Skip to main content
Sanctions for non-compliance with NIS2
Back to all Insights

Insights · IT security

Sanctions for non-compliance with NIS2

The national legislator was required to transpose the NIS2 Directive ((EU) 2022/2555) into national law by 17 October 2024. Even though that deadline could hardly be met, the rules are coming. And they are foreseeable. Action is therefore required! The NIS2 Directive covers a far wider range of institutions than its 2016 predecessor.

Published
11 October 2024
Reading time
4 min read

Share this article

NIS2: sanctions and liability risks for companies

Digital processes are more efficient processes. Unfortunately, however, increasing connectivity also has its downsides: cyberattacks threaten the security of companies, public authorities and other institutions. It is therefore all the more important to give cybersecurity sufficient attention. To ensure that this task is not underestimated, the EU has adopted the NIS2 Directive. It affects around 30,000 institutions across Germany, primarily companies. The Directive covers all companies with more than 50 employees or annual turnover exceeding EUR 10 million. Even if they are smaller, companies may fall under the NIS2 provisions if they are considered structurally important.

The NIS2 Directive (Network and Information Security) aims to ensure a high common level of cybersecurity throughout the EU. If you would like to learn more about the NIS2 Directive, read how NIS2 is being implemented in Germany and how companies can implement the cybersecurity requirements.

Germany will transpose the NIS2 Directive into national law through the Act on the Federal Office for Information Security (BSIG), even though the original October 2024 deadline could not be met. While the NIS Directive initially applied only to so-called critical infrastructure, the group of addressees is now being expanded considerably. It is therefore high time for companies to examine the technical, operational and organisational requirements that apply to them and consider the liability risks under the new sanctions regime. One thing is already clear: failure to comply with the NIS2 requirements can result in substantial fines.

What does the NIS2 Directive regulate?

We have already summarised general information about the NIS2 Directive and whether it applies to your company elsewhere: How do companies implement the NIS2 cybersecurity requirements? (clarius.legal) or NIS2 Directive: implementation and current status in Germany (clarius.legal).

What sanctions does the implementing act provide for?

Disregarding the NIS2 Directive can be costly. The new section 65 of the draft BSIG gives supervisory authorities the power to impose fines. Unlike before, the legislator bases these on worldwide annual turnover as well as fixed maximum amounts. The basis for calculating fines is therefore becoming stricter.

Section 28 of the draft BSIG distinguishes between “important entities” and “essential entities”. Classification is based on particular industry sectors and company size. “Essential entities” face fines of up to EUR 10 million or 2 per cent of worldwide turnover in the preceding financial year. For “important entities”, the fine may rise to EUR 7 million or 1.4 per cent of turnover — whichever amount is higher.

(For an overview of the obligations, see: NIS2 Directive: implementation and current status in Germany). It must be assessed in each individual case which companies are covered and with what consequences. It should be noted that smaller companies may also be covered if they have particular sector-specific importance.

What can fines be imposed for?

Once the NIS2 Directive has been transposed into national law, all companies that disregard or circumvent the requirements of the updated BSIG will face fines. This covers legal, technical and organisational aspects:

  • Companies covered by the NIS2 requirements must register with the Federal Office for Information Security (BSI) and report security incidents to it.
  • Companies must demonstrate that they have appropriate security measures in place to protect their network and information systems at all times.
  • They must also raise their employees’ awareness of the importance of cybersecurity through training and information campaigns.

Fines may also be imposed if documentation or evidence requirements are not met.

Personal liability of management

In future, management will be personally liable for ensuring compliance with the NIS2 requirements. This is set out in section 38 of the government draft of the new BSIG. Management is therefore responsible for implementing and monitoring the measures that establish cybersecurity within the company. As a general rule, management is personally liable for losses resulting from failure to implement the risk-management measures required under section 30 of the draft BSIG. Correspondingly, section 38(3) of the draft BSIG also imposes a continuing professional development obligation on management.

The new Act expands cybersecurity compliance, including legal sanctions. Companies should therefore take the requirements of the NIS2 Directive and the new BSIG seriously. We will be glad to support you in implementing the NIS2 Directive. We provide comprehensive advice and practical assistance with implementing the required security measures, complying with reporting obligations and training your employees.

Contact us to find out how we can help you successfully meet the requirements of the NIS2 Directive and avoid sanctions

Get in touch now

Do you have questions about this topic?

We can assess what the development means for your organisation and advise you directly.

Contact us

Would you like to stay up to date with the latest developments?

Sign up for our newsletter

From EU directives and AI to the industrialisation of different service areas, the market is undergoing significant change, and so is Clarius.

Our newsletter provides regular updates on developments that may be relevant to you.

Form loading …

Your personal contact

Matthias Schulz

Matthias Schulz

Director Sales

Get in touch by email