< Back to all clusters
[BUSINESS] · Germany · 2 sources

Germany's NIS2 Cybersecurity Law Takes Effect, Companies Struggle to Comply

The EU's NIS2 directive entered German law on 6 December 2025 without a transition period. It obliges about 29,500 medium‑ and large‑size firms across 18 sectors—those with at least 50 employees and €10 million annual turnover—to implement verifiable cybersecurity measures for networks, sites and cloud services. The law, enforced by the Federal Office for Information Security (BSI), imposes personal liability on senior management and fines up to €10 million or 2 % of worldwide turnover.

A recent Civey survey for TÜV Rheinland of 500 German IT leaders shows most firms are not yet ready. Only 14.3 % report full implementation, 16.9 % are far advanced, 6.4 % have started, and 3.4 % plan to begin. Meanwhile 6.6 % say NIS2 is not a topic for them, 21.6 % believe they are not affected, and 30.8 % are unsure of their status. Experts warn that without a clear roadmap firms risk compliance gaps and personal liability for executives.

The BSI launched its reporting portal on 6 January 2026, with the registration deadline having passed on 6 March 2026. Companies must now prove compliance or face sanctions.

Sources

about 1 month ago
about 1 month ago