home/Blog/NIS2 Fines: What Penalties Apply for Non-Compliance?
Guide

NIS2 Fines: What Penalties Apply for Non-Compliance?

Authored by NIS2Compass Team, NIS2 Compliance Expert
Last updated:July 30, 20269 min read
NIS2 fines and management liability — shield with euro and paragraph symbol

NIS2 violations can cost companies up to EUR 10 million or 2% of global annual turnover. Learn about fines for different violations, personal management liability, and what two practical scenarios reveal.

NIS2 violations can cost companies up to EUR 10 million or 2% of global annual turnover. The NIS2UmsuCG has been in force since December 2025, and the BSI can audit and impose sanctions. Of the roughly 29,500 affected companies in Germany, only about 18,500 had registered with the BSI by the end of May 2026. The free Pre-Check from NIS2Compass shows you in just a few minutes where your company stands.

If you already hold an ISO 27001 certificate: the § 38 liability of executive management applies to certified companies too. An ISO 27001 certificate protects you from neither personal liability nor fines, and it does not cover core NIS2 obligations such as reporting deadlines and BSI registration. More on this: Is an ISO 27001 certificate enough for NIS2 compliance?

What Fines Does the NIS2UmsuCG Impose?

The NIS2UmsuCG sets out a tiered penalty structure based on entity type and violation in § 65 BSIG. Essential entities face fines of up to EUR 10 million or 2% of global annual turnover, while important entities face up to EUR 7 million or 1.4%. Whichever amount is higher applies. For comparison: cyberattacks cause EUR 202.4 billion in damage in Germany every year (Bitkom Wirtschaftsschutz 2025). To estimate what your own exposure looks like, the NIS2 fine calculator works it out from entity type and turnover.

What Are the Maximum Penalties by Entity Type?

  • Essential entities (§ 28 Abs. 1 BSIG): up to EUR 10 million. Above roughly EUR 500 million in annual turnover, the 2% turnover cap is higher and therefore applies.
  • Important entities (§ 28 Abs. 2 BSIG): up to EUR 7 million. Above roughly EUR 500 million in annual turnover, the 1.4% cap applies accordingly.

How Are Penalties Tiered by Type of Violation?

Not every violation carries equal weight. § 65 BSIG differentiates by the nature of the breach:

  • Reporting and registration violations: up to EUR 5 million
  • Non-compliance with BSI enforcement orders: up to EUR 2 million
  • Failure to provide evidence: up to EUR 1 million
  • Other violations: up to EUR 500,000
  • Obstruction of supervision: up to EUR 100,000

So even a missed BSI registration can have severe consequences. That is precisely where the biggest gaps currently are.

What Does This Mean for Mid-Sized Companies?

A manufacturing company with 160 employees and EUR 25 million in annual turnover qualifies as an important entity and falls under the EUR 7 million cap. Since its turnover is far below EUR 500 million, the fixed cap applies, not the percentage. The maximum fine therefore amounts to more than a quarter of annual turnover.

The NIS2Compass Guide walks you through the implementation measures for each of these obligations, step by step.

Who Is Personally Liable? Executive Liability Under § 38 BSIG

Under § 38 BSIG, executive management is personally liable with their personal assets for implementing cybersecurity obligations. This responsibility cannot be delegated: neither to a CISO nor to external service providers. According to the BSI Annual Report 2025, 48% of KRITIS operators still lack adequate attack detection capabilities.

Executive management must actively approve the risk management framework under § 30 BSIG and supervise its implementation. Security strategies therefore belong on the boardroom agenda. A CISO can be responsible for operational execution, but overall strategic accountability remains with executive management.

Liability applies as internal liability with personal assets. The company itself can hold executive management liable for damages caused by breaches of duty. A waiver of liability is prohibited by law. § 38 Abs. 2 BSIG explicitly prohibits shareholder agreements from releasing executive management from this responsibility. Even a D&O insurance policy does not protect against all consequences.

There is also a training obligation. Executive management must attend cybersecurity training at least every three years. The BSI offers a dedicated executive training program that takes approximately four hours. The obligation applies equally to essential and important entities.

Which board resolutions, records and documents management has to keep on file is covered in the article NIS2 Management Liability: §38 BSIG Explained. The NIS2Compass Guide walks you through the risk management measures required by § 30 BSIG across 8 chapters.

Which Violations Trigger Fines?

Fines can be imposed for five core offenses, ranging from missing security measures to late reporting of an incident. The statutory registration deadline expired on March 6, 2026. The BSI has granted a grace period until July 31, 2026; by the end of May 2026, around 18,500 of roughly 29,500 affected entities had registered (heise online). If you have still not registered, you are committing an administrative offense under § 65 BSIG. What to do now is covered in the article NIS2 BSI Registration: Missed the Deadline, What Now?.

Which Offenses Occur Most Frequently?

  • Missing risk management measures (§ 30 BSIG): the central obligation. Companies must demonstrate technical and organizational measures.
  • Reporting obligation violation (§ 32 BSIG): the deadlines of 24 hours, 72 hours, and one month are not met. For details, see the article NIS2 Reporting Obligations: When, What, and to Whom?.
  • Failure to register with the BSI (§ 33/34 BSIG): the statutory deadline of March 6, 2026 has expired.
  • Missing documentation and evidence (§ 39, § 61 BSIG): documents must be provided upon BSI request.
  • Obstruction of a BSI audit: anyone who impedes or refuses inspections faces additional sanctions.

Which Ten Areas Does § 30 BSIG Define?

The first offense listed above carries particular weight. § 30 Abs. 2 BSIG defines ten specific areas in which entities must implement appropriate measures:

  1. Risk analysis and security concepts
  2. Incident handling
  3. Business continuity and crisis management
  4. Supply chain security
  5. Security in the acquisition, development, and maintenance of IT systems
  6. Assessment of the effectiveness of measures
  7. Cyber hygiene and training
  8. Cryptography and encryption
  9. Personnel security, access controls, and asset management
  10. Multi-factor authentication and secure communications

If even one area is missing, a violation exists. The BSI can specifically inquire about each individual point during audits.

Implementation lags well behind that: according to the study Cybersicherheit in Zahlen by G DATA, brand eins and Statista, only 12.1% of affected companies have fully implemented NIS2. Whether your company is affected is covered in the article Am I Affected by NIS2?. Ready-made templates for risk analyses, security concepts, and incident response plans are available in the NIS2Compass Template Library. An overview of all NIS2 compliance templates is available on the dedicated templates page.

How Does Supervision Differ by Entity Type?

Essential and important entities carry substantively identical obligations. What differs is the intensity of supervision, the penalty ceiling, and the BSI's power to suspend management. Essential entities are subject to proactive BSI oversight even without a specific triggering event, while important entities are audited only on a reactive basis. As of March 31, 2026, 1,173 KRITIS operators with 2,109 facilities were registered with the BSI (BSI, KRITIS in Zahlen).

In detail, the two types differ as follows:

  • Supervision type: proactive (ex ante) for essential entities, incident-triggered for important entities.
  • BSI audits without cause: yes for essential entities, from December 2028 at the earliest for non-KRITIS. No for important entities.
  • On-site inspections: any time for essential entities, only with specific cause for important entities.
  • Management suspension: only for essential entities, temporarily under § 61 BSIG.
  • Maximum fine: EUR 10 million or 2% of annual turnover, against EUR 7 million or 1.4%.
  • Reporting obligations, risk management under § 30 and executive liability under § 38: identical for both types.

For mid-sized companies, this means: a manufacturing company with 160 employees typically qualifies as an important entity. It is audited only on a reactive basis but must meet the same requirements for risk management and reporting as an energy provider under proactive supervision.

What Happens If You Violate the Reporting Obligation?

If you fail to report a significant security incident within 24 hours, you commit an administrative offense with fines of up to EUR 5 million. The BSI puts speed before completeness: the statutory deadlines are upper limits, not targets. The BKA Bundeslagebild Cybercrime 2024 shows how real the risk is: 950 companies and institutions reported a ransomware case to the police in 2024, two to three serious attacks per day.

How Does the Three-Stage Reporting Process Work?

  • Early initial report, 24 hours: a first assessment of the incident. Speed is what counts here.
  • Follow-up report, 72 hours: updated assessment including severity details.
  • Final report, 1 month: root cause analysis, measures taken, concrete impact.

Reports are submitted through the BSI reporting platform. Each stage builds on the previous one, so you do not need to have all the answers at once.

What Is the Most Common Mistake When Reporting?

Many companies want to sort everything out internally first and then report. This is exactly what leads to missed deadlines. The 24-hour initial report does not require a complete analysis. A preliminary assessment is sufficient: which systems are affected and whether the incident is ongoing. Do not wait for a finished forensics report. Report first, investigate in parallel.

Are There Consequences Beyond Fines for NIS2 Violations?

Yes. Beyond fines, companies face personal liability of executive management with personal assets (§ 38 BSIG), temporary suspension of management functions by the BSI (§ 61 BSIG), binding enforcement orders with deadlines, and significant reputational damage. According to Bitkom (2025), ransomware caused damage at 34 percent of companies within a single year. Two scenarios illustrate how fines, liability, and supervisory measures interact.

Scenario A: Ransomware at a Manufacturing Company

A mid-sized manufacturer with 160 employees and EUR 25 million in annual turnover falls victim to a ransomware attack. Production comes to a standstill. As an important entity, the company is subject to NIS2 obligations.

The managing director decides: "Let's figure out what happened internally first, then report." As a result, the 24-hour deadline for the initial report passes. That alone constitutes a violation of § 32 BSIG and a possible fine of up to EUR 5 million.

The subsequent investigation uncovers further deficiencies. There is no documented incident response process. The last backup test was 18 months ago. Both violate the risk management obligations under § 30.

More serious still: the managing director had never formally approved the security measures and never supervised their implementation. This triggers personal liability under § 38. The company can hold him personally liable for damages, and a waiver of liability by the shareholders is prohibited by law.

Scenario B: BSI Audit at an IT Service Provider

A managed service provider with 80 employees qualifies as an essential entity and is therefore subject to stricter supervision. The BSI conducts a proactive audit under § 61 without any specific triggering event.

The auditors find: no documented risk management, no regular risk analysis, no asset inventory. These are fundamental violations of § 30, and the penalty framework here reaches EUR 10 million.

The BSI orders a remediation plan with a concrete deadline. The company fails to respond in time. The BSI then resorts to its most powerful instrument and temporarily prohibits the managing director from performing their duties (§ 61 Abs. 5). The suspension is only lifted once all orders have been fully implemented.

Why Are These Scenarios Not Exceptions?

According to the ENISA Threat Landscape 2025, manufacturing is one of the five most targeted sectors in the EU, and essential entities account for 53.7 percent of all recorded incidents. How to meet the reporting deadlines in the first hours after an attack is covered in the article NIS2 Reporting Obligations: When, What, and to Whom?. In-depth articles on risk management and reporting obligations are available in the NIS2Compass Knowledge Hub. With the Pre-Check from NIS2Compass, you can assess upfront whether your company is prepared.

Both scenarios are constructed examples and serve as illustrations. They do not constitute legal advice.

Frequently Asked Questions About NIS2 Fines

How High Are the NIS2 Fines?

The penalty amount depends on your company's classification. Essential entities face fines of up to EUR 10 million or 2% of global annual turnover, whichever amount is higher. Important entities must reckon with up to EUR 7 million or 1.4% of annual turnover. The exact amount depends on the type and severity of the violation under § 65 BSIG.

Is Executive Management Personally Liable, Including With Personal Assets?

Yes. Under § 38 BSIG, managing directors and board members are personally liable toward their own company (known as internal liability). A waiver of these claims through shareholder agreements is prohibited by law. Even delegating operational tasks to a CISO does not release executive management from its supervisory duty; they remain ultimately responsible.

Is There a Transition Period?

No. The NIS2 transposition law has been in force since December 6, 2025, and there is no general transition period. For BSI registration, the statutory deadline expired on March 6, 2026; the BSI has granted a grace period until July 31, 2026. That grace period is a matter of enforcement discretion and does not change the fact that the obligation has been breached since March.

What Happens If I Fail to Report a Security Incident?

Failure to report or late reporting of a security incident is an administrative offense under § 65 BSIG and can result in fines of up to EUR 5 million. The initial report to the BSI must be submitted within 24 hours of becoming aware of the incident. The guiding principle is speed before completeness: a preliminary assessment is sufficient initially.

Am I Affected as a Manufacturing Company With 160 Employees?

Very likely, yes. The manufacturing sector falls under Annex II of the NIS2 Directive. Companies with 50 or more employees or EUR 10 million or more in annual turnover qualify as important entities and are subject to the full range of NIS2 obligations. With the free Pre-Check from NIS2Compass, you can determine in just a few minutes whether your company is affected.

Further answers on fine amounts, supervision and reporting obligations are available in the official BSI FAQ on NIS-2 (German only).

Calculate the Fine Risk for Your Company

The NIS2 fine calculator estimates your individual exposure anonymously in 2 minutes, based on sector, turnover and type of violation.

Related Articles

Do I Need an ISMS for NIS2? Mandatory or Optional · NIS2 Reporting Obligations: When, What, and to Whom? · NIS2 Management Liability: §38 BSIG Explained

Implement NIS2 step by step

NIS2Compass guides you step by step through implementation – with guide, templates and knowledge hub.

Get started

Ähnliche Artikel

guide

When Is a Security Incident Reportable? (§ 32 BSIG)

A significant security incident under § 2 no. 11 BSIG: when you have to report to the BSI, and why the 500,000 euro threshold binds only eleven types of digital service provider.

9 Min. Lesezeit

tips-tricks

Management Self-Check under Section 38 BSIG: The Free Excel Template

Free Management Self-Check under Section 38 BSIG as an Excel template: 20 yes/no questions, 5 sections, traffic-light status, no email gate.

6 Min. Lesezeit

guide

NIS2 Guide: How 8 Chapters Lead to Compliance

The NIS2Compass NIS2 Guide walks you through 8 chapters, from registration to training, toward NIS2 compliance. What each chapter covers and how templates help.

10 Min. Lesezeit

Back to Blog