Skip to content

NIS2 Implementation Deadline Ends End of July – Fines Threaten Thousands of Companies

The bottom line: The NIS2 implementation deadline ends on 31 July 2024; approximately 11,000 companies face the risk of fines up to €10 million.

The implementation deadline for the EU NIS2 Directive expires at the end of July 2024. Estimates suggest that approximately 11,000 companies have not yet fully implemented the required measures and thus risk substantial fines.

The National Directive for Network and Information Security (NIS2) requires operators of critical infrastructure and digital services to implement comprehensive cybersecurity measures. The deadline for national implementation by EU Member States ends on 31 July 2024. After this date, violations can be sanctioned with fines of up to €10 million or 2 percent of global annual turnover.

The large scale of the implementation gap poses significant challenges for compliance officers: 11,000 affected companies have not yet implemented all required security standards, such as in incident response, vulnerability management or supply chain security. This affects energy suppliers, telecommunications providers, financial institutions, healthcare and other critical sectors.

For CISOs, this means a critical deadline. Companies should immediately review their compliance status: Are all required policies in place? Have technical and organisational measures been documented and actually implemented? Have audit and incident reporting procedures been established? Full implementation within a few weeks is unrealistic – however, demonstrable, good-faith effort in addressing regulatory requirements can be conducive to regulatory forbearance.


Source: news.google.com · Published 20 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: