Skip to content

NIS2 Implementation: 29,500 Companies Miss Registration Deadline by 31 July

The gist: Around 29,500 German companies failed to register under the NIS2 Directive by 31 July, creating fines risks and legal uncertainty.

About 29,500 German firms did not register under the NIS2 Directive by 31 July 2024, despite this being a binding obligation. The deadline marked an important milestone in the implementation of EU cybersecurity regulation.

The NIS2 Directive (Network and Information Security Directive 2) requires operators of critical infrastructure and digital economy enterprises to register and report cybersecurity incidents. 31 July 2024 was the binding registration deadline for affected organisations in Germany.

According to ad-hoc-news.de, around 29,500 companies missed this deadline. This points to an implementation gap that reflects both technical and administrative hurdles – from lack of clarity on how the regulatory framework applies to capacity constraints in compliance implementation.

For CISOs, this represents an immediate risk: unregistered firms face fines and lose legal clarity regarding incident reporting obligations. Regulators are expected to respond with graduated measures – from notices through warnings to formal penalties. CISOs should prioritise catching up on all required registrations while simultaneously preparing documentation of previous reasons for delays for authorities.


Source: news.google.com · Published 17 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: