Skip to content

NIS2: 29,500 German companies must upgrade their IT security

In a nutshell: Nearly 30,000 German companies must upgrade their cybersecurity measures in accordance with NIS2, with binding implementation deadlines.

The NIS2 Directive obligates around 29,500 German companies to comply with new cybersecurity requirements. CISOs and compliance officers must adapt their protective measures by the implementation deadlines.

The European NIS2 Directive (Network and Information Security Directive 2) regulates elevated security standards for operators of critical infrastructure (KRITIS) and suppliers of essential services. In Germany, this affects approximately 29,500 organizations from sectors such as energy, water, transport, health, public administration and the financial sector.

The Directive prescribes binding minimum requirements for risk management, incident reporting, penetration testing and technical controls. Affected companies must document their IT governance structures, report security incidents to regulatory authorities without delay and review their supply chain for security gaps.

CISOs and security leaders require substantive evidence of compliance with these requirements. A gap analysis of existing controls and a structured implementation roadmap with concrete milestones help prevent missing the compliance deadline. At the same time, budget planning for necessary investments in security technology and personnel should be carried out early.


Source: news.google.com · Published 17 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: