Skip to content
RGPD

Article 36

Penalties

Member States shall lay down rules on penalties applicable to infringements of national measures adopted pursuant to this Directive and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive. Member States shall, by 17 January 2025, notify the Commission of those rules and of those measures and shall notify it, without delay of any subsequent amendment affecting them.
Common Questions

Frequently Asked Questions

What penalties are required under the NIS2 directive?
Under the NIS2 directive, European Union member countries must establish clear rules for penalties to deal with violations of cybersecurity regulations, ensuring these penalties are strong enough to discourage future breaches, but still fair and proportionate to the severity and impact of the offence; they must then inform the European Commission of these rules.
By when must member states inform the Commission about their penalty rules?
Member states have until January 17, 2025, to inform the European Commission about the specific penalty rules they have put in place related to the NIS2 directive, and they must also let the Commission know immediately if they later change these rules to ensure transparency and compliance.
Why do penalties under the NIS2 directive need to be 'effective, proportionate and dissuasive'?
Penalties under NIS2 have to be effective, proportionate, and dissuasive so they are strong enough to prevent parties from violating cybersecurity standards, while still being fair by matching the severity and impact of the offense, thus supporting strong protection standards and consistent cybersecurity practices across all EU members.
Who decides the specific penalties for violations under the NIS2 rules?
Each EU member state decides independently on the exact penalties they will apply when organizations or individuals violate rules implemented because of the NIS2 directive; however, these penalties must meet certain EU requirements of being strong enough, fair, and effective in deterring further cybersecurity breaches.