In a nutshell: The NIS2 Directive will require approximately 29,500 German companies to meet enhanced cybersecurity standards with stricter requirements for governance, risk management, and incident reporting beginning in October 2026.
The NIS2 Directive will oblige around 29,500 German companies starting in 2026 to comply with tightened cybersecurity standards. CISOs must significantly intensify their governance, risk management, and incident response processes.
The European NIS2 Directive (Network and Information Security) significantly expands the scope of regulated entities. Under the previous NIS1 Directive, approximately 1,000 companies in Germany were obligated to comply; under NIS2, this will increase to around 29,500. The directive applies to operators of essential entities (energy, transport, water, health, digital infrastructure) as well as important digital and other service providers.
The new requirements enter into force on 17 October 2024, with compliance required by October 2026. The focus is on enhanced technical and organisational security measures: risk management, incident reporting, cybersecurity governance, supply chain security, minimum standards for cryptography and authentication, and business continuity and disaster recovery capabilities. In addition, affected companies must report cybersecurity incidents to the competent authority.
For CISOs, this means an expansion of responsibility across a significantly larger corporate landscape. In particular, medium-sized enterprises and smaller critical infrastructure operators must systematically establish their governance and technical defence measures. Implementation requires strategic planning, resource allocation, and regular communication with management and authorities.
Source: news.google.com · Published 26 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.