< Back to all clusters
[TECHNOLOGY] · Germany, United States · 4 sources

started · updated

German companies grapple with NIS2 cybersecurity mandates amid new EU rules

The EU’s NIS2 directive, incorporated into German law in October 2024, now requires around 29,000 organisations—those with at least 50 employees or €10 million revenue in critical sectors such as energy, health, transport and digital infrastructure—to implement rigorous cyber‑security measures. Non‑compliance can attract fines up to €10 million or 2 % of worldwide turnover.

German firms face practical challenges on the ground. AUCOTEC highlighted that its Engineering Base platform already meets the heightened transparency and audit requirements, having passed an independent ReversingLabs Spectra analysis with Level 3 certification and delivering a full software bill of materials. Meanwhile, experts stress that many companies overlook the security of end‑devices, prompting calls for continuous endpoint monitoring and automated remediation, as described by SOTI and other vendors.

In the northern Thuringia and southern Lower Saxony region, IT‑systems house TTG Daten & Bürosysteme GmbH warns that many medium‑size businesses remain unaware of or unprepared for NIS2 obligations, and offers a free compliance assessment. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also released a guide on adopting Secure Access Service Edge (SASE) and Zero‑Trust architectures, illustrating an international push toward similar security frameworks.