29,500 German companies in critical infrastructures and essential services are obligated to implement the EU cybersecurity standards of the NIS2 Directive.
Orphaned accounts in decentralized cloud services constitute a direct breach of NIS2 requirements and trigger personal liability for company executives.
NIS2 makes board members personally liable for cybersecurity and requires annual management documentation – CISOs must establish formal compliance evidence.
Approximately 1,300 CRITIS operators must register by July 17 under the CRITIS Umbrella Act and will thereby be subject to stricter cybersecurity and reporting obligations.
Mid-sized enterprises must manage NIS2 requirements, DADG obligations, and EU AI Act compliance in parallel, which consolidates resources and expertise.