In brief: With the NIS2 deadline on 31 July, CEOs assume direct personal responsibility for cybersecurity compliance under the regulatory framework.
On 31 July 2024, the NIS2 Directive enters into German law. Executives of critical infrastructures and enterprises of strategic importance assume personal liability from this date onwards for the fulfilment of cybersecurity requirements.
The NIS2 Directive (Network and Information Systems Directive 2) obligates operators of critical infrastructures as well as enterprises of strategic importance (so-called operators of essential services) to implement comprehensive cybersecurity measures. The implementation deadline of 31 July 2024 marks the point from which these regulations become binding.
Responsibility no longer rests solely with the IT department or the Chief Information Security Officer. Executives are explicitly named in the regulatory text as personally liable bodies. This means: they can be held personally accountable if cybersecurity standards are not met or organisational failures lead to security deficiencies.
For board members and executives, it is therefore essential to review a concrete inventory before 31 July: Which facilities fall under NIS2? Which technical and organisational measures have not yet been implemented? Who bears internal responsibility for compliance and documentation? Without clear governance and regular compliance reviews, liability risks emerge that can extend beyond administrative fines.
Source: news.google.com · Published 20 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.