On point: Approximately 11,000 German companies have not fully completed NIS2 compliance by the 31 July 2024 deadline and face fines.
The implementation deadline for the NIS2 Directive ends on 31 July 2024. According to current estimates, approximately 11,000 companies have not yet fully implemented the required measures and risk incurring fines.
The EU’s National Information and Cybersecurity Directive 2 (NIS2) prescribes binding cybersecurity standards for operators of critical infrastructure and other companies. The aim is to increase IT security in Europe. The deadline for implementation into German law was 31 July 2024.
According to information from ad-hoc-news.de, around 11,000 German companies are missing this deadline. This particularly affects medium-sized and larger enterprises from sectors such as energy, water, transport, health and digital infrastructure – sectors that fall under NIS2 regulations.
For CISOs, this presents significant compliance risks: companies that have not completed the implementation of measures such as incident response plans, security architecture, penetration testing or multi-factor authentication by the deadline must expect warnings, fines of up to several million euros or even criminal consequences. The exact amount of fines is determined by the national implementation of the directive.
Source: news.google.com · Published 20 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.