Key point: CISOs must demonstrate NIS2 compliance by October 17, 2024, or companies face fines up to €500,000 for missing the deadline.
The transition to the new NIS2 Directive must be completed in Germany by October 17, 2024. Approximately 11,000 companies have missed the deadline and risk fines up to €500,000.
The Network and Information Security Directive (NIS2) obliges operators of critical infrastructure and digital service providers in the EU to implement enhanced security standards. Germany has transposed the directive into national law and set an implementation deadline of October 17, 2024. According to current reports, approximately 11,000 German companies have missed this deadline.
For CISOs, failure to comply poses concrete risks: companies unable to demonstrate that they meet NIS2 requirements must expect fines of up to €500,000. These sanctions are imposed by the competent regulatory authorities. Organizations in the energy, transport, water, healthcare, digital infrastructure, and financial services sectors are particularly affected.
For affected companies, there is still an opportunity to promptly implement the required measures: establish security management systems, conduct risk analyses, implement incident reporting procedures, and foster a cybersecurity culture. Those who demonstrate compliance now will document their compliance with supervisory authorities in time and mitigate potential sanctions.
Source: news.google.com · Published July 20, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.