NIS2 obligates operators of critical infrastructures and essential services to comply with enhanced cybersecurity standards by 3 October 2026; non-compliance carries penalties of up to €10 million.
The NIS2 Directive implementation deadline expires on July 31; companies that have not met their cybersecurity requirements face substantial penalties.