- 17 October 2024 — the transposition deadline set by Directive (EU) 2022/2555. Several member states, Germany included, missed it.
- 6 December 2025 — Germany's NIS2UmsuCG entered into force, amending the BSI Act. No transition period.
- 6 January 2026 — the BSI registration portal opened; in-scope German entities were required to register by 6 March 2026.
- Germany's regulated population expanded from roughly 4,500 KRITIS operators to about 29,500 entities.
- Still unchanged: no NIS2 fine has been published by a competent authority in a form that can be verified against an official source.
Transposition and enforcement status differ by member state and move continually. Check your own competent authority rather than relying on any summary, including this one.
About Those Fine Figures You Have Seen
A set of specific NIS2 penalties has been circulating widely in vendor briefings and compliance newsletters — a large German fine against a cloud provider, smaller figures attributed to Italy, Belgium, Hungary and Lithuania. They are repeated with confidence and precise amounts.
We went looking for the underlying decisions and could not find them. Neither, more importantly, can the people who track this most rigorously: the position of the most careful public trackers is that no NIS2 fine has been published by a competent authority that can be verified against an official source.
That does not prove no penalty exists. Administrative enforcement is not always published, and national practice varies. What it does mean is that anyone citing a specific NIS2 fine should be able to name the decision — the authority, the date, the register entry. If they cannot, the number is not evidence of anything.
We are pointing this out because the argument for taking NIS2 seriously does not need invented numbers, and because a compliance case built on a figure that evaporates under scrutiny is worse than no case at all. The real position is quite strong enough.
What the Statute Actually Says
These figures come from the Directive and its national implementations, not from reporting:
- Essential entities — administrative fines with a maximum of at least €10,000,000 or 2% of total worldwide annual turnover, whichever is higher
- Important entities — a maximum of at least €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher
- Qualifying maritime transport operators are listed in Annex I, which places them in the essential entity tier and therefore under proactive supervision — a competent authority does not have to wait for an incident before examining you
Note the construction: the Directive sets a floor on the maximum member states must provide for. It is a ceiling requirement, not a minimum penalty. Anyone telling you the minimum NIS2 fine is €10 million has misread it.
Registration Is the Obligation Being Enforced First
The German timeline is instructive because it is documented and dated. The NIS2UmsuCG entered into force on 6 December 2025 with no transition period. The BSI opened its registration portal on 6 January 2026, and in-scope entities were required to register by 6 March 2026.
Registration is a binary, checkable obligation. An authority does not need to form a view about the quality of your security to establish whether you registered by a published date. That makes it the natural first enforcement surface, and it is where an operator who has been treating NIS2 as a future problem is most immediately exposed.
The scale of the German expansion — from around 4,500 KRITIS operators to roughly 29,500 entities — also explains why many organisations do not realise they are in scope. A great many were brought in by the widening, not by anything they did.
Why Maritime Operators Keep Underestimating This
The pattern is consistent, and it is not carelessness. Operators have concentrated cyber effort on IMO and USCG requirements, which feel closer to vessel operations, while treating NIS2 as a corporate IT matter for the shore office. Three things make that a poor bet.
Scope follows operations, not flag. NIS2 applies by where you operate. An operator headquartered outside the EU running non-EU-flagged vessels can still fall within scope by providing services into the EU maritime transport chain.
Supply chain security is an explicit Article 21 obligation. Most maritime operators have never formally assessed the cyber posture of equipment manufacturers, class societies or port service providers. Building that framework, running the evaluations and getting security terms into contracts is months of work.
Accountability attaches to the management body. NIS2 requires management bodies to approve and oversee risk management measures, and member states may introduce accountability measures for the individuals concerned. Delegating the work is normal; delegating the obligation is not available.
What Demonstrating Compliance Requires
Article 21 sets out the risk management measures. Article 23 sets the reporting clock: an early warning within 24 hours of becoming aware of a significant incident, a detailed notification within 72 hours, and a final report within one month.
Demonstrating that across a fleet means being able to produce, on request:
- Registration with the relevant competent authority, within the published window
- Evidence that detection exists and is monitored — not merely that security products were purchased
- A timestamped incident record showing when an event was identified, classified and escalated
- Notifications generated against the right framework, with the right fields, inside the right window
- Risk analysis, business continuity, supply chain assessment, training records, cryptography and access control evidence, maintained rather than written once
- Records showing management body review, because that is a named obligation rather than good practice
NCoDE Command is built around this problem: incident workflows that timestamp every step, reporting panels that generate NIS2, USCG and IMO notifications from a single incident, audit logging that produces the trail rather than requiring someone to reconstruct it, and a risk register, document vault and training matrix holding the supporting evidence in one place. It does not make you compliant — nothing does that except doing the work — but it means the evidence exists when a competent authority asks.
The exposure that matters is not a headline fine. It is being unable to show what you did, and when.