Skip to content

NIS2 Implementation Deadline Ends on 31 July: Fines up to €500,000 Threaten

In brief: The NIS2 implementation deadline ends on 31 July, and around 11,000 German companies must complete their cybersecurity measures by then to avoid fines up to €500,000.

The implementation deadline for the European NIS2 Directive ends on 31 July 2024. Around 11,000 companies in Germany risk high fines if they have not implemented the required cybersecurity measures by then.

The Directive on the security of network and information systems (NIS2 Directive) must be transposed into national law in Germany and the other EU member states by 31 July 2024. The NIS2 Directive specifies cybersecurity requirements for operators of essential services and providers of digital infrastructure services (DIKI providers).

For affected companies that fail to meet the requirements by the deadline, the penalty system provides for fines of up to €500,000. According to estimates, around 11,000 companies in Germany are affected by NIS2 requirements — including energy suppliers, water utilities, financial institutions, hospitals and telecommunications companies, as well as specialized DIKI providers.

CISOs should immediately review the status of their compliance measures: the key requirements include a cybersecurity management system, reporting obligations for significant security incidents, and incident response structures. Uncertainties regarding own applicability can be clarified via the competent Federal Office for Information Security (BSI) and the respective supervisory authorities.


Source: news.google.com · Published 19 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: