Skip to content

NIS2 Implementation Deadline 31 July: 11,000 Companies in Germany Under Pressure

In a nutshell: 11,000 German companies must comply with NIS2 requirements by 31 July or face fines up to €500,000.

Approximately 11,000 companies in Germany must have met the requirements of the NIS2 Directive by 31 July. Failure to comply threatens fines of up to €500,000.

The European Network and Information Security Directive NIS2 mandates binding measures from 31 July 2024 for operators of critical infrastructure and certain enterprises. Around 11,000 organisations in Germany are affected, and must implement their IT security governance, risk management systems and reporting obligations by the deadline.

The regulation requires, among other things, the identification and management of cybersecurity risks, the establishment of incident response processes and the reporting of significant incidents to the competent authorities. For companies that fail to meet the requirements by the deadline, administrative fines of up to €500,000 are provided for. These sanctions are enforced by the cybersecurity authorities responsible at federal and state level.

Compliance teams should promptly review whether their organisations fall within the scope of the regulation, and if they are subject to it, launch an implementation programme. The remaining time until the deadline is running short for many companies, particularly if there are still fundamental gaps in governance or documentation.


Source: news.google.com · Published 21 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: