German firms face NIS2 compliance deadline and multi‑million euro fines
The EU NIS2 cybersecurity directive entered into force in Germany on 6 December 2025, with the first‑time registration deadline passing on 6 March 2026. Only about 38 % of the roughly 29 000 affected German companies had registered by that date, leaving the majority in formal breach and exposing them to enforcement actions by the Federal Office for Information Security (BSI).
Under NIS2, any enterprise employing more than 50 staff or generating over €10 million in annual revenue – including many medium‑sized manufacturers in Ostwestfalen‑Lippe and Lower Saxony – must demonstrate hardened digital infrastructure for production control systems. The law eliminates transition periods; non‑compliant access, such as unsecured remote maintenance connections, can trigger fines of up to €7 million and personal liability for senior management. Regional firms like symmedia of Bielefeld are offering certified platforms to secure data exchange and isolate remote access, helping manufacturers meet the new requirements.
Companies are urged to establish documented incident‑response processes, secure external connections, and maintain detailed audit trails to avoid penalties and protect market eligibility.