Skip to content

NIS2 Directive: 30,000 Companies Must Meet Cybersecurity Standards

The bottom line: The NIS2 Directive now requires approximately 30,000 additional companies to implement documented cybersecurity management systems and incident reporting.

With the implementation of the NIS2 Directive into German and European law, around 30,000 companies are now subject to new binding information security requirements.

The National and European Security and Cybersecurity Directive (NIS2) significantly expands the circle of affected organisations. While the predecessor directive NIS1 primarily addressed operators of critical infrastructure and providers of digital services, NIS2 now covers significantly more companies – including medium and large enterprises from the manufacturing, financial and energy sectors, as well as service providers.

The new security obligations include in particular risk management systems, technical and organisational measures to defend against cyberattacks, incident response procedures, and the documentation and reporting of security incidents. Companies must also assess their supply chain risks and anchor security standards in procurement.

For compliance officers, this means in concrete terms: the implementation of security management systems, the training of employees and regular review of measures become a standard task. Violations of NIS2 requirements can result in substantial fines, which is why systematic implementation and documentation are essential.


Source: news.google.com · Published 24 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: