The essentials: 11,000 companies in Germany miss the NIS2 implementation deadline of 31 July and face fines of up to €500,000.
The national implementation of the EU NIS2 Directive in Germany reaches its first implementation deadline on 31 July. According to estimates, around 11,000 companies do not yet have the required security measures in place and risk fines of up to half a million euros.
The National Authority for Cybersecurity and Critical Infrastructure (NBCI) and the Federal Office for Information Security (BSI) have specified the NIS2 requirements. Companies classified as operators of essential services or critical infrastructure must have implemented comprehensive cybersecurity measures by 31 July 2024. These include risk management systems, incident response processes, penetration testing, multi-factor authentication, and encrypted data storage.
For CISOs and security officers, the deadline entails significant operational consequences. Companies that do not meet the deadline risk fines of up to €500,000. Furthermore, unresolved deficiencies can lead to the shutdown of critical systems or the prohibition of business operations. The German government has already announced that compliance will be verified through regular audits.
A survey of German companies suggests that a large proportion of affected organisations still have gaps in their implementation. Common bottlenecks lie in budgeting for security investments, availability of qualified personnel, and the complexity of system integration. CISOs should immediately conduct a gap analysis and – if not already done – initiate a prioritised implementation plan with milestone tracking before the deadline.
Source: news.google.com · Published 20 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.