The bottom line: Only 39 percent of companies subject to the NIS2 Directive have registered; outstanding registrations and compliance gaps result in fines.
Only 39 percent of companies falling under the NIS2 Directive have registered so far. The registration deadline is approaching, and violations carry substantial penalties.
According to current data, only 39 percent of affected companies have fulfilled their registration obligations under NIS2. The directive requires critical infrastructures and other organizations to register with competent authorities and document their cybersecurity measures.
For CISOs, this represents significant compliance risk. Companies that miss the registration deadline or register incompletely face fines. The regulatory requirements of NIS2 demand systematic inventory of systems, risk analysis, and demonstrable technical and organizational security measures.
Registration is not a one-time administrative act but the starting point of continuous compliance. CISOs should verify whether their organization is subject to the registration obligation and, if necessary, immediately initiate measures to meet the requirements and avoid sanctions.
Source: news.google.com · Published 13 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.