Skip to content

NIS2 Implementation Deadline: 11,000 German Companies Risk Fines

In brief: Approximately 11,000 German companies risk fines of up to €500,000 if they fail to meet NIS2 requirements by the deadline.

The implementation deadline for the European NIS2 Directive is drawing to a close. According to estimates, approximately 11,000 German companies face fines of up to €500,000 if they fail to meet compliance requirements.

The NIS2 Directive (Network and Information Security Directive 2) requires operators of critical infrastructure and digital service providers in the EU to strengthen their IT security standards. The legislator has set binding implementation deadlines whose compliance is monitored and enforced by member states.

For CISOs and responsible parties in companies, this means that technical measures, governance structures and incident response processes must be documented and demonstrable. Non-compliance with the requirements can result in significant fines – for serious violations up to €500,000 per company.

Comprehensive NIS2 compliance requires a stocktaking of the current security posture, identification of compliance gaps and prioritisation of measures. Special attention should be paid to the new requirements for zero-trust architectures, cryptography, multi-factor authentication and notification obligations in the event of security incidents.


Source: news.google.com · Published 10 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: