In a nutshell: The NIS2 implementation deadline ends on July 31, 2024; non-compliant businesses face fines of up to 500,000 euros.
The implementation deadline for the NIS2 Directive expires on July 31, 2024. Around 11,000 German businesses must have converted their cybersecurity measures to the new EU standards by then, otherwise they face fines of up to 500,000 euros.
The National Cybersecurity Directive NIS2 (Network and Information Security Directive 2) sets new binding requirements for cybersecurity for operators of critical infrastructure and other organizations. With July 31, 2024, the implementation deadline for the transition to the new standards in Germany expires.
According to information from Börse Express, approximately 11,000 businesses in Germany are affected. For companies that are not fully compliant by the deadline, the directive provides for fines of up to 500,000 euros. In addition to financial sanctions, further regulatory consequences may follow.
CISOs and IT management should immediately check whether their company has implemented all required security measures. These typically include risk analyses, network segmentation, incident response processes, and regular security testing. Documented compliance evidence must be established before the deadline.
Source: news.google.com · Published July 18, 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrasing and classification through Lumi News Pipeline v1.7.3.