Skip to content

NIS2 Implementation: Only 34 Percent of Companies Meet Requirements

Key takeaway: Two-thirds of companies are currently failing to achieve NIS2 compliance and must carry out extensive measures within the remaining time to avoid fines.

A current survey shows that only 34 percent of companies are already meeting the requirements of the NIS2 Directive. The implementation deadline is approaching and reveals significant compliance gaps across German mid-market companies and industry.

The compliance rate of 34 percent documents a substantial discrepancy between regulatory requirements and operational reality. Concretely, this means that two-thirds of affected organizations still need to make substantial adjustments to their IT security architecture, governance processes, or documentation.

For CISOs and security officers, this presents a dual challenge: on one hand, internal stakeholders and management need to be informed about compliance risks. On the other hand, two-thirds of companies still have fundamental tasks pending — from identifying critical infrastructure to implementing technical controls through to establishing incident response procedures according to NIS2 standards. Authorities will sanction violations of the Directive with fines in the double-digit millions.

Companies that have not yet taken action or have only taken partial measures should immediately conduct a gap analysis against NIS2 requirements and develop a prioritized action plan. A focus on core areas — asset management, access control, cryptography, logging and monitoring — can still achieve significant progress within the remaining time.


Source: news.google.com · Published 12 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 of the EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: