The gist: The implementation deadline for the NIS2 Directive expires on July 31 – companies that have not implemented their required cybersecurity measures face substantial fines.
The implementation deadline for the European NIS2 Directive on network and information security runs out on July 31. Approximately 11,000 companies in Germany risk significant fines if they have not implemented the required measures by then.
The NIS2 Directive (Network and Information Security Directive 2) imposes binding minimum cybersecurity standards on European companies. Organizations in critical sectors such as energy, water, transport, health, as well as finance and digital infrastructure are affected. The deadline for implementation into national law expired on October 17, 2024 for EU member states; companies themselves must have demonstrated compliance by July 31, 2025.
An estimated 11,000 German companies fall within the scope of NIS2 regulation. Not a few organizations are still in the implementation phase of their security measures. The regulatory requirements include, among other things, risk management, incident response processes, emergency planning and regular security assessments – measures that require time and specialized resources.
Companies that fail to meet the deadline face administrative fines. The amount varies depending on the member state and type of violation, but can be substantial. For CISOs, this means: a detailed gap analysis should be conducted immediately to determine which NIS2 requirements have not yet been met. Prioritization of critical control implementation and demonstration of compliance to the relevant authorities are now central.
Source: news.google.com · Published July 21, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.