Skip to content

NIS2 Implementation: Two-Thirds of Operators Still Not Registered

In brief: Two-thirds of operators falling under NIS2 have not yet registered, indicating significant compliance gaps.

As of now, approximately two-thirds of affected operators have not yet registered in the context of NIS2 implementation. This points to substantial delays in meeting registration obligations, which represent one of the core requirements of the Directive.

The Network and Information Security Directive 2 (NIS2) requires operators of essential services and important digital infrastructure providers to register and comply with enhanced cybersecurity standards. According to estimates, so far only approximately one-third of affected companies have completed their registration.

This creates a twofold risk for compliance officers: first, non-registered companies face fines and supervisory sanctions. Second, many organisations apparently lack the necessary clarity about their classification as an essential entity or the correct interpretation of requirements. The registration deadline is a key milestone for compliance maturity.

Companies should promptly verify whether they fall under NIS2 and complete their registration. In parallel, a review of technical and organisational security measures is recommended to withstand future supervisory inspections. National authorities such as the BSI in Germany are intensifying their monitoring activities.


Source: news.google.com · Published 10 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: