NIS2 penalties and fines are no longer only a security issue. They are a financial, operational, and board-level risk.

Under Article 34 of the NIS2 Directive, Essential entities can face maximum fine levels of at least EUR 10 million or 2% of global annual turnover, whichever is higher. Important entities can face maximum fine levels of at least EUR 7 million or 1.4% of global annual turnover, whichever is higher.

Article 34 does not mean every breach starts at EUR 10 million. It sets the minimum maximum fine level Member States must be able to impose for serious Article 21 or Article 23 infringements.

For Dutch organisations, NIS2 is implemented through the Cyberbeveiligingswet (Cbw). As of 30 June 2026, the Cbw has not yet been enacted. The bill has passed the Tweede Kamer and is in the Eerste Kamer plenary stage. The Eerste Kamer committees issued a second report on 26 June 2026 and are waiting for the government’s response before plenary treatment, expected on 6 or 7 July 2026 if that response arrives on time.

That does not mean Dutch companies can wait. Vendor due diligence, buyer questionnaires, cyber insurance reviews, and board risk discussions are already using NIS2 as the evidence standard. The practical risk in H2 2026 is not only a future fine. It is the inability to prove Article 21 controls, Article 23 reporting readiness, management oversight, and supplier security discipline when a buyer, insurer, or authority asks.

This article explains what NIS2 fines can cost, when enforcement can be triggered, what changes in 2026, and how to estimate your maximum fine exposure before a customer, insurer, or authority asks for evidence.

TL;DR

NIS2 fines depend on whether your organization is classified as an Essential entity or an Important entity. Essential entities face a higher fine ceiling and more proactive supervision. Important entities face a lower ceiling, but still carry board-level accountability under Article 20.

QuestionEssential entityImportant entity
Maximum fine levelEUR 10,000,000 or 2% of global annual turnover, whichever is higherEUR 7,000,000 or 1.4% of global annual turnover, whichever is higher
Typical supervision modelProactive supervision: audits, inspections, and assessments can happen before an incidentReactive supervision: action is usually triggered by an incident, complaint, or evidence of non-compliance
Governance dutyManagement bodies must approve and oversee cybersecurity risk-management measuresManagement bodies must approve and oversee cybersecurity risk-management measures
Main enforcement focusArticle 21 risk-management measures and Article 23 incident reportingArticle 21 risk-management measures and Article 23 incident reporting
First pressure point after July 2026Regulator, buyer, insurer, or board risk reviewBuyer, insurer, customer due diligence, or incident-triggered supervision
Essential entity vs Important entity

Not sure whether NIS2 applies to your organisation? Start with the scope question first: check if NIS2 applies to your organisation.

What changes in 2026: Dutch NIS2 pressure starts before fines

The important change in 2026 is not that every Dutch organisation will immediately face a fine. The change is that NIS2 evidence becomes harder to avoid.

Cyberbeveiligingswet status in June 2026

As of 30 June 2026, the Dutch Cyberbeveiligingswet has not yet entered into force. The bill has passed the Tweede Kamer and is now in the Eerste Kamer. The Eerste Kamer status page shows that the Digitalisation and Justice & Security committees issued the second report on 26 June 2026 and are waiting for the government’s response. Plenary treatment is expected on 6 or 7 July 2026 if that response is received on time.

The law will enter into force only after the parliamentary process is complete and the effective date is set. Until then, Dutch organisations should avoid wording that says Cbw fines are already active.

The operational risk is different: customers and procurement teams do not need to wait for national enforcement before asking suppliers for evidence. If your company sells into regulated sectors, supports critical services, provides digital services, or handles sensitive operational data, NIS2 can already appear in vendor questionnaires and renewal discussions.

What buyers can ask for before formal Dutch enforcement

A buyer does not need to issue a fine to create commercial pressure. They can delay onboarding, pause a renewal, request remediation evidence, or require cyber insurance answers before signing.

Buyer questionEvidence they may ask for
Are you in scope for NIS2 or the Dutch Cbw?Scope assessment, sector classification, Essential or Important status, registration readiness
Can you prove Article 21 risk-management measures?Current risk assessment, control map, access control record, supplier security process, business continuity plan
Can you report a significant incident within the required timeline?Incident response plan, escalation matrix, 24-hour early warning workflow, 72-hour notification workflow, final report template
Can management show oversight?Board approval record, cybersecurity training record, assigned risk owner, management review minutes
Can you prove supplier and access discipline?Supplier review process, role-based access control record, quarterly access review, offboarding evidence

That is why 2026 should not be framed only as a deadline. It is a buyer-risk threshold.

If your organisation cannot produce a scope assessment, Article 21 control map, incident reporting workflow, supplier security record, access review evidence, and remediation roadmap, the first cost may appear before the first Dutch fine: a delayed contract, a failed vendor onboarding, an insurer escalation, or a renewal condition your team cannot answer.

Essential vs Important: the classification that determines your fine ceiling

NIS2 fines and penalties

The most important fine question is not: “How large is our company?”

It is: “Are we classified as Essential or Important under NIS2?”

That classification determines three things:

  • The fine ceiling your organisation faces.
  • The supervisory model you can expect.
  • The level of evidence pressure your board, security team, and suppliers need to prepare for.

Essential entities usually operate in sectors where disruption would have a large effect on society or the economy. These include energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, and space.

Important entities cover a wider set of sectors. These include postal and courier services, waste management, chemicals, food production and distribution, manufacturing, digital providers, and research organisations.

For Dutch companies, classification should not be treated as a legal label to check once and forget. It affects your fine ceiling and your evidence burden.

A medium-sized software company may assume NIS2 does not apply because it is not a hospital, bank, energy provider, or telecom operator. That assumption can fail if the company provides managed services, cloud services, cybersecurity services, data centre services, or operational technology support to entities already in scope.

The practical test is simple: if your service is important to the continuity, security, or digital operations of a regulated sector, check the scope before assuming you are outside NIS2.

The NIS2 penalties and fines structure: what Article 34 actually says

Article 34 sets the administrative fine structure for violations of Article 21 and Article 23. The Article 21 covers cybersecurity risk-management measures. And Article 23 covers incident reporting. These are the two areas where NIS2 enforcement becomes financially serious.

The fine ceilings apply per violation and must be effective, proportionate, and dissuasive. Article 34 also allows Member States to provide periodic penalty payments to force an entity to stop an ongoing infringement, but the Directive itself does not set fixed daily EUR amounts for those payments.

Essential entities: maximum fine level of at least EUR 10 million or 2%

For Essential entities, Article 34 sets the fine ceiling at EUR 10 million or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher.

That last phrase matters. EUR 10 million is not always the cap. For larger groups, the percentage-based amount can exceed EUR 10 million.

Global annual turnover2% of turnoverFine ceiling logic
EUR 100 millionEUR 2 millionEUR 10 million applies because it is higher
EUR 300 millionEUR 6 millionEUR 10 million applies because it is higher
EUR 600 millionEUR 12 millionEUR 12 million applies because 2% is higher
EUR 1 billionEUR 20 millionEUR 20 million applies because 2% is higher
Essential entity fine ceiling examples

For an Essential entity with EUR 600 million in global annual turnover, the fine ceiling is not EUR 10 million. It is EUR 12 million. That is why boards should not read the fixed EUR amount in isolation. The turnover percentage is the real exposure for larger groups.

Important entities: maximum fine level of at least EUR 7 million or 1.4%

For Important entities, Article 34 sets the fine ceiling at EUR 7 million or 1.4% of total worldwide annual turnover in the preceding financial year, whichever is higher.

Global annual turnover1.4% of turnoverFine ceiling logic
EUR 100 millionEUR 1.4 millionEUR 7 million applies because it is higher
EUR 300 millionEUR 4.2 millionEUR 7 million applies because it is higher
EUR 600 millionEUR 8.4 millionEUR 8.4 million applies because 1.4% is higher
EUR 1 billionEUR 14 millionEUR 14 million applies because 1.4% is higher
Important entity fine ceiling examples

For many EU SMEs and mid-market companies, the fixed EUR 7 million ceiling will be higher than the turnover percentage. That does not mean the authority will always impose the maximum. It means the legal power exists.

The Dutch Cbw explanatory memorandum follows the same NIS2 fine structure for care duty and reporting duty violations: EUR 10 million or 2% for Essential entities, and EUR 7 million or 1.4% for Important entities, with the higher amount applying.

The practical question is not only “What is the maximum fine?” It is “Can we prove that our Article 21 controls and Article 23 reporting workflow were in place before the incident, audit, or customer review?”

Management personal liability: what Article 20 means for Dutch boards

NIS2 does not treat cybersecurity as a technical task that management can fully delegate.

Article 20 requires Member States to ensure that management bodies approve cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements of Article 21. It also requires members of management bodies to follow training so they can identify risks and assess cybersecurity risk-management practices.

For Dutch organisations, the Cbw carries this board responsibility into national law. NCTV guidance states that board members must have enough knowledge and skills to identify network and information system risks and assess cybersecurity risk-management measures. It also refers to training and certification requirements for board members.

This creates five board-level requirements.

  • First, “we delegated this to IT” is not enough. The board must approve the cybersecurity risk-management measures and oversee implementation.
  • Second, board meeting minutes matter. If management approved the NIS2 programme, the evidence should show when, what was reviewed, what was decided, and what follow-up was required.
  • Third, NIS2 training is not a soft recommendation. Management needs enough knowledge to challenge the risk assessment, not just receive a slide deck.
  • Fourth, personal liability does not mean every board member automatically receives a personal fine. It means management accountability can become part of the enforcement discussion when the organisation failed to approve, oversee, or evidence its cybersecurity programme.
  • Fifth, cyber governance becomes an insurance issue. Directors and officers’ insurance may not protect management if the claim relates to a breach of statutory duties. That risk should be checked with legal counsel and the insurer before an incident happens.

For the full governance angle, see the related article on NIS2 management personal accountability.

The 5 things that actually trigger NIS2 enforcement

The 5 things that actually trigger NIS2 enforcement

NIS2 enforcement usually starts with evidence.

The authority does not need a perfect security programme. It needs to see whether your organisation had proportionate measures, documented decisions, and a clear response process.

These five triggers are the most important to prepare for.

Enforcement trigger 1: failing to report a significant incident

Article 23 requires a staged incident reporting process:

StageTimingWhat it should contain
Early warningWithin 24 hours of becoming aware of the significant incidentWhether the incident is suspected to be unlawful or malicious, and whether it may have cross-border impact
Incident notificationWithin 72 hours of becoming aware of the significant incidentInitial assessment of severity, impact, and available indicators of compromise
Intermediate reportIf requested by CSIRT or competent authorityRelevant status updates
Final reportNo later than one month after the incident notificationDescription, severity, impact, likely root cause, mitigation measures, and cross-border impact where relevant
NIS2 Article 23 reporting sequence

Failure to report on time can become a violation separate from the incident itself.

The control to prepare is not only an incident response policy. You need a tested reporting process: who classifies the incident, who contacts the CSIRT or authority, who approves the message, and what evidence is retained.

Enforcement trigger 2: not implementing Article 21 risk-management measures

Article 21 is the operational core of NIS2. It requires covered entities to implement cybersecurity risk-management measures that are appropriate and proportionate to the risk.

In practice, enforcement risk appears when an audit or incident investigation finds gaps such as:

  • no current risk assessment;
  • no incident response plan;
  • no access control evidence;
  • no supply chain security review;
  • no MFA rollout plan;
  • no business continuity testing;
  • no vulnerability handling process;
  • no documented remediation owners.

A work-in-progress gap is not the same as an undocumented gap. If a measure is still being implemented, document the current state, owner, deadline, and risk acceptance decision.

Enforcement trigger 3: not registering with the competent authority

Under the Dutch Cbw, organisations in scope must register in the entity register. The NCSC states that organisations covered by the Cbw are legally required to register.

Registration is not an admin detail. It is how the supervisory structure knows which entities fall under the regime.

A Dutch company that waits until a customer, authority, or incident forces the issue has already lost control of the timeline.

Enforcement trigger 4: providing false or misleading information

During an audit, inspection, or incident notification, inaccurate information can create a second problem.

This applies especially to incident reporting. If the organisation understates the severity, impact, affected systems, or personal data exposure, the authority may treat the reporting failure separately from the incident.

The control is evidence discipline. Incident logs, forensic notes, escalation records, and decision trails should support what was reported and when.

Enforcement trigger 5: not cooperating with supervision

Essential entities face proactive supervision. Important entities are more often supervised after an incident, complaint, or indication of non-compliance.

In both cases, cooperation matters. If an authority requests documents, access, interviews, or evidence of controls, the organisation must respond within the legal process.

The practical preparation is an evidence pack. It should show the current risk assessment, approved security measures, incident response process, access control review, supplier security process, and remediation roadmap.

The five triggers above are the situations where supervisory authorities can investigate, request evidence, and impose sanctions. A NIS2 gap analysis shows which Article 21 measures are missing, which risks are undocumented, and what your actual exposure looks like before an authority asks the same questions. Start with NIS2 compliance readiness support.

Dutch NIS2 enforcement: who investigates, supports, and fines

For Dutch organisations, NIS2 enforcement will not sit with one generic cyber authority for every company. The Cbw introduces a sector-specific model.

The practical point: your organisation needs to know both who supports incident response and who supervises compliance. Those are not always the same role.

Authority or roleWhat it means in practice
NCSC / national CSIRT roleSignificant incidents are reported through the national incident reporting structure. The organisation needs a workflow that can meet the 24-hour early warning, 72-hour notification, and final report sequence.
CSIRT-DSP / digital service provider supportCSIRT-DSP has been integrated with NCSC-NL since 1 January 2025. Digital service providers now contact NCSC for assistance. This is a support role, not the same as supervisory enforcement.
RDI supervisionRDI presents itself as the Cyberbeveiligingswet supervisor for nine sectors and provides guidance on registration duty, reporting duty, duty of care, governance, supply chain security, and supervision.
Sector-specific supervisorSupervision depends on the sector and classification of the entity. A healthcare, energy, digital infrastructure, transport, financial, or public-sector organisation may face a different supervisory route.
Autoriteit Persoonsgegevens (AP)AP becomes relevant when a cybersecurity incident also involves personal data and GDPR reporting duties. AP is not the general NIS2 supervisor for every incident.
ACM and other sector regulatorsDo not assume ACM is the default NIS2 fining authority for every Dutch company. If ACM is relevant to your wider regulatory position, confirm the sector-specific designation and enforcement route with legal counsel. For NIS2, the evidence requirement remains the same: documented controls, incident workflow, supplier security record, and management oversight.

The AP overlap matters because many real incidents are not cleanly separated into “cybersecurity only” and “privacy only.”

A ransomware incident, exposed database, compromised identity system, or supplier breach can trigger both NIS2 reporting and GDPR reporting. Your organisation then needs one incident record that can answer both tracks: timeline, affected systems, personal data assessment, mitigation steps, external notifications, and retained evidence.

EU enforcement precedent: NIS2 is already operational in other member states

Dutch companies should not treat NIS2 as theoretical just because the Cbw is still moving through the Eerste Kamer.

Other EU member states are already using national NIS2 laws, registration systems, supervisory letters, and compliance milestones. That matters for Dutch suppliers because enterprise buyers often benchmark supplier evidence against the strictest active EU regimes, not only the Dutch timetable.

Member stateWhat is already happeningWhy Dutch suppliers should care
BelgiumThe Belgian NIS2 law entered into force on 18 October 2024. The Centre for Cybersecurity Belgium set an 18 April 2026 milestone for Essential entities to demonstrate implementation of cybersecurity risk-management measures and a recognised compliance pathway.Belgium shows that supervision can move from policy to evidence requests: certification scope, Statement of Applicability, audit report, self-assessment, or inspection path.
ItalyThe Italian ACN registration process required in-scope NIS entities to register through the national platform, with the 2025 registration window running up to 28 February 2025.Italy shows that registration and authority classification can become an operational obligation before companies feel “ready” internally.
GermanyThe BSI Portal supports registration and reporting requirements under the German NIS2 Implementation Act. The portal is used for NIS2 registration and security incident reporting.Germany shows how NIS2 enforcement becomes a portal-driven evidence process: register, report, and maintain documentation through the national authority route.

The pattern is clear: enforcement starts with evidence.

A formal fine may come later. The first supervisory action is often a registration request, information request, audit path, inspection letter, incident report review, or proof that management has approved and monitored the control programme.

For Dutch organisations, the safest assumption is simple: if you cannot show the evidence pack today, build it before H2 2026 procurement pressure turns into a regulatory or contractual problem.

NIS2 fine risk calculator: estimate your maximum exposure

A fine risk calculator will not predict the final sanction. Article 34 requires fines to be effective, proportionate, and dissuasive, and the actual amount depends on the facts of the case.

What the calculator can do is show the maximum fine exposure your board, legal, finance, and security teams should plan around.

Calculator inputs

Use two inputs:

InputWhat the user enters
Entity typeEssential entity or Important entity
Annual global turnoverTotal worldwide annual turnover from the preceding financial year

Calculator logic

Entity typeFixed amountTurnover percentageEstimated maximum fine exposure
Essential entityEUR 10,000,0002% of annual global turnoverHigher of fixed amount or turnover percentage
Important entityEUR 7,000,0001.4% of annual global turnoverHigher of fixed amount or turnover percentage

Formula:

Essential entity maximum exposure = higher of EUR 10,000,000 or 2% of annual global turnover.

Important entity maximum exposure = higher of EUR 7,000,000 or 1.4% of annual global turnover.

Example calculator outputs

Entity typeAnnual global turnoverCalculationEstimated maximum fine exposure
Essential entityEUR 100 million2% = EUR 2 millionEUR 10 million
Essential entityEUR 600 million2% = EUR 12 millionEUR 12 million
Important entityEUR 100 million1.4% = EUR 1.4 millionEUR 7 million
Important entityEUR 600 million1.4% = EUR 8.4 millionEUR 8.4 million

The output is not a fine prediction. It is the maximum exposure level your organisation should use for risk planning.

Add your enforcement trigger score

The maximum fine number only shows ceiling exposure. The next question is whether your current evidence position makes enforcement more likely or harder to defend.

Risk factorLow riskMedium riskHigh risk
Scope clarityClassification documentedScope likely, not approvedScope unknown
Article 21 controlsControl map exists with ownersControls exist but evidence is incompleteNo current control map
Incident reporting24h / 72h / final report workflow testedWorkflow exists but not testedNo tested reporting workflow
Supplier securitySupplier review process documentedKey suppliers reviewed manuallyNo supplier security evidence
Access controlQuarterly access review completedAccess review plannedNo current access review
Management oversightBoard approval and review record existsCybersecurity discussed but not evidencedNo management record
Registration readinessRegistration owner and data preparedOwner assigned, data incompleteNo registration plan
ResultWhat it meansNext action
Mostly low riskYour exposure is mainly documentation and maintenance risk.Keep evidence current and prepare for buyer or supervisory questions.
Several medium risksYour controls may exist, but the evidence is not audit-ready.Build a 30/60/90-day remediation roadmap.
Any high risk in reporting, Article 21, or management oversightA serious incident could expose both compliance and governance gaps.Run a NIS2 evidence review before the next buyer review, insurance renewal, or board risk meeting.

The highest fine ceiling is not always the most urgent risk. A company with incomplete incident reporting, no supplier security evidence, and no board record may face commercial pressure before formal enforcement: blocked onboarding, delayed renewals, insurer questions, or customer escalation.

The useful output is not a single number. It is a short list of evidence gaps your team can close before someone else controls the timeline.

Beyond the headline fine: the full cost of NIS2 non-compliance

The fine is the easiest number to quote. It may not be the largest cost.

For a board or CFO, the real exposure sits across five cost categories.

Cost categoryWhat it means in practice
Regulatory fineThe Article 34 fine for Article 21 or Article 23 violations. This is the visible sanction.
Operational disruptionManagement, legal, IT, security, and vendor teams are pulled into investigation response. The cost is measured in time, delay, and urgent remediation.
Reputational damagePublic enforcement, customer concern, procurement review, and investor questions can follow a serious failure.
Contract lossEnterprise customers increasingly ask suppliers to prove NIS2 readiness. Weak evidence can block renewals, onboarding, or new contracts.
Insurance impactCyber and D&O insurers may ask whether statutory duties were met. A weak governance record can create coverage disputes.

“We will fix it if the authority asks” is an expensive strategy.

After enforcement starts, the organisation is no longer choosing its own timeline. It is responding to regulatory pressure, customer pressure, and internal escalation at the same time.

A lower-cost path is to identify the gaps before the trigger happens.

How Sunbytes approaches NIS2 compliance readiness for EU and Dutch organisations

The exposure outlined above is why NIS2 readiness should start with evidence, not assumptions.

Sunbytes helps EU and Dutch organisations map their current security posture against NIS2 Article 21, identify missing controls, and turn those gaps into a practical remediation plan.

The output is clear:

  • what is already in place;
  • what needs to be fixed first;
  • what evidence your team needs for board review;
  • what buyers or insurers may ask for;
  • what to prioritise before a supervisory question arrives.

For NIS2 readiness, that evidence pack should include a scope assessment, Article 21 control map, incident reporting workflow, supplier security record, access review evidence, board oversight record, and 30/60/90-day remediation roadmap.

Sunbytes is a Dutch technology company with 15+ years of experience helping international clients turn strategy into reliable delivery with security built in. For NIS2, that matters because compliance is not only a legal checklist. It depends on secure systems, accountable delivery, and the right people maintaining controls over time.

Sunbytes Cybersecurity Solutions helps organisations reduce risk through security assessments, vulnerability management, and compliance readiness. For NIS2, this means mapping Article 21 requirements into evidence, remediation priorities, and audit-ready documentation.

Sunbytes Digital Transformation Solutions supports the implementation layer: secure systems, delivery pipelines, access control, documentation, and product workflows. NIS2 controls should be built into real systems, not left as policy documents.

Sunbytes Accelerate Workforce Solutions supports the people layer where controls often fail: role ownership, access discipline, supplier coordination, onboarding, and offboarding.

Start with a NIS2 gap analysis through Sunbytes Compliance Readiness.

FAQs

NIS2 penalties depend on whether the organisation is classified as an Essential entity or an Important entity. Essential entities can face maximum fine levels of at least EUR 10 million or 2% of global annual turnover, whichever is higher. Important entities can face maximum fine levels of at least EUR 7 million or 1.4% of global annual turnover, whichever is higher.

No. Article 34 sets the minimum maximum fine level Member States must be able to impose. It does not mean every breach starts at EUR 10 million. The actual fine should be effective, proportionate, and dissuasive, based on the circumstances of the case.

Dutch NIS2 enforcement follows the Cyberbeveiligingswet. For organisations in scope, duties apply from the moment the Cbw enters into force. The NCSC states that the Cbw is expected to enter into force around 1 July 2026 and that covered organisations must meet the obligations from the effective date.

After the Dutch Cyberbeveiligingswet enters into force, in-scope organisations must meet the Cbw obligations from the effective date. For suppliers, the first pressure may come from buyers rather than regulators. Enterprise customers, insurers, and regulated clients can ask for NIS2 evidence during onboarding, renewal, or due diligence.

Article 20 requires management bodies to approve and oversee cybersecurity risk-management measures and allows them to be held liable for infringements of Article 21. Whether a specific board member faces a personal sanction depends on Dutch law, the facts, and the enforcement decision. The practical requirement is to document board approval, oversight, training, and risk ownership.

ISO 27001 helps, but it is not immunity. Certification can show that many governance, access control, risk management, incident response, and supplier controls are in place. NIS2 still requires the organisation to show that the relevant Article 21 measures are implemented, proportionate, current, and evidenced.

They apply if your organisation is in scope as an Essential or Important entity. Some smaller companies assume they are out of scope because they are not a bank, hospital, or energy provider. That assumption can be wrong if the company operates in a listed sector or provides digital services to regulated entities.

Start with four documents: a scope assessment, Article 21 control map, Article 23 incident reporting workflow, and board oversight record. Those four outputs answer the first questions a buyer, insurer, or authority is likely to ask. After that, build the supplier security record, access review evidence, and 30/60/90-day remediation roadmap.

Yes, but the wording needs care. Article 34 allows Member States to provide periodic penalty payments to compel an entity to stop an infringement. The Directive does not set fixed daily EUR amounts, so any daily penalty figure should be checked against the national implementation and the authority’s decision.

Let’s start with Sunbytes

Let us know your requirements for the team and we will contact you right away.

Name(Required)
untitled(Required)
Untitled(Required)
This field is for validation purposes and should be left unchanged.

Blog Overview