The Bottom Line: 11,000 German enterprises have failed to meet the NIS2 registration deadline by July 31 and risk fines and compliance violations.
The registration deadline for the EU NIS2 Directive expires on July 31. Around 11,000 enterprises in Germany have not yet registered, although they are classified as critical infrastructure operators and are therefore required to register.
According to available data, approximately 11,000 companies still lack the required registration under the Directive on measures for a high common level of cybersecurity across the Union (NIS2). The registration obligation applies to enterprises that operate critical infrastructure or provide important digital services and therefore fall within the scope of NIS2.
For CISOs, failure to register has significant legal and operational consequences. Once the deadline passes, missing registrations become compliance violations that can result in fines. At the same time, the deadline for implementing the technical and organizational measures required by NIS2 is extended.
Enterprises should immediately verify whether a registration obligation applies to them. Identification is based on sector-specific thresholds and classifications. Registrations must be submitted through the competent German authorities, such as the Bundesnetzagentur or the Federal Office for Information Security (BSI), depending on the sector and area of activity.
Source: news.google.com · Published July 15, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.