The bottom line: The legal implementation deadline for NIS2 on 31 July 2024 requires approximately 11,000 German companies to document and implement their cybersecurity in regulatory compliance.
The deadline for implementing the NIS2 Directive ends on 31 July 2024. By then, in Germany, approximately 11,000 critical infrastructures and other essential service providers must have their cybersecurity measures in place in regulatory compliance.
The Directive on Network and Information Security (NIS2 Directive) must be transposed into national law by 31 July 2024. This affects operators of critical infrastructure in the energy, transport, water, health, digital infrastructure and public administration sectors as well as other providers of essential services such as banks and insurers.
For compliance officers, this means in concrete terms: risk management systems must be documented, security measures implemented and cyber incident reporting obligations established. The deadline allows for no postponements – as of August, the corresponding enforcement mechanisms will take effect.
Companies that do not complete their adjustments in time risk fines. The authorities – above all the Federal Office for Information Security (BSI) – will begin conducting inspections as of August. An inventory of one’s own measures and a conformity check with legal requirements should therefore be carried out immediately.
Source: news.google.com · Published 19 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.