Skip to content

NIS2 and KRITIS: Fines up to 10 Million Euro Threaten

To the point: NIS2 imposes mandatory security standards for KRITIS operators, with non-compliance subject to fines up to 10 million euros.

The NIS2 Directive obligates companies in critical infrastructures to meet enhanced cybersecurity standards. Violations of these requirements can result in penalties of up to 10 million euros.

The EU’s Network and Information Security Directive 2 (NIS2) requires operators of critical infrastructures (KRITIS) to implement comprehensive cybersecurity measures. They must systematically identify and assess risks in their information systems and implement countermeasures – from technical controls to organisational requirements such as incident response plans.

For CISOs and security officers, NIS2 implementation presents a compliance challenge: insufficient or missing security controls not only jeopardise the operational continuity of critical services but also trigger regulatory investigations. In particular, during security incidents, supervisory authorities verify compliance with NIS2 requirements.

The maximum fine of 10 million euros or – if higher – two percent of global annual turnover underscores regulatory enforcement. In addition, operational bans and reputational damage threaten. Companies should document their NIS2 compliance through regular audits, risk assessments and control tests and be able to demonstrate this to authorities upon request.


Source: news.google.com · Published 1 August 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: