Key takeaway: as of July 2026 no national competent authority has published a NIS2 fine decision that can be checked against a primary source. What is documented is the infringement track: the European Commission sent reasoned opinions to 19 member states on 7 May 2025, and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union. The obligations themselves are in force wherever national law is, and the ones a supervisor can check first are registration, a management-approved risk management framework, and a working incident notification process.
There is a lot of confident writing about NIS2 fines and very little of it survives a check against a regulator publication. Specific amounts attributed to national authorities circulate widely, and when you follow them back they end at another vendor blog rather than at a decision, a press release, or a supervisory register. So this update sticks to what can be verified: the state of transposition, the formal steps the Commission has taken, and the obligations that follow directly from the directive text.
That is a narrower story than "the first fines have landed", and it is a more useful one. The absence of published fines is not the absence of supervision. Supervisory correspondence, information requests, and administrative measures are generally not published anywhere, which means the first signal most entities get is a letter, not a headline.
What has the European Commission actually done?
The infringement track is the part of NIS2 enforcement that is fully documented, because the Commission publishes every step. Three dates matter.
The transposition deadline was 17 October 2024. On 7 May 2025 the Commission sent reasoned opinions to 19 member states for failing to notify full transposition: Bulgaria, Czechia, Denmark, Germany, Estonia, Ireland, Spain, France, Cyprus, Latvia, Luxembourg, Hungary, the Netherlands, Austria, Poland, Portugal, Slovenia, Finland and Sweden. That is the formal warning step, not a referral. The Commission published the list itself in its announcement of 7 May 2025.
On 8 July 2026 the Commission took the next step and referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to notify transposing measures, asking the Court to impose financial sanctions. That decision is published in European Commission press release IP/26/1499, 8 July 2026. Note who is on that list: these are large economies where a great many in-scope entities are established, and the sanction lands on the member state, not on them.
Country-by-country status changes often enough that it is worth checking at source rather than trusting a summary. The Commission maintains a NIS2 transposition page on the Shaping Europe's digital future portal.
Have any NIS2 fines been published?
Not that can be verified. Specific figures attributed to national authorities circulate on consultancy and vendor sites, sometimes with a named country, a month, and a sector. Followed back, they do not resolve to a regulator publication: no decision, no press release, no entry in a supervisory register. We are not going to repeat them here, and you should be sceptical of any advisor who does without a link.
Two things are true at the same time. There is no published fine, and supervision is real. Most supervisory activity under Articles 32 and 33 never becomes public: requests for information, on-site inspections, security audits, binding instructions, and orders to remedy are addressed to one entity and stay there. Only a formal fine decision would normally surface, and even then publication practice differs per member state. So treat the empty scoreboard as a reporting artefact, not a grace period.
What is visible is the machinery being built. Germany's BSI opened its registration and notification portal for the roughly 29,500 entities in scope of the German implementing law, described in its press release on the BSI portal. In the Netherlands, the NCSC states that the Cyberbeveiligingswet enters into force on 15 August 2026, with the duty of care, the notification duty and registration applying from that date.
Which member states have transposed NIS2?
NIS2 is a directive, which means every EU member state must transpose it into national law. The deadline was 17 October 2024. In July 2026 transposition is still uneven. Your country's status matters because fines and supervisory powers only become enforceable once the national law is in force.
National law in force
Obligations apply and the supervisory authority has its powers.
Includes member states that were never sent a reasoned opinion, plus those that transposed afterwards. Germany's implementing law is in force and the BSI portal for registration and notification is open.
Transposed late, supervision still forming
Law recently adopted or about to enter into force.
The Netherlands sits here: the Cyberbeveiligingswet enters into force on 15 August 2026 with no separate transition period, so obligations apply from day one.
Still incomplete
Transposition not notified. Referred to the Court of Justice on 8 July 2026.
Ireland, Spain, France and the Netherlands, per Commission press release IP/26/1499. Check current status on the Commission transposition page.
What this means in practice: Even if your home member state has not fully transposed, you are likely affected in three ways. Customer contracts may require compliance under another member state's law. Your group holding company may be subject in a country that has transposed. And harmonized Commission guidance applies across the single market regardless of local delay. Treat the directive as operative everywhere.
The Article 34 ceilings get a lot more concrete once your own numbers are in them. Turnover and entity class are all the fine exposure calculator needs, and it never asks for an email address.
What does a supervisor ask for first?
Without published decisions to reason from, the honest basis is the directive text plus what national authorities have set up so far, and it points the same way in every member state. Three obligations are checkable on paper, which is why they come first.
Priority 1: Documented governance and management approval
Can you produce a written, management-approved cybersecurity policy and risk assessment? Article 20 makes the management body responsible for approving the Article 21 measures and puts training on them personally, so approval is not a formality that can be reconstructed later. It is the fastest to check and the hardest to fake.
Priority 2: Incident notification compliance
Article 23 imposes a three-stage reporting regime: early warning within 24 hours, incident notification within 72 hours, and a final report within one month. A missed notification is a discrete, dated, provable breach that stands on its own, independently of how good your controls are. It is the cleanest thing for a supervisor to establish after the fact.
Priority 3: Registration and entity identification
Article 3(4) of the directive obliges member states to have in-scope entities submit their identifying details, and every national implementation carries that through. Failure to register is a binary finding: you are either in the register or you are not. It is the easiest deficiency to spot and one of the easiest to fix, so it is a poor one to be caught on.
5 working assumptions while enforcement is still quiet
Paperwork beats tooling in a first visit
A supervisor cannot meaningfully audit your SIEM configuration in an afternoon, but can establish in minutes whether a signed cybersecurity policy and a risk register exist. Spend proportionately. Governance documentation is cheaper than new tools and closes the gap a supervisor can actually reach on a first visit.
Management liability is in the text, whether or not it has been used
Article 20 puts approval and oversight of the risk management measures on the management body and requires its members to follow training. Article 32(5) lets supervisors temporarily bar an individual from management functions at an essential entity. No public case has tested this yet. That is a reason to have the sign-off records and training evidence on file, not a reason to assume the powers are decorative.
Mid-sized entities are not too small to be in scope
Scope follows the sector and the size threshold, not visibility. An entity that clears 50 staff or EUR 10 million turnover in an Annex I or Annex II sector is in scope on the same terms as a household name. There is no de minimis exemption for being obscure.
Incident notification is a separate enforcement vector
An entity can be fully compliant with Article 21 risk measures and still be fined for Article 23 notification failures. Treat incident reporting as a separate, specifically-resourced workstream with named roles, trained responders, and tested channels to your national authority.
Supply chain security is an explicit obligation, not a nice-to-have
Article 21(2)(d) names supply chain security, including the security of relationships with direct suppliers and service providers, as one of the ten minimum measures. Answering it means being able to show how you identify, assess, and contractually bind your critical suppliers. If your vendor list has more than a few dozen names, tiering and documenting is the slow part, so start it early.
What should you prepare next?
If you have not already started a structured NIS2 programme, the deadline passed in October 2024 and the runway is whatever your national law gives you. Here is a prioritized list of work for the next two quarters, ordered by what a supervisor can establish quickest.
Do first
- Confirm your entity classification (essential vs important) and register with the national authority if not already done.
- Produce or refresh a management-approved cybersecurity policy with an explicit reference to NIS2 Article 21.
- Document your Article 23 incident notification process with named roles, thresholds, and a tested channel to your national CSIRT.
- Conduct management training on cybersecurity risk and sign-off. Keep attendance records.
Do next
- Complete a supply chain risk assessment. Tier your critical vendors, map concentration risk, and add NIS2-aligned contractual clauses.
- Run a tabletop exercise simulating a significant incident with full Article 23 notification timeline.
- Perform an independent gap assessment against the 10 Article 21 measures. Prioritize top three residual risks.
- Prepare a pre-audit readiness pack: registration, policy, risk register, evidence log, incident records, training records, supplier list. One folder, ready to hand to a supervisor.
Frequently asked questions
Has any NIS2 fine been published yet?
As of July 2026 no national competent authority has published a NIS2 fine decision that can be verified against a primary source. Individual amounts circulating on vendor blogs do not trace back to any regulator publication. That is a statement about what is public, not about what is happening: supervisory correspondence and administrative measures are generally not published, so an empty scoreboard is not evidence of an absence of supervision.
Which countries have fully transposed NIS2 in 2026?
Transposition is still uneven. On 7 May 2025 the European Commission sent reasoned opinions to 19 member states for failing to notify full transposition. On 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice and asked for financial sanctions. The Commission's transposition page has the current country-by-country view.
Can my organization be fined if my country has not transposed NIS2 yet?
National administrative fines require a national transposition law in force. But your exposure is broader than that. If your group operates in a transposed member state, you are subject there. If your customers or contracts are governed by transposed laws, flow-down obligations apply. And once your country transposes, any historical significant incidents may be revisited by the supervisor.
What are the maximum fines under NIS2?
For essential entities, up to EUR 10 million or 2 percent of global annual turnover, whichever is higher. For important entities, up to EUR 7 million or 1.4 percent of global annual turnover. Beyond monetary penalties, supervisory authorities can suspend certifications, issue binding instructions, and in some member states temporarily ban individuals from management functions.
What does a supervisor ask for first?
The obligations that can be checked on paper: registration with the national authority under Article 3(4), a management-approved risk management framework under Article 21 with the management body accountability of Article 20, and a working incident notification process under Article 23. All three are governance and process obligations rather than technical ones, and all three come straight from the directive text.
Will there be NIS2 fines in 2026?
Fines are a matter of national law and national supervisory practice, so nobody outside the authorities can honestly predict the timing. What is certain is that the legal basis exists wherever transposition is complete, and that the powers in Articles 32 to 34 are available to supervisors from the moment national law is in force.
How do competent authorities pick which entities to inspect?
The directive sets the frame. Article 32 gives supervisors proactive powers over essential entities, including on-site inspections and security audits without a prior incident. Article 33 limits supervision of important entities to ex post action, meaning after evidence of an infringement, an incident notification, or a complaint. How each authority prioritises within that frame is set nationally.
Are you ready for an NIS2 audit?
We help essential and important entities prepare a defensible NIS2 evidence pack: policy, risk register, incident procedures, supplier map, training records. The things a supervisor asks for on the first visit.
Request a readiness reviewRelated articles
NIS2 penalties explained
How NIS2 fines are calculated and the personal liability for management.
NIS2 incident response playbook
The 24/72-hour reporting clock and how to manage a significant incident.
How to prepare for a NIS2 audit
What the supervisory powers behind enforcement look like when they arrive at your office.
NIS2 registration requirements
The register entry that decides which authority contacts you first.