In brief: Approximately 29,500 German entities must register with their competent authority by July 2024 in accordance with the NIS2 Directive to demonstrate legal compliance.
The NIS2 Directive registration deadline expires in July 2024. Around 29,500 German entities must register by then to meet the new EU cybersecurity requirements.
The National Cybersecurity and Information Security Authority (or equivalent national body) requires critical infrastructure operators and certain digital service providers to register in accordance with the NIS2 Directive. Germany estimates that approximately 29,500 affected entities must register by the end of July.
For compliance officers, this means in practical terms: registration is a mandatory prerequisite to demonstrate legal compliance with NIS2. Those who miss the deadline risk fines and classification as non-compliant by supervisory authorities. Registration also documents compliance with fundamental cybersecurity standards such as the performance of risk assessments and the implementation of security measures.
Entities should promptly verify whether they fall within the scope of the NIS2 Directive and familiarise themselves with the requirements of their competent authority. Typically, operators of critical infrastructure (energy, water, transport, health) as well as qualified providers of digital services (clouds, DNS, exchanges, marketplaces) must take action.
Source: news.google.com · Published 27 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.