For two years, NIS2 was a planning problem. Legal teams reviewed the directive. Compliance teams built frameworks. Security teams mapped controls against Article 21. The assumption across most organizations was that enforcement was coming, but not yet.
That changed in Q1 2026. The first NIS2 enforcement actions and administrative penalties are emerging across Europe. Enforcement authorities in several member states are operational, resourced, and active. The conversation has shifted from what NIS2 requirements are to what enforcement looks like in practice and whether your organization is prepared for it in the specific countries where you operate.
This post covers which member states are enforcing NIS2 right now, what triggered the first fines, what enforcement authorities can do beyond financial penalties, and what that means for security and compliance teams operating across multiple EU jurisdictions.
What you'll learn:
Need a clear picture of NIS2 enforcement in your country?
The NIS2 Enforcement Readiness Tracker maps transposition status, enforcement authority, public enforcement activity, and practical risk ratings for eight EU member states.
Download the trackerNot every member state is at the same stage. Enforcement maturity varies significantly across the EU, and where your organization operates determines what enforcement pressure looks like in practice.
As of Q2 2026, four member states have moved into active enforcement with public supervisory and enforcement activity.
Germany. BSI (Bundesamt für Sicherheit in der Informationstechnik) entered NIS2 supervision with an established track record from NIS1. It has significant resourcing, a clear mandate, and has already issued administrative fines and enforcement notices. Germany is the highest-activity enforcement jurisdiction in this tracker.
Netherlands. The Dutch supervisory model splits oversight between NCSC-NL for national coordination and RDI (Rijksinspectie Digitale Infrastructuur) for sectoral supervision. Supervisory activity is well established. The Netherlands has a strong tradition of active digital regulation, and organizations should expect proactive supervisory contact.
France. ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information) has established active supervisory practices under the expanded NIS2 framework. Its mandate has expanded beyond critical national infrastructure under NIS2, meaning a broader set of organizations are now in scope for supervisory attention.
Belgium. CCB (Centre for Cybersecurity Belgium) was among the earlier member states to move to active enforcement. It is one of the more active and well-resourced national authorities in the EU. Organizations with Belgian operations should treat NIS2 enforcement as a live operational risk.
Three member states are in early enforcement, with supervisory activity underway but limited formal fine decisions as of Q2 2026.
Poland. Poland's KSC amendments implement NIS2. UODO's active GDPR enforcement history gives some indication of posture. Poland has one of the largest NIS2-affected populations in the EU. Enforcement capacity is building, and organizations should treat this as an active enforcement environment within 12 to 18 months.
Sweden. NCSC-SE coordinates nationally, with IMY involved where GDPR overlap exists. Supervisory activity is underway. Organizations in regulated sectors should confirm which authority has primary responsibility for their sector.
Czech Republic. NUKIB has initiated supervisory activity and signaled active enforcement intent. Organizations in critical infrastructure, digital infrastructure, and public administration should expect early supervisory contact.
Spain remains the exception. Transposition is still incomplete as of Q2 2026 and no formal NIS2 fines have been confirmed. That is a short-term factor, not a reason to deprioritize readiness.
Early enforcement actions across member states have focused on a consistent set of failures. The pattern is worth understanding because it tells you where enforcement authorities are looking first.
The pattern across early enforcement actions is consistent enough to be useful. Three triggers have surfaced repeatedly across member states, and in each case the failure was not a security failure. It was a documentation and process failure.
| Enforcement trigger | What authorities looked for | What was commonly missing |
|---|---|---|
| Incident notification failure | Evidence that the organization identified, classified, and reported the incident within Article 23 timelines | Documented notification sent within 24 hours. Final report produced within one month. |
| Absent risk management documentation | Written records showing Article 21 measures were implemented and actively maintained | Security measures existed in practice but were never documented in a reviewable format |
| Governance failures | Board-level awareness, accountability, and oversight of cybersecurity risk | Security entirely delegated below board level with no documented governance trail |
The pattern across all three areas is the same. Detection capability was not the issue. Documentation, notification, and demonstrable governance were.
Financial penalties are the most visible enforcement tool but not the only one. NIS2 gives national authorities a broader set of powers, and several member states have implemented them in full.
Binding instructions. Authorities can require organizations to take specific remediation actions within defined timeframes. Non-compliance with a binding instruction is itself an enforcement issue.
Public disclosure. Non-compliance can be made public. For organizations in regulated industries or publicly listed companies, reputational exposure from a public enforcement decision is a material risk that sits alongside the financial penalty.
Management liability. Some member states have introduced provisions allowing temporary prohibition of management functions for senior executives where serious or repeated failures are found. This is the provision that tends to get board attention most quickly.
On-site inspections. Authorities have the power to conduct on-site inspections without prior notice in several jurisdictions. Germany's BSI and Belgium's CCB both have established inspection frameworks from their NIS1 supervisory activity.
The three Article 23 notification stages each require a different action within a different window. If your team does not yet have a documented process for meeting these timelines, the NIS2 Incident Response Plan Template includes pre-written notification drafts and a decision log built around the 24h, 72h, and 1-month reporting windows.
If you operate across multiple EU member states, you are dealing with multiple enforcement environments simultaneously. The NIS2 directive is the same. The national implementations are not. The enforcement authorities have different mandates, different resourcing, and different supervisory histories.
The risk is not uniform, and neither is the preparation. An organization operating in Germany and Spain faces active enforcement in one jurisdiction and a pending enforcement environment in the other. The immediate priorities are different in each case.
For active enforcement jurisdictions, the question is whether your incident notification process meets Article 23 timelines right now and whether your security documentation would support an audit review if requested tomorrow.
For early enforcement jurisdictions, the window to get ahead of supervisory contact is open but narrowing. The preparation is the same as for active jurisdictions. The timeline is more forgiving, for now.
For pending jurisdictions, the practical factor is real but temporary. Transposition is progressing. Build readiness now rather than waiting for the national law to finalize.
Not sure whether your organization qualifies as an essential or important entity? The NIS2 Compliance Self-Assessment Toolkit runs a 40-question diagnostic across all NIS2 requirements in under 20 minutes.
Understand your enforcement exposure across every market you operate in
The NIS2 Enforcement Readiness Tracker maps transposition status, enforcement authority, public enforcement activity, and practical risk ratings for eight EU member states. The multi-market worksheet inside helps you assess your exposure jurisdiction by jurisdiction.
Download the trackerNIS2 enforcement is active. Early enforcement activity has begun across several member states, and the patterns are becoming clear. Documentation, notification readiness, and demonstrable governance have been the issues, not detection capability. If you operate across multiple EU member states, the enforcement environment you face is different in each one, and the priorities should reflect that.
Sources and further reading:
Need to understand your enforcement exposure across markets?
Q-Sec works with security and compliance teams operating across the EU. We can review your multi-market risk profile, identify the gaps most likely to attract supervisory attention, and help you build a prioritized readiness plan.
Talk to a Q-Sec expertAs of Q2 2026, Germany, the Netherlands, France, and Belgium have the most mature supervisory and enforcement activity. Poland, Sweden, and the Czech Republic are in early enforcement, while Spain is still completing transposition.
Germany, Netherlands, France, and Belgium have all confirmed NIS2 enforcement actions. Early actions focused on incident notification failures and absent risk management documentation across all four jurisdictions.
The three most common triggers across early enforcement actions are late or missing incident notifications under Article 23, undocumented risk management measures under Article 21, and inability to demonstrate board-level governance obligations were met.
NIS2 Article 34 sets the maximum at €10 million or 2% of global annual turnover for essential entities and €7 million or 1.4% for important entities. National transposition laws may set different structures within those limits.
Yes. The NIS2 directive applies to any organization providing services within the EU regardless of where it is headquartered. If you are in scope in any member state, the national enforcement provisions of that jurisdiction apply to you.
The lead authority is generally in the member state where your main establishment is located. For organizations operating across multiple member states, sector-specific authorities may also have supervisory responsibility. The country profiles in the NIS2 Enforcement Readiness Tracker identify the relevant authority for each of the eight member states covered.