The point: NIS2 implementation obliges enterprises outside critical infrastructure to adopt strengthened cybersecurity measures from 2026 onwards and threatens substantial fines for non-compliance.
With the EU Directive NIS2, new cybersecurity requirements come into force from 2026 that also affect mid-sized enterprises. The fine regime will be significantly tightened.
The NIS2 Directive (Network and Information Security Directive 2) obliges EU member states to adapt their national laws by October 2024. From October 2026, the new requirements will apply. Unlike the old NIS1 Directive, NIS2 covers not only operators of critical infrastructure such as energy suppliers or hospitals, but also a broader group of medium-sized enterprises in sectors such as manufacturing, automotive and digital services.
The NIS2 fine regime is substantially stricter than under NIS1. Violations of cybersecurity obligations can be punished with fines of up to 10 million euros or 2 percent of global annual turnover—whichever is higher. Particularly serious violations of notification requirements in the event of security incidents are sanctioned with up to 20 million euros or 4 percent of annual turnover. For mid-sized enterprises that often have limited IT resources, this represents a considerable risk.
CISOs should already now review their own compliance status: Does the enterprise have an information security management system (ISMS)? Are incident response processes documented and regularly tested? What risk mitigation measures are implemented? Implementation should not begin only in 2026, but should be completed by 2025 to allow sufficient time for testing and validation.
Source: news.google.com · Published 16 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.