Bottom line: Approximately 11,000 companies have failed to meet the BSI deadline of July 31 for their NIS2 compliance measures.
According to the German Federal Office for Information Security (BSI), around 11,000 companies have not met the deadline for implementing the national transposition of the NIS2 Directive by July 31. This poses compliance risks and potential sanctions.
The German Federal Office for Information Security (BSI) has published concrete figures for the first time on the implementation of the NIS2 Directive in Germany: Approximately 11,000 companies have not met the deadline of July 31, 2024 and are classified as non-compliant.
For compliance officers, this represents a critical situation. Failure to meet NIS2 requirements by the agreed deadline constitutes a violation of the European directive and can result in formal warnings, fines and supervisory measures. Companies affected must assume that authorities will initiate follow-up action.
Compliance teams should immediately conduct a stocktake: Which control measures are still missing? Which documentation needs to be submitted? The immediate pressure to act is considerable, as the BSI has recorded the non-compliance and regulatory authorities can use this information to initiate enforcement measures.
Source: news.google.com · Published July 16, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.