Skip to content

NIS2 Registration Deadline Passed: Majority of Critical Infrastructure Operators Not Registered

On point: The NIS2 Directive registration deadline has expired, but many critical infrastructure operators have failed to register.

The registration deadline for critical infrastructure operators under the NIS2 Directive has expired today. According to reports, large portions of affected companies in the industrial sector have not registered by the deadline.

The European Network and Information Security Directive (NIS2) requires operators of critical infrastructure to report their systems and contact details to the competent national authorities. This reporting obligation was to be fulfilled by today.

For CISOs and security officers, the widespread failure to register represents a significant compliance risk. Companies that have missed the deadline must expect administrative sanctions and thereby endanger their legal position as well as their insurance coverage in the event of security incidents. At the same time, the widespread non-compliance signals an implementation gap that weakens the overall cyber resilience of critical European infrastructure.

Affected organizations should act immediately: making up for the registration and demonstrating why the deadline was exceeded can mitigate the consequences. In parallel, CISOs should verify whether their organization actually qualifies as a critical infrastructure operator under NIS2 or whether it must fulfil additional requirements as a dependent service provider or supplier.


Source: news.google.com · Published 31 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: