The BSIG provides for substantial fines for NIS2 violations — tiered by entity category and severity of the violation. We explain the figures, the procedure, and how to effectively avoid fines.
The fine regime under § 65 BSIG tiers sanctions by entity category and severity of the violation. The higher of the two amounts always applies — the percentage of turnover or the absolute maximum amount.
Note: Fines can also be imposed even if no security incident has occurred — based solely on inadequate compliance evidence. The BSI can carry out proactive reviews at any time.
No or inadequate implementation of the risk management measures under § 30 BSIG.
Late, incomplete or missing notification of significant security incidents to the BSI.
Executive management has not fulfilled or cannot demonstrate the training obligation under § 38 BSIG.
The affected entity has not registered with the BSI.
We help you fulfil all NIS2 obligations completely and build the documentation that protects you in the event of a BSI review.
Request Consultation Now