In brief: 30,000 EU companies must register with national authorities by 31 July 2026 under the NIS2 Directive and harmonise their cybersecurity across the EU.
The NIS2 Directive obliges approximately 30,000 companies in the EU and EEA to register with their competent authorities by 31 July 2026. This affects critical infrastructure and operators of essential services.
On the basis of the NIS2 Directive (Directive (EU) 2022/2555), companies in certain sectors must align their cybersecurity measures with harmonised EU standards. The registration deadline for the approximately 30,000 affected operators ends on 31 July 2026.
The requirement applies to companies classified as operators of essential services or critical infrastructure – for instance in the fields of energy, transport, water, health, digital infrastructure and public administration. Certain digital service providers must also register.
CISOs must in this phase register their organisation, document IT assets, analyse risks and implement or validate security measures in accordance with the state of the art. Registration is the first formal step towards compliance; this is followed by ongoing notification obligations in the event of security incidents and regular audits by national authorities.
Source: news.google.com · Published 26 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.