NIS2 Fines 2026: Up to €10 Million — Who Is Liable and How to Avoid It

NIS2 is the EU's expanded cybersecurity directive, and Germany implements it through the BSIG, its national cybersecurity act. It applies to medium and large companies in 18 regulated sectors — energy, transport, health, digital infrastructure, manufacturing and more. Crucially for international companies: if you operate a German subsidiary, run infrastructure in Germany, or supply regulated German customers, NIS2 obligations can reach you even if your headquarters are outside the EU.

Enforcement sits with the BSI, Germany's Federal Office for Information Security. It can demand evidence of risk management, order audits, and impose fines that scale with global group turnover — not just German revenue. Unlike earlier regimes, NIS2 also makes executive management personally liable for overseeing cybersecurity measures, a liability that cannot simply be delegated or insured away.

Foreign companies typically get caught in three ways: through mandatory registration and incident reporting (security incidents must be flagged to the BSI within 24 hours), through supply-chain clauses imposed by regulated German customers, and through BSI follow-up after a publicly known breach. The safest path is to determine your exposure now, document it, and close the gaps before the regulator asks.

The sanctions you are facing

€10 millionor 2% of turnover

NIS2 violations carry fines of up to €10 million or 2% of global annual turnover.

Personalmanagement liability

Company management is personally liable for implementing and overseeing the cybersecurity measures.

24 hrsreporting deadline

Security incidents must be reported to the BSI (Germany's Federal Office for Information Security) within 24 hours — hardly feasible without preparation.

Matching tool

Comply with NIS2 before the BSI comes knocking.

NIS2 Shield → Check now for free

Frequently asked questions

Does NIS2 apply to non-EU companies selling into Germany?

It can. NIS2 obligations attach to entities providing in-scope services within the EU, regardless of where the parent company is headquartered. A non-EU group with a German subsidiary, EU-based infrastructure, or in-scope services offered in the EU should assess its exposure — and even out-of-scope suppliers are often bound contractually by their regulated customers.

Who enforces NIS2 fines in Germany?

The BSI, Germany's Federal Office for Information Security, supervises in-scope entities under the BSIG, the German NIS2 implementation act. It can request documentation, order audits and corrective measures, and impose fines of up to €10 million or 2% of worldwide annual turnover for serious violations.

Are executives personally liable under NIS2?

Yes. The German implementation makes executive management personally responsible for approving and monitoring cybersecurity risk-management measures. Directors who fail to oversee implementation can be held personally liable, which is one of the sharpest departures from the previous legal situation.

What happens if we miss the 24-hour incident reporting deadline?

Significant incidents must be reported to the BSI without undue delay — an early warning within 24 hours, followed by a fuller report within 72 hours. Missing these deadlines is itself a sanctionable violation, separate from the incident. In practice, meeting them is only realistic with a prepared and tested reporting process.

More about NIS2 Shield →