The bottom line: Tens of thousands of companies have missed the NIS2 implementation deadline and must expect fines.
Between 11,000 and 12,000 companies have failed to meet the implementation deadline for the NIS2 Directive and must now expect penalty payments. Compliance officers should immediately review their conformity status.
Following expiration of the statutory deadline for implementing the European NIS2 Directive, between 11,000 and 12,000 companies found that they have not fulfilled its requirements. These companies are thus automatically subject to fine proceedings.
The NIS2 Directive regulates network and information security in the EU. Companies operating in critical infrastructures or exceeding a certain operational size must meet specific security standards and notification obligations. Implementation into national law was central to the compliance strategy of affected organizations.
For compliance officers, this makes an immediate review of implementation status and identified compliance gaps mandatory. Even if the deadline has passed, sanctions can be mitigated through evidence of subsequent implementation. In addition, it should be clarified in parallel whether the organization is affected and which specific requirements remain outstanding.
Source: news.google.com · Published 2 August 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.