Skip to content

NIS2 Deadline Approaching: 11,000 German Companies Must Act

In a nutshell: 11,000 German companies must complete their NIS2 compliance measures within less than two weeks, or face regulatory consequences.

In Germany, approximately 11,000 companies are obligated to implement the requirements of the NIS2 Directive — the deadline expires in just under two weeks. As critical infrastructure operators and larger companies, they must document their cybersecurity measures and demonstrate them to the responsible authority.

The National Industrial Strategies Security Directive 2 (NIS2) obliges companies above a certain size and from defined sectors (energy, water, transport, health, ICT and others) to meet enhanced cybersecurity standards. In Germany, this affects an estimated 11,000 organizations that have had to implement their compliance measures to date.

The implementation deadline for the NIS2 requirements into German law and their operational implementation is approaching a fixed cut-off date. CISOs and executive management of these companies must ensure that their systems, processes and governance structures comply with the new requirements — particularly with regard to risk management systems, incident reporting obligations and technical security measures.

For companies that have not yet completed the implementation status, the remaining time is critical. Delays can result in supervisory measures or sanctions. At the same time, reporting channels to authorities such as the BSI must also be established to correctly classify and escalate security incidents.


Source: news.google.com · Published July 18, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: