Bottom line: 31 July 2024 marks the binding registration deadline for approximately 11,000 companies under the NIS2 Directive.
Approximately 11,000 companies in the German-speaking region must register under the NIS2 Directive by 31 July 2024. This deadline is mandatory for operators of critical infrastructure and digital service providers.
The National Government Authority for Cybersecurity (or corresponding authority) has set the registration deadline for implementation of the European NIS2 Directive. Approximately 11,000 companies are required to register by 31 July – including operators of critical infrastructure such as energy, transport and water, as well as digital service providers and larger digital services.
For CISOs, the deadline translates into concrete action requirements: registration is not merely documentation, but the formal entry into NIS2 compliance obligations. These include risk assessment processes, incident reporting according to the Directive’s requirements, business continuity measures and regular security audits. Companies that have not registered by then risk regulatory sanctions and possible operating restrictions.
A checklist should ensure registration is complete: identification of all affected business areas, evidence of cybersecurity measures, designation of incident response contacts and documentation of the existing governance structure. Many companies are still in an orientation phase; those with gaps before the deadline should now clarify with the competent authorities which documentation will be accepted.
Source: news.google.com · Published 21 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.