NIS 2 penalties

What does your organisation risk if it fails to meet the requirements?

Clément Rose · 5 min read
Illustration: a glass judge's gavel next to a stack of coins and a shield
ESSENTIAL ENTITIES €10M or 2% of turnover
IMPORTANT ENTITIES €7M or 1.4% of turnover
MANAGEMENT Held accountable

By October, France must transpose the European NIS 2 Directive (Network and Information Security 2), which strengthens NIS, a directive adopted six years earlier. The new text goes further on several levels: more sectors concerned, a wider scope and, finally, tougher penalties. But what do the organisations concerned risk if they fail to comply with the requirements of NIS 2?

01

Heavier penalties under NIS 2

To strongly encourage organisations to meet the requirements of the directive, the text provides for new penalties. They will be heavier than in the first version of the text, the aim being to move from a best-efforts approach to a regulatory and legal obligation.

Three main categories of penalties stand out:

  • Breaches made public
  • Substantial fines
  • Management held accountable
A · PUBLICITY Breaches made public
B · FINES
up to
or 2% of turnover whichever is higher
Substantial fines
C · LIABILITY
Senior management LIABLE
Elected officials and civil servants LIABLE
Failure to ensure compliance with the directive
Management held accountable

First, one set of penalties provides for publicly naming organisations that fail to comply with the requirements of the law. More specifically, the competent national authorities will make the non-compliance of the organisations concerned public. Going further still, they will be able to publicly identify, through statements, the natural and legal persons responsible for the non-compliance.

In addition, fines could be much heavier than those provided for by NIS 1. They can now reach €10 million or 2% of turnover for essential entities. As we will see in the second part of this article, the amount of these fines depends on the type of entity concerned.

Finally, the directive emphasises the legal liability of management, to make sure these cybersecurity requirements are taken seriously. Company executives, as well as public officials and elected representatives, may therefore be held liable for failing in their obligation to ensure compliance with the directive.

Moving from a best-efforts approach to a regulatory and legal obligation.

02

Penalties that depend on the type of organisation

While penalties will be heavier for all organisations covered by the directive, the measures will differ. The new European directive distinguishes between two types of entities, essential entities and important entities, which will not be affected by NIS 2 in the same way.

As explained in our previous blog post, essential and important entities differ by size and sector. The minimum requirements are the same for both types of entities, but the form of supervision and the penalties vary. Supervision refers to the measures and checks put in place by the competent authorities: continuous monitoring, audits and compliance reports.

In terms of supervision and how strict the checks are:

  • essential entities will have to meet the supervision requirements as soon as NIS 2 comes into force and may be inspected at any time;
  • important entities will be subject to ex post supervision, meaning the authorities will step in if they receive evidence of non-compliance.

Financial penalties are differentiated too:

  • essential entities may face fines of up to €10 million or 2% of their turnover;
  • important entities may face fines of up to €7 million or 1.4% of their turnover.
Your organisation is an…
SUPERVISION Ex ante Supervised from the introduction of NIS 2: the entity can be inspected at any time.
MAXIMUM FINE 10 M€ or 2% of turnover
Fixed amount10 M€
2% of turnover16 M€
Applicable cap 16 M€
The cap is whichever of the two amounts is higher (Article 34 of Directive (EU) 2022/2555). Indicative simulation: the actual amount is set by the authority according to the seriousness of the breach.

So although NIS 2 is more demanding than NIS 1 overall, it will not affect all organisations in the same way, whether in terms of how strict the checks are or how large the fines can be.

03

The role of ANSSI in France regarding NIS 2 penalties

NIS 2 is a European directive: each country must transpose the text into its own law, and each country is responsible for enforcing that law. In France, ANSSI, the National Cybersecurity Agency of France, which is responsible for protecting the nation against cyberattacks, will be in charge of supervision and of applying NIS 2 penalties.

As it points out on its website, ANSSI will be able to identify cases of non-compliance and carry out inspections that may lead to penalties. To that end, the agency is currently defining supervision mechanisms suited to the change of scale that NIS 2 represents.

ANSSI's role is not limited to enforcing penalties: it also supports organisations. It has already launched a beta version of a digital portal called “MonEspaceNIS2”, designed to make its interactions with regulated entities easier. In addition to the solutions available on the market, companies will therefore be supported by a specialised public body on their path to compliance. ANSSI intends to help companies through three main channels:

  • Advisory actions
  • Awareness-raising
  • Operational assistance
INSPECT · PENALISE SUPPORT
Identify non-compliance
Carry out inspections
Apply penalties
ANSSI NIS 2 AUTHORITY IN FRANCE
Advisory actions
Awareness-raising
Operational assistance
MonEspaceNIS2ANSSI portal · beta

Summary

01

An ambitious directive

Overall, NIS 2 is more ambitious than NIS 1, which is also reflected in heavier penalties designed to better ensure it is enforced.

02

Differentiated penalties

Penalties will nevertheless differ between essential and important entities, which will not face the same level of supervision or the same fines.

03

A key role for ANSSI

In France, ANSSI will be responsible for supervising organisations to ensure they comply with the directive, and also for supporting them on their path to compliance.

Written by Clément Rose Phinasoft

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.