Key takeaway: 29,500 companies risk fines up to €10 million as the NIS2 implementation deadline expires on 31 July 2024.
The implementation deadline for the NIS2 Directive ends on 31 July 2024. According to current information, fines threaten approximately 29,500 companies that have not fully implemented their cybersecurity measures by then.
National regulatory authorities and compliance departments in EU member states are preparing for the enforcement of the NIS2 Directive. According to available information, approximately 29,500 companies lack full compliance by the set deadline.
The NIS2 Directive obliges operators of critical infrastructure and providers of digital services to meet defined cybersecurity standards. Implementation requirements include measures for risk minimisation, notification obligations in the event of security incidents, and the establishment of governance structures for IT security.
Failure to comply threatens fines of up to €10 million or up to 2 percent of annual global turnover — whichever is higher. Affected organisations should immediately review their implementation status and prioritise any outstanding measures to avoid penalties.
Source: news.google.com · Published 16 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.