Skip to content

NIS2: 29,500 Companies Must Take Action by July 31

At a glance: 29,500 companies have until July 31 to upgrade their cybersecurity in line with NIS2 standards.

The NIS2 Directive sets a new deadline: approximately 29,500 companies in the DACH region must adapt their cybersecurity measures to EU requirements by July 31.

The Network and Information Security Directive (NIS2) sets a binding deadline of July 31 for approximately 29,500 companies. These companies are subsequently required to design their IT security according to the new requirements of the Directive or to demonstrate that existing measures are compliant.

For CISOs, this deadline represents a critical control phase. They must specifically verify whether risk treatment measures, incident response procedures and security governance meet the new standards. NIS2 requirements include, among other things, cybersecurity measures in supply chain management, regular penetration testing and documented emergency plans.

Companies that cannot demonstrate by this date that their security infrastructure complies with NIS2 requirements risk fines and regulatory intervention. CISOs should therefore immediately conduct a gap analysis against NIS2 requirements and consolidate outstanding items in a binding implementation plan.


Source: news.google.com · Published July 14, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: