NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Explore

  • Blog
  • FAQ
  • Glossary
  • Use Cases
  • Sectors
  • Pricing

Official Sources

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Your Navigator Through NIS2 Compliance

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Imprint

Resources

  • Blog
  • Use Cases
  • Industries
  • Pricing
  • FAQ
  • Glossary

Connect

Contact

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. All Rights Reserved.

Made in GermanyAllianz für Cyber-Sicherheit — Teilnehmer
Home/Blog/§65 BSIG: What Fine Tiers Apply to NIS2 Violations?
  1. How Many Fine Tiers Does §65 BSIG Have, and What Do They Mean in Practice?
  2. When Does the Turnover-Based Fine Cap Under §65 (6) and (7) BSIG Apply?
  3. By What Criteria Does the BSI Assess a Fine Within the Statutory Range?
  4. What Does GDPR Enforcement Practice Show: Authority Approach vs. Court Ruling?
  5. How Does a §65 Fine Proceeding Play Out for a Typical Mid-Sized Company in Practice?
  6. How Can You Realistically Assess Your Own §65 Fine Risk?
  7. Frequently Asked Questions
  8. How Many Fine Tiers Does §65 BSIG Actually Have?
  9. Can a Company Receive Both a GDPR and a NIS2 Fine for the Same Incident?
  10. Who Sets the §65 Fine, and Can It Be Challenged?
  11. At What Turnover Does the Percentage-Based Cap Under §65 (6) and (7) BSIG Apply?
  12. How High Were Fines Under the Old BSIG Rules Before NIS2?
Guide

§65 BSIG: What Fine Tiers Apply to NIS2 Violations?

Authored by NIS2Compass Redaktion, NIS2 Compliance Expert
Last updated:September 27, 202612 min read
Share
Isometric staircase of increasing steps with a section-sign (§) symbol above the highest step, symbolizing the seven fine tiers under §65 BSIG

§65 BSIG tiers NIS2 fines into seven brackets, from EUR 100,000 to EUR 10 million or 2% of turnover. NIS2Compass explains the assessment criteria and real GDPR comparison cases.

Written by the NIS2Compass editorial team | Last updated: September 2026

§65 BSIG tiers fines for NIS2 violations into seven brackets: from EUR 100,000 for obstructing supervisory authorities up to EUR 10 million or 2 percent of worldwide annual turnover for failing to implement risk management. Which bracket applies depends on the specific violation, not on the entity type alone. NIS2Compass maps the seven tiers to the underlying obligations and shows, using real GDPR cases, what authorities impose and courts uphold.

How Many Fine Tiers Does §65 BSIG Have, and What Do They Mean in Practice?

§65 (2) BSIG lists 17 administrative offenses, which (5) groups into seven fine brackets from EUR 100,000 to EUR 10 million. The highest bracket applies to a failure to implement risk management under §30 and to breached reporting obligations under §32. Which tier applies depends on the type of violation, not just company size.

NIS2Compass breaks the seven tiers down against the actual statutory wording, instead of repeating the number seven as a bare headline figure without the underlying provisions. Based on §65 BSIG in full, the structure looks like this:

  • EUR 10 million (essential entities) / EUR 7 million (important entities): §65 (5) No. 1 (a)/(b): failure to implement risk management under §30 (1) sentence 1, missing documentation under §30 (1) sentence 3, breached reporting obligation under §32 (1) sentence 1 or (2) sentence 2, non-compliance with an order under §35 (1) sentence 1 or §36 (2) sentence 1, failure to notify under §35 (2) sentence 1.
  • EUR 5 million: §65 (5) No. 2, violation of §41 (5) sentence 2, covering cooperation and notification duties for critical ICT components.
  • EUR 2 million: §65 (5) No. 3, non-compliance with an order under §11 (6), §16 (1) sentence 1 (also with (4)), §17 sentence 1, or §39 (1) sentence 5, relevant mainly to IT product manufacturers and telecoms.
  • EUR 1 million: §65 (5) No. 4, defective or late evidence under §39 (1) sentence 1.
  • EUR 500,000: §65 (5) No. 5, including missed registration or missing details under §33 (1)/(2) and §34 (1)/(2), non-compliance with orders under §18, §40 (5), or §61 (3)/(6)/(7)/(8), violations of the EU Cybersecurity Act, and violations of certain certification and labeling requirements.
  • EUR 100,000: §65 (5) No. 6, including refusing inspections or information under §61 (5) sentence 3, an unreachable point of contact under §33 (2) sentence 2, and negligent commission of offenses under (1) or (3).

The seven therefore means seven different maximum amounts, not seven equal categories: the top tier splits in two by entity type. §65 BSIG, gesetze-im-internet.de confirms this structure directly in the statutory text.

For mid-sized companies, two tiers matter most in practice. Most violations fall into either the EUR 10/7 million tier for failing to implement risk management under §30 or missing reporting deadlines under §32, or the EUR 500,000 tier for a missed registration under §33. The EUR 2 million and EUR 5 million brackets, by contrast, stay limited to manufacturers and telecoms and rarely apply to NIS2-obligated SMEs.

A compact overview of entity types and maximum thresholds is available in NIS2 Fines: What Penalties Apply for Non-Compliance?

When Does the Turnover-Based Fine Cap Under §65 (6) and (7) BSIG Apply?

The percentage-based cap only applies to essential and important entities with more than EUR 500 million in worldwide annual turnover, and only for the most severe violation category (risk management, reporting obligations). Essential entities then risk up to 2% of total turnover, important entities up to 1.4%. For all other companies, the fixed EUR 10 million or EUR 7 million cap remains decisive.

Under §65 (6) BSIG, an essential entity with turnover above EUR 500 million can face up to 2% of total turnover instead of the fixed EUR 10 million cap, but only for the offenses under (5) No. 1 (a), the §30/§32 category. §65 (7) BSIG applies the same logic to important entities, at 1.4% instead of the fixed EUR 7 million cap.

What counts as total turnover? §65 (8) BSIG defines it as the sum of the company's worldwide revenue in the preceding financial year, group-wide, not just the individual entity's. The authority can estimate this figure if needed.

For the vast majority of NIS2-obligated companies in Germany, the fixed cap remains the relevant one. At the typical SME size of 30 to 250 employees, annual turnover of EUR 500 million is unrealistic. The percentage-based cap affects only large corporations and groups.

According to BSI, NIS-2 in Zahlen, as of June 30, 2026, 6,215 of 17,729 registered companies were recorded as essential entities. No official breakdown by turnover bracket exists, but only a small share of this group likely exceeds the EUR 500 million threshold.

A qualitative leap compared to the old law. Under the version of the BSIG in force before December 2025, there was no turnover component at all; the maximum amount, depending on the offense, was up to EUR 2 million (§14 BSIG old version). The new turnover link still marks a qualitative leap: for large corporations, it can override the fixed cap entirely. The NIS2 fine calculator shows which cap, fixed or percentage-based, would apply in your case.

By What Criteria Does the BSI Assess a Fine Within the Statutory Range?

Within the statutory ceiling, the actual fine is assessed against eight EU-wide criteria: severity, duration, intent or negligence, damage caused, prior violations, preventive measures, certification status, and cooperation. §65 BSIG does not list these itself; it refers instead to the NIS2 Directive and general administrative offense law.

The criteria are set out in Art. 32 (7) of Directive (EU) 2022/2555, which Art. 34 (3) of the same Directive refers back to. Supervisory authorities must give due consideration to these eight criteria in every sanction.

In detail, these are:

  • Severity of the violation and importance of the provision breached. Repeated violations, failure to report significant incidents, failure to remedy deficiencies after being instructed to do so, obstruction of audits, and false statements to authorities are all considered particularly severe.
  • Duration of the violation.
  • Relevant prior violations by the entity.
  • Material or immaterial damage caused, including financial losses and impact on other services or users.
  • Intent or negligence.
  • Measures taken to prevent or mitigate the damage.
  • Compliance with codes of conduct or certification schemes.
  • Degree of cooperation with the authorities.

This list closely resembles Art. 83 (2) GDPR. That makes GDPR enforcement practice methodically transferable: authorities and courts weigh the same factors when setting a fine within the statutory range. The BSIG itself contains no separate list, referring implicitly instead to general administrative offense law: §17 (3) OWiG names the significance of the offense, degree of culpability, and the offender's financial circumstances as assessment factors.

Precision in terminology matters here: §30 OWiG governs corporate fines against companies, whereas §30 BSIG covers risk management measures. The two provisions have nothing to do with each other and should never be referred to imprecisely as just "§30" in the context of fines.

One notable special rule concerns double punishment: §65 (11) BSIG bars an additional BSIG fine where a GDPR authority has already sanctioned the same conduct under Art. 58 (2) (i) GDPR. That links GDPR enforcement to §65 BSIG not just methodically, but legally.

What Does GDPR Enforcement Practice Show: Authority Approach vs. Court Ruling?

No fines have yet been finally imposed under NIS2 in Germany, which is why GDPR practice is the benchmark for comparison. It reveals a clear gap: some fines are accepted in full, others are drastically reduced by courts. The case against notebooksbilliger.de illustrates both directions within a single proceeding.

Case 1, fully accepted: H&M Germany. The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) imposed a fine of EUR 35,258,707.95 in October 2020 for the systematic recording of employees' private details, including illnesses and vacation experiences. The company accepted the decision without appeal. Source: HmbBfDI, press release, October 2020

Case 2, record fine, accepted: Vodafone GmbH. The Federal Commissioner for Data Protection (BfDI) imposed a fine of EUR 45 million on June 3, 2025, still the highest German GDPR fine to date. It consists of EUR 15 million for inadequate control of contracted sales partners and EUR 30 million for authentication gaps that enabled eSIM takeovers. Vodafone accepted and paid the fine in full. Source: BfDI, press release, 06/03/2025

Case 3, authority vs. court, multi-stage: notebooksbilliger.de AG. The Data Protection Commissioner of Lower Saxony imposed a fine of EUR 10.4 million in 2020 for years of unlawful video surveillance of sales floors, warehouse areas, break rooms, and in part customer areas. Source: LfD Niedersachsen, press release

In May 2024, the Hannover Regional Court (Landgericht Hannover) reduced the fine to EUR 700,000, citing new EDPB guidelines and mitigating factors such as cooperation. On appeal by the prosecutor's office, the Celle Higher Regional Court (OLG Celle) raised that reduction slightly to EUR 900,000 on December 18, 2025. The court made clear there is neither a "grace period" in early GDPR enforcement nor a reduction for feared reputational damage. Source: heise online on the OLG Celle ruling

Case 4, a smaller organizational failure: Universitätsmedizin Mainz. The Data Protection Commissioner of Rhineland-Palatinate (LfDI Rheinland-Pfalz) imposed a fine of EUR 105,000 in December 2019 over a mix-up of patients during admission that led to incorrect billing and exposed structural deficiencies in patient management. Even smaller organizational failures without intent can therefore result in fines, albeit at a considerably lower level. Source: dsgvo-portal.de, fine database

Authorities tend to set fines high for deterrent effect. Courts review proportionality case by case, but as notebooksbilliger.de shows, can also raise a fine back up if a reduction went too far. For mid-sized companies, this means: the maximum bracket under §65 (5) BSIG is a signal value, not a realistic prediction. The actual amount depends on the assessment criteria described above.

How Does a §65 Fine Proceeding Play Out for a Typical Mid-Sized Company in Practice?

An anonymized example shows how several §65 tiers can add up in a single case, even without a security incident. An IT service provider first misses BSI registration and later submits incomplete evidence when queried. Both violations trigger separate, independent fine brackets.

An IT service provider with 40 employees and EUR 6 million in annual turnover qualifies as an important entity. The statutory BSI registration deadline of March 6, 2026 passes unnoticed because responsibility was never clearly assigned internally. This is a standalone violation of §33 BSIG and falls under the EUR 500,000 tier of §65 (5) No. 5 BSIG.

When the BSI later asks for evidence of risk management as part of a triggered audit (§39 BSIG), the company can only produce incomplete documentation. This is a separate violation falling under the EUR 1 million tier of §65 (5) No. 4 BSIG. Both fine brackets exist independently. They don't automatically add up to a combined total, but each can be fully exhausted on its own.

Had executive management additionally breached its supervisory duty under §38 (1) BSIG by neither implementing risk management measures under §30 nor supervising their implementation, this would not constitute an additional §65 offense. §38 does not appear in the list of offenses under §65 (2) BSIG. Executive management would instead be liable under §38 (2) BSIG internally, toward its own company, with a separate claim for recourse.

More on this in the article NIS2 Management Liability: §38 BSIG Explained as well as §38 BSIG in full. Both mechanisms can occur together in practice, but must be considered as legally separate matters.

Such cases are not the exception, but the core target group of the NIS2 Directive: by June 30, 2026, BSI, NIS-2 in Zahlen had already registered 11,501 companies as important entities. IT service providers like the one in this scenario typically fall into exactly this category.

How Can You Realistically Assess Your Own §65 Fine Risk?

The statutory framework only shows the abstract ceiling, not the realistic amount in a specific case. Anyone who knows the type of violation, company size, turnover class, and mitigating factors such as early cooperation can assess their own risk considerably more precisely. NIS2Compass has an anonymous, non-binding estimation tool for exactly this purpose.

Four questions help with an initial assessment: Which type of violation is most likely to affect your company: risk management, reporting obligations, or registration? Essential or important entity, or does the company fall under a different category? What is your group-wide annual turnover? And which mitigating factors, such as willingness to cooperate, an existing ISO 27001 certification, or a self-report, could apply in your specific case?

The NIS2 fine calculator captures exactly these variables: type of violation, entity type, turnover class, and mitigating and aggravating factors. The result is a range together with a comparable GDPR case for reference.

The sensible next step is usually an internal stocktaking exercise. Check whether your BSI registration is complete and whether your risk management documentation under §30 reflects the current state. The NIS2Compass Guide walks you through exactly these implementation steps in a structured way.

Frequently Asked Questions

How Many Fine Tiers Does §65 BSIG Actually Have?

§65 (5) BSIG distinguishes seven different maximum amounts: EUR 10 million or EUR 7 million (depending on entity type) for the most severe category, followed by EUR 5 million, EUR 2 million, EUR 1 million, EUR 500,000, and EUR 100,000 for the remaining 17 administrative offenses listed under (2). Which tier applies depends on the specific breach of obligation.

Can a Company Receive Both a GDPR and a NIS2 Fine for the Same Incident?

No. §65 (11) BSIG expressly rules out double sanctioning: if a supervisory authority has already imposed a fine for the same conduct under Art. 58 (2) (i) GDPR, no additional BSIG fine may follow for the same matter. Authorities must therefore coordinate before opening proceedings.

Who Sets the §65 Fine, and Can It Be Challenged?

The BSI is responsible in the vast majority of cases; in certain cases under §65 (2) No. 11, the Federal Ministry of the Interior is responsible instead (§65 (10) BSIG). Fine notices can be challenged through the ordinary courts. The notebooksbilliger.de cases under the GDPR show that judicial review can lead to significant reductions.

At What Turnover Does the Percentage-Based Cap Under §65 (6) and (7) BSIG Apply?

Only once worldwide total turnover exceeds EUR 500 million in the preceding financial year, and even then only for the most severe violation category concerning risk management and reporting obligations. For the vast majority of NIS2-obligated companies in Germany, the fixed cap therefore remains the relevant one.

How High Were Fines Under the Old BSIG Rules Before NIS2?

The version of §14 BSIG in force until December 2025 tiered fines by offense up to a maximum of EUR 2 million for the most serious violations of orders, scaling down to EUR 100,000 for the remaining offenses, considerably lower than today's ceilings. No reliable official statistics on how often fines were actually imposed under this earlier regime could be identified.

Implement NIS2 step by step

NIS2Compass guides you step by step through implementation – with an Implementation Guide, templates and Knowledge Hub.

Get started

Related Articles

guide

AI Agents in GRC Tools: Which Vendor Leads in 2026?

No clear leader has emerged among AI agents in GRC tools in 2026. NIS2Compass compares KaitoSec, Kertos, Athereon, Drata, and Vanta on features, NIS2 coverage, and price.

15 min read

news

Ransomware Attack on a Hospital: Which NIS2 Duties Apply?

A ransomware attack on Nipigon Hospital (Canada) knocked out lab and diagnostics. Which NIS2 duties (§§30, 32, 65 BSIG) apply to German hospitals.

5 min read

guide

NIS2 Crisis Communication: What Role Does Telfo Play?

NIS2 requires crisis management and secure emergency communication under §30 BSIG: escalation matrix, redundant channels, crisis communication plan — plus where Telfo fits in.

10 min read

Back to Blog