Introduction
For most of 2025 and early 2026, NIS2 enforcement was theoretical - a directive with large penalty ceilings and no track record. That changed this summer. Confirmed fines have now landed in at least four member states, formal supervisory orders number in the dozens across Germany and France alone, and on July 8, 2026 the European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU for failing to fully transpose the directive into national law. NIS2 is no longer a compliance deadline on a slide. It is an active enforcement regime.
The Fines So Far
- Belgium: approximately €185,000
- Italy: approximately €450,000
- Hungary: approximately €78,000
- Lithuania: approximately €52,000
Supervisory activity is outpacing fines
Fines are a lagging indicator. The more immediate signal is the volume of formal supervisory orders already issued: roughly 47 by Germany's BSI and 23 by France's ANSSI, operating under its existing 2018 framework while formal NIS2 transposition remains pending domestically. Audit programmes are now active in at least 14 member states, targeting essential entities first. An organization that has not yet been fined should not read that as evidence it is compliant - only that its supervisor hasn't reached it yet.
Why Four Member States Are Facing the Court
NIS2 required national transposition by October 2024. By May 2026, roughly 21 to 23 of 27 member states had done so, leaving a persistent minority - including some of the EU's largest economies - operating under partial or incomplete national frameworks. The Commission's referral of Ireland, Spain, France, and the Netherlands to the CJEU is a formal escalation, not a symbolic gesture: it starts a legal process that can ultimately result in financial penalties against the member state itself, layered on top of - not instead of - the obligations already falling on regulated entities operating there.
What this means for compliance evidence, practically
The organizations avoiding fines so far are not the ones with the best policies on paper - fines have landed on essential and important entities that, on investigation, could not produce continuous evidence of the controls their policy documents described. A supervisory audit does not ask whether a security policy exists; it asks whether the organization can demonstrate, with timestamped evidence, that the policy was followed on the dates that matter. That distinction is exactly where machine-verifiable, continuously generated compliance evidence outperforms a point-in-time audit binder.
As NIS2 enforcement moves from theoretical to active, the gap between a compliance policy and compliance evidence is where fines are landing. See how ROOTKey generates continuous, audit-ready NIS2 evidence.
Recebe insights de ciber-resiliência no teu email
Orientação prática e pronta para auditoria sobre integridade de dados, conformidade e continuidade - à medida que publicamos.





