NIS2 fines and director liability in Luxembourg

The fines are large; the part that surprises boards is that responsibility lands on them personally — and cannot be fully delegated to an IT provider.

The short version: the fines are large — up to €10 million or 2% of worldwide turnover — but the part most owner-managers miss is sharper: under the Law of 5 May 2026, the management body is personally on the hook. This is not a liability you can fully hand to your IT provider.

The fines

 Essential entityImportant entity
Maximum administrative fine€10 million or 2% of total worldwide annual turnover, whichever is higher€7 million or 1.4% of total worldwide annual turnover, whichever is higher
How you are supervisedProactively — the ILR can inspect and request evidence at any timeReactively — after an incident or a complaint

These are ceilings, not tariffs. A first, honestly-disclosed shortfall with a credible remediation plan is a very different conversation from being found non-compliant after an incident. But the ceilings tell you how seriously the law is meant to be taken.

The part that surprises directors: personal responsibility

Article 20 of the NIS2 Directive, transposed by the Luxembourg law, places specific duties on the management body — the board, the directors, the gérants:

  1. They must approve the cybersecurity risk-management measures.
  2. They must oversee their implementation.
  3. They must follow training themselves, so they can identify risks and judge the measures — and are encouraged to offer similar training to staff.

The consequence is the point: because the law names the management body, responsibility cannot be fully delegated. "Our IT provider handles security" does not discharge a director's duty to approve, oversee and understand it. A board that signed off measures it never examined has not met Article 20, however good the underlying setup.

For essential entities, the sanctions can reach the individual. Where an essential entity fails to remedy a breach within a set deadline, the competent authority can, among other measures, request a temporary prohibition on a person exercising management functions at chief-executive or legal-representative level. It is not automatic and it is a last resort — but it exists, and it is aimed at people, not just the company.

The corrective measures short of a fine

Fines are the visible end of the range. Before that, the ILR can issue binding instructions and warnings, order you to bring specific measures into compliance by a deadline, require you to inform affected clients, and — for essential entities — suspend an authorisation or certification. For a business that depends on client trust, a public compliance order can cost more than the fine.

What this means in practice

Three things follow for a management body that wants to sleep at night:

  1. Get trained, briefly. Directors do not need to become engineers. They need enough to approve the measures knowingly and to ask the right questions. The law expects it, and a recorded video is a weak answer to a regulator.
  2. Approve on the basis of evidence, not assurances. Sign off on measures you can see are real — tested, documented — rather than a folder you were told is complete.
  3. Keep the paper trail. The board decision approving the measures, the training record, the risk acceptance — these are what show, later, that the duty was met.

How we help

Our Compliance Audit produces exactly the file a management body needs to discharge Article 20: a risk assessment and security policy your board can approve, an action plan it can own, and a board session that includes the training directors are now required to have — delivered by people who test systems for a living, not read from a slide. What we do not do is accept the risk on your behalf: the law puts that on the management body, and it stays there.

Unsure whether the law even applies to you? That is a separate, quicker question, and we answer it in writing first.