The Point: 11,000 German companies face NIS2 fines up to €500,000 due to missed registration.
In Germany, approximately 11,000 companies have missed the NIS2 Directive registration deadline. They face fines of up to €500,000.
The National Authority for Cybersecurity and Crisis Response (NCAZ) and the responsible regulators in the federal states have identified that around 11,000 operators of critical infrastructure and large enterprises did not register with the required authorities after the deadline expired.
The NIS2 Directive requires certain organisations to report their cyber protection measures and to register with the authorities. The deadline for meeting this obligation has elapsed; fines of up to €500,000 are now the enforcement instrument for non-compliance.
For CISOs, this means: affected companies must immediately verify whether their organisation falls under the NIS2 reporting obligation, and – if not already done – immediately initiate registration. A retroactive registration can reduce the amount of the fine. In parallel, cybersecurity governance and incident reporting processes should be adapted to NIS2 requirements.
Source: news.google.com · Published 20 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.