Skip to content

NIS2 Implementation Deadline Passed: Fines Up to €10 Million Possible

Bottom line: Following the expiration of the NIS2 implementation deadline, fines of up to €10 million threaten non-compliant companies.

The deadline for implementing the NIS2 Directive has passed. Companies that have not met their cybersecurity requirements face the risk of substantial penalties.

The implementation deadline for the NIS2 Directive (Network and Information Security Directive 2) has expired. EU member states were obligated to transpose the Directive into national law by October 2024 at the latest. Companies and operators of critical infrastructure must have adapted their cybersecurity measures accordingly.

Organizations that have not fulfilled their NIS2 obligations face considerable sanctions. Maximum fines can reach up to €10 million or — depending on interpretation by national authorities — up to 2 percent of annual turnover. In this regard, NIS2 follows the stricter sanctions regime familiar from the GDPR.

For CISOs and security managers, this creates a dual compliance obligation: on the one hand, the technical and organizational measures required by NIS2 must be demonstrably implemented. On the other hand, comprehensive documentation of compliance is required to prove conformity during audits or inspections by national authorities. Regular security assessments and incident management processes are key requirements in this context.


Source: news.google.com · Published 1 August 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: