Skip to content

NIS2 implementation deadline ends July 31 – 11,000 companies face fines

On point: Companies in critical sectors must meet NIS2 requirements by July 31, otherwise face fines of up to €500,000 per company.

The implementation deadline for the NIS2 Directive in Germany ends on July 31, 2024. Approximately 11,000 companies face fines of up to €500,000 if they fail to meet the requirements.

The National Cybersecurity Strategy 2 (NIS2) establishes binding cybersecurity standards for critical infrastructures and other operators of essential services in the EU. By July 31, companies in the affected sectors – including energy, water and waste management, transport, banking, financial market infrastructures, healthcare, public administration and digital infrastructure – must have adapted their cybersecurity governance and technical controls to the new standards.

For CISOs and IT security officers, this concretely means: All required measures for network security, incident response processes, risk assessments and documentation of compliance activities must be demonstrated by the deadline. The Federal Network Agency and supervisory authorities of the states will conduct compliance reviews starting in August.

The threat of fines of up to €500,000 per company underscores the seriousness of the requirement. This affects not only large corporations, but also mid-sized companies classified as operators of essential services. Non-compliance can result in regulatory measures in addition to financial penalties.


Source: news.google.com · Published July 19, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: