German firms fall short on EU NIS-2 cyber‑security compliance
A Civey online survey commissioned by TÜV Rheinland of 500 IT managers in Germany found that only one‑third of companies consider themselves on track to meet the EU’s NIS‑2 network and information‑security directive. Fully compliant firms account for 14.3 %, while 16.9 % are far advanced, 6.4 % have begun implementation, 3.4 % are planning, and 6.6 % say the directive is not an issue. One‑fifth (21.6 %) believe the regulation does not apply to them, and 30.8 % answered “don’t know” when asked about their progress.
Michael Silvan, cybersecurity expert at TÜV Rheinland, warned that “the time is running out; companies must soon prove they meet the new legal duties, or risk compliance gaps and personal liability for management.” The survey shows 60.3 % of respondents consider NIS‑2 important or very important for enhancing resilience. TÜV Rheinland is offering an expert week to help firms understand obligations such as IT‑compliance, supplier management, risk management and incident response ahead of the deadline when the directive is transposed into German law at the end of 2025.