Skip to content

NIS2 Implementation Deadline Expired: 12,000 Companies Face Fines

The Bottom Line: Approximately 12,000 companies have failed to implement NIS2 requirements and risk fines of up to 10 million euros.

The deadline for implementing the NIS2 Directive has expired. According to estimates, approximately 12,000 businesses have not yet fulfilled the new cybersecurity requirements and must reckon with significant administrative penalties.

With the expiration of the implementation deadline for the NIS2 Directive (Network and Information Security 2), thousands of businesses must prepare for monetary fines. According to available estimates, approximately 12,000 companies in the German-speaking region have not yet implemented the required compliance measures. The EU-wide directive obligates operators of critical infrastructure and large enterprises to adhere to strengthened security standards in the field of information security.

For a Chief Information Security Officer (CISO), failure to comply poses considerable risks. In addition to financial penalties of up to 10 million euros, reputationally damaging administrative proceedings, publicly issued fine notices, and potential liability risks for boards of directors or management threaten. Independently of this, information security deficiencies in the operation of critical systems are increasingly monitored by authorities and can lead to regulatory escalation.

CISOs should immediately examine what compliance gaps remain and document them. In enforcement practice, authorities often differentiate between wilful non-compliance and demonstrable efforts to achieve compliance. Comprehensive documentation of transition processes can have a mitigating effect in proceedings.


Source: news.google.com · Published August 1, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: