The key point: With only 39% registration rate by the NIS2 deadline on July 31, non-compliant companies face significant fine and liability risks.
The registration deadline for the NIS2 Directive ends on July 31, but so far only 39 percent of affected companies have completed registration. This leaves the majority facing a compliance challenge in the final weeks.
The NIS2 Directive requires critical infrastructures and digital service providers to register with national authorities. The registration process is a prerequisite for meeting further compliance requirements such as risk management systems, incident reporting, and audit obligations.
With a registration rate of 39 percent, approximately 61 percent of affected organizations are behind schedule. For CISOs, this means massive organizational pressure: alongside registration, security mechanisms themselves (network resilience, identity management, cryptography, multi-factor authentication) must be established by the deadline.
Companies that miss the deadline risk substantial fines – in the EU up to 10 million euros or 2 percent of global turnover – as well as reputational damage and regulatory sanctions. Additionally, the liability position worsens: in the event of a breach, missed compliance measures can be construed as negligence.
CISOs should immediately conduct an inventory to clarify whether their organization falls under NIS2, review registration documentation, and prioritize outstanding technical measures.
Source: news.google.com · Published July 13, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrasing and classification via Lumi News Pipeline v1.7.3.