On point: Approximately 11,000 German companies from critical infrastructure sectors must implement NIS2 by 31 July 2024, or face administrative fines.
On 31 July 2024, the implementation deadline for the NIS2 Directive in Germany expires. Approximately 11,000 companies from critical infrastructure sectors must have fulfilled their cybersecurity measures according to the new standards by then, otherwise substantial fines threaten.
The European NIS2 Directive (Network and Information Security) obligates operators of critical infrastructure and digital services to meet enhanced security requirements. In Germany, this affects around 11,000 organisations from sectors such as energy, water, health, transport, finance and telecommunications. The national implementation must be completed by the end of July 2024.
For CISOs, the deadline entails substantial implementation requirements: these include mandatory minimum requirements for information security, incident reporting obligations, cyber insurance evidence and the establishment of cybersecurity governance structures. Companies that do not meet the requirements by the deadline must expect administrative fines, the amount of which will be determined according to German regulations (expected to be set via the IT Security Act amendment).
A considerable proportion of affected companies are experiencing implementation delays, due to factors such as lack of resources, unclear regulatory requirements at federal state level, or necessary adjustments to governance and processes. CISOs should use the remaining time to identify compliance gaps and finalise documentation.
Source: news.google.com · Published 21 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification via Lumi News Pipeline v1.7.3.