Cybersecurity

NIS2 Enforcement Has Started: The First Fines and What Triggered Them

TuniCyberLabs Team
6 min read

NIS2 enforcement now moves on two tracks: CJEU referrals against late-transposing member states and national fines against in-scope entities. Here is what triggered the escalation and what mid-market suppliers must fix first.

Has NIS2 enforcement actually started, or is this still a grace period?

Enforcement has started, but it runs on two separate tracks. The European Commission is pursuing member states that missed the 17 October 2024 transposition deadline, escalating toward the Court of Justice of the EU. Separately, national authorities in states that did transpose can now open supervisory actions and levy fines on in-scope entities. Verify current status against primary EU sources.

  • The directive is not self-executing. NIS2 (Directive (EU) 2022/2555) is not directly enforceable against companies. It had to be written into national law by 17 October 2024, and fines land under that national transposition, not the directive text itself.
  • Most states were late. According to public reporting, a large majority of member states missed the deadline, and the Commission opened infringement proceedings against them in stages through late 2024 and 2025.
  • Two clocks are ticking. In a state that has transposed, the competent authority already holds supervisory powers today. In a state that has not, your obligation crystallizes the moment national law lands, often with little runway.
  • For the engineering view of these obligations, see NIS2 in 2026: Turning the Directive into an Engineering Backlog.

What triggered the first CJEU referrals against member states?

The referrals are an infringement remedy against governments, not a corporate penalty. When a member state ignores a letter of formal notice and then a reasoned opinion, the Commission can refer it to the Court of Justice of the EU under Article 258 TFEU. Public reporting points to several states, reportedly including Ireland, Spain, France and the Netherlands, facing escalation in 2026.

  • The escalation ladder. Formal notice, then reasoned opinion, then CJEU referral. On a second referral under Article 260 TFEU, the Court can impose lump sums and daily penalty payments on the state itself.
  • The fault was transposition, not a breach. States were faulted for incomplete or partial transposition, missing sectors, absent supervisory regimes or no registration mechanism, not for any single security incident.
  • Why suppliers should care. Court pressure accelerates national law. Provisions that felt theoretical in 2024 become live obligations quickly once a government rushes to close the gap.
  • Treat any specific referral list as provisional and confirm it against the Commission infringement decisions register.

Who can be fined under NIS2, and how large can the fines get?

NIS2 sets maximum administrative fines in Article 34. Essential entities face up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to EUR 7 million or 1.4%. National law sets the exact regime, and management bodies can be held personally accountable.

  • Essential versus important. Annex I sectors (energy, transport, banking, health, digital infrastructure, public administration, space) skew essential. Annex II sectors (postal, waste, chemicals, food, manufacturing, digital providers, research) skew important, with lighter supervision.
  • Personal liability is real. Article 20 requires management bodies to approve and oversee the risk-management measures. Article 32 lets authorities, for essential entities, suspend certifications and temporarily bar individuals from management functions.
  • Non-monetary measures bite too. Binding instructions, mandatory audits and public disclosure of non-compliance can damage a supplier relationship more than the fine itself.

What actually triggers a fine for a company, not a member state?

For companies, enforcement is triggered by a supervisory finding, not automatically by a breach. Authorities act after an incident notification, a third-party complaint, a risk-based or random audit, or evidence that you failed the Article 21 baseline measures or the Article 23 reporting clocks. A breach compounded by weak controls and late reporting is the classic trigger.

  • Common triggers: failure to register as an in-scope entity, missing MFA, untested backups, no supply-chain security process, and late or absent incident reports.
  • Two supervision styles. Essential entities face proactive, ex ante supervision, meaning authorities can audit without cause. Important entities face reactive, ex post supervision, typically after an incident or complaint.
  • Documentation is your defense. The difference between a warning and a fine is often whether you can show a dated risk assessment, tested controls and a reporting runbook.

Am I in scope if I only supply an essential entity?

Often yes, through one of two doors. First, you may be directly in scope if you are a medium or larger enterprise operating in an Annex I or II sector. Second, even when you are out of scope directly, Article 21(2)(d) forces your customers to manage supply-chain risk, so their obligations reach you through contracts.

  • The size-cap rule. In-scope generally means at least 50 staff or over EUR 10 million in annual turnover or balance sheet, within a listed sector. Some entity types (DNS providers, TLD registries, cloud, data centres, CDNs, managed service and security providers) are in scope regardless of size.
  • Contractual flow-down. Expect security clauses, evidence requests, SBOMs, incident-cooperation terms and right-to-audit language from essential-entity customers.
  • The vetting mechanics are covered in NIS2 Supply-Chain Security in 2026: Who Is in Scope, How to Vet Vendors, and How to Build Auditable Software.

What must a mid-market supplier fix in the next 90 days?

Focus on the controls authorities check first. Confirm your in-scope status and register with the competent authority, stand up 24-hour and 72-hour incident reporting, enforce MFA and tested backups, formalize supply-chain security, and get your management body to approve the risk-management program in writing. These map directly to Articles 20, 21 and 23.

  • Scope and registration: determine essential or important status and register where required; several digital-infrastructure entity types had early registration duties.
  • Incident runbook: wire the 24-hour early warning, 72-hour notification and one-month final report into an on-call process, not a wiki page.
  • Article 21 baseline: risk analysis, incident handling, business continuity and backup, supply-chain security, secure development, effectiveness testing, cyber hygiene and training, cryptography, and access control with MFA.
  • Governance evidence: board minutes approving the program and dated training records for leadership.
  • A pragmatic starting point is The 2026 SME Cybersecurity Checklist for GDPR, NIS2 and DORA.

How do the 24-hour and 72-hour reporting clocks work?

Article 23 sets a staged clock for significant incidents. You submit an early warning within 24 hours of becoming aware, a fuller incident notification within 72 hours with an initial assessment, and a final report within one month. Authorities can request intermediate updates. Missing any of these deadlines is itself a sanctionable failure.

  • What counts as significant: an incident causing severe operational disruption or financial loss, or one affecting other parties through cascading impact.
  • The 24-hour warning is minimal. It only needs to indicate whether the incident is suspected to be malicious or could have cross-border impact, buying you time for the fuller 72-hour report.
  • Rehearse it. A tabletop that walks the clock end to end exposes gaps faster than any policy review, as covered in Incident Response Playbooks That Teams Actually Use.

How TuniCyberLabs helps

We treat NIS2 as an engineering program, not a paperwork exercise. TuniCyberLabs maps your entity classification, builds the Article 21 control baseline into your stack, wires the 24/72-hour reporting runbook into on-call, and produces the audit evidence a competent authority will actually ask for. We work across the EU and North Africa, with delivery engineered in Tunisia.

If NIS2 scope or enforcement exposure is unclear, talk to our team for a scoped readiness review.

TAGS
NIS2EU cybersecurity regulationcomplianceincident reportingsupply chain securityCJEUadministrative fines

Frequently Asked Questions

When was the NIS2 transposition deadline?

+

The NIS2 transposition deadline was 17 October 2024, the date by which every EU member state had to write Directive (EU) 2022/2555 into national law. Many states missed it, which triggered European Commission infringement proceedings and, per public reporting, referrals toward the Court of Justice of the EU in 2026. Confirm your national law status with the competent authority.

How much can a company be fined under NIS2?

+

NIS2 Article 34 sets maximum administrative fines of up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher, for essential entities, and up to EUR 7 million or 1.4% for important entities. National transposition laws set the precise regime, and management bodies can face personal accountability, including temporary bans from management functions.

What is the difference between essential and important entities?

+

Essential entities sit mainly in NIS2 Annex I sectors such as energy, transport, banking, health and digital infrastructure, and face proactive, ex ante supervision. Important entities sit mainly in Annex II sectors such as postal services, waste, manufacturing and digital providers, and face reactive, ex post supervision after incidents or complaints. Both must meet the Article 21 baseline.

Does NIS2 apply to my company if I only supply an in-scope entity?

+

Possibly, through two routes. You are directly in scope if you are a medium or larger enterprise in an Annex I or II sector. Even if not, Article 21 requires your essential-entity customers to manage supply-chain risk, so they will push NIS2-style security clauses, evidence requests and audit rights into your contracts, effectively extending obligations to you.

What are the NIS2 incident reporting deadlines?

+

Article 23 sets a staged clock for significant incidents: an early warning within 24 hours of awareness, a fuller notification within 72 hours with an initial assessment, and a final report within one month. Authorities may request intermediate updates. The 24-hour warning only needs to flag suspected malicious activity or possible cross-border impact, so it is quick to file.

What should a mid-market supplier prioritize for NIS2 now?

+

Confirm scope and register with the competent authority, then implement the controls audits check first: MFA, tested backups, a supply-chain security process, secure development, and a working 24/72-hour incident reporting runbook. Have your management body formally approve the risk-management program and keep dated evidence. These map to NIS2 Articles 20, 21 and 23 and de-risk any supervisory review.

Need help with
this topic
?

Our team specializes in the technologies and strategies discussed in this article. Let’s talk about how we can help your business.

Get in Touch