Article 34 of the NIS2 Directive (EU 2022/2555) provides for administrative fines for certain breaches of cybersecurity obligations. For essential entities, Member States must provide for a maximum fine of at least 10 million euros or 2% of total annual global turnover in the preceding financial year, whichever is higher when setting that ceiling. This is not a minimum fine automatically imposed on every non-compliant entity.
For important entities, national law must provide for a maximum fine of at least 7 million euros or 1.4% of total annual global turnover in the preceding financial year, whichever is higher. The actual fine depends on factors including the severity and duration of the breach and the circumstances of the case, under applicable national rules. The directive sets requirements for fine ceilings, rather than a minimum for each penalty. Source: NIS2 Directive, Article 34.
A simple configuration error can now directly impact your net income. Compliance is no longer a technical issue relegated to the basement. It is becoming a major financial risk that your finance department must integrate into its forecasts. A major data breach now costs an average of $4.88 million even before fines are applied, according to IBM’s Cost of a Data Breach report.
Your personal liability is now involved
NIS2 marks a historic breakthrough in cybersecurity law. Article 32(6) of the directive introduces the personal liability of executives. It is no longer just the legal entity that is targeted. Your civil and professional liability is directly exposed in cases of proven negligence.
Supervisory authorities have unprecedented coercive powers. They can order a temporary suspension of your management duties. This ban on practicing affects members of management bodies at the individual level. The sanction decision is also published by name. The impact on your professional reputation is immediate and often irreversible.
The executive must now approve cyber risk management measures. They must also rigorously supervise their implementation. Ignoring the real state of your attack surface constitutes a management fault. In 2026, passivity in the face of digital risk becomes a legal ground for dismissal.
Cybersecurity Threat Report
Download our Cybersecurity Threat Report and outlook for 2026.
A comprehensive analysis of the evolution of threats by sector and by country.
Learn how to protect your assets from the latest threats and be compliant with the latest regulations.
Ignorance of your attack surface is no longer an excuse
Article 21 of NIS2 imposes ten categories of minimum security measures. Among them, asset management and supply chain security are priorities. You cannot protect what you cannot see. Yet a large share of companies that fall victim to a significant attack had unknown exposed assets.
ANSSI considers ignorance of one’s perimeter as gross negligence. An audit revealing shadow servers or open administration interfaces is enough to trigger sanctions. Asset documentation must be exhaustive and kept up-to-date in real time. A six-month-old Excel list has no legal value during an inspection.
Proof of diligence is your only protection. You must demonstrate that you have implemented the necessary means to identify your vulnerabilities. The lack of visibility over your subsidiaries or third-party partners worsens your case. The directive requires continuous monitoring rather than occasional audits.
The attack surface explodes under the effect of AI
The digital perimeter of companies is constantly expanding. Billions of records are exposed every year through data breaches. Attackers now use artificial intelligence to scan and exploit flaws in minutes. Your defense must adopt the same speed.
The massive deployment of cloud and remote work has fragmented your infrastructure. Every new SaaS service or partner API creates a potential entry point. Manual discovery methods have become obsolete. They can no longer keep up with the pace of daily changes in your digital ecosystem.
Generative AI facilitates the creation of ultra-realistic phishing sites targeting your employees. It also enables the discovery of complex vulnerabilities in your web applications. Faced with this automated threat, intermittent human monitoring is doomed to fail. Detection must be permanent to be effective.
AI EASM becomes your compliance shield
External Attack Surface Management (EASM) powered by AI changes the equation. It automates the discovery of your assets across the internet. Unlike traditional scanners, it identifies indirect links and forgotten assets. This technology sharply reduces the time it takes to discover critical assets compared to traditional methods.
The Autodit.io platform uses advanced algorithms to map your digital footprint. It prioritizes risks based on their actual exploitability and their impact on your NIS2 compliance. You get a clear view of what an attacker sees, before they can act. That is the difference between suffering an incident and managing a risk.
Automation makes it possible to generate compliance reports that are legally binding for authorities. You have a time-stamped history of your remediation actions. In the event of an audit, you prove your active diligence. AI eliminates the false positives that overwhelm your technical teams. It allows them to focus on the vulnerabilities that practically threaten your business.
Comparison of monitoring approaches
| Criterion | Manual / Occasional Audit | Automated AI EASM |
|---|---|---|
| Frequency | Quarterly or annual | Continuous (24/7) |
| Visibility | Known perimeter only | Discovery of unknown assets |
| Responsiveness | Delay of several weeks | Real-time alerts |
| NIS2 Proof | Fragile static document | Complete dynamic history |
| HR Cost | Very high (expert time) | Low (automation) |
| Accuracy | Risk of human error | Massive data analysis |
FAQ
What are the first steps to comply with NIS2?
First, identify whether you are an essential or important entity. Then map your entire external attack surface. Finally, document your risk management measures for each identified asset.
Is a simple vulnerability scan enough for NIS2?
No. NIS2 requires comprehensive risk management and continuous monitoring. A one-off scan does not cover the discovery of unknown assets or the security of your supply chain.
How does AI reduce the risk of personal sanctions?
AI provides proof of proactive and comprehensive monitoring. It demonstrates that the executive has implemented modern technological means to protect the entity. This strongly reduces the qualification of negligence during an audit.