Skip to content

NIS2 Implementation Deadline Ends on 31 July: Fines Up to €500,000 Threatened

The gist: Approximately 11,000 German companies must implement the NIS2 Directive by 31 July 2024 or risk fines up to €500,000.

On 31 July 2024, the deadline for implementing the NIS2 Directive expires. Approximately 11,000 German companies risk fines of up to €500,000 if they fail to comply.

The NIS2 Directive (Network and Information Security Directive 2) requires operators of critical infrastructures and companies as providers of digital infrastructure services to comply with specific cybersecurity standards. The German Federal Government has implemented the Directive into national law through the IT Security Act 2.0. The binding implementation deadline for affected companies is 31 July 2024.

For compliance officers, this means concretely: All required technical and organisational measures to protect IT systems and networks must be implemented and documented by this deadline. This includes security measures such as network segmentation, access controls, encryption and regular security assessments. Companies must also fulfil reporting obligations and report incidents to the Federal Office for Information Security (BSI).

Companies that do not meet the requirements by 31 July must expect significant sanctions. Fines can amount to up to €500,000. In addition, there is potential reputational damage and operational risks due to inadequate security measures. Particularly for larger organisations with complex IT infrastructures, a structured implementation is required. Compliance teams should conduct an inventory, identify gaps and implement remaining measures in a prioritised manner.


Source: news.google.com · Published 20 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: