Network Blind Spots Plague German Companies as EU Cyber Compliance Deadlines Approach
Published on 07/20/2026 at 12:44 | Redaktion boerse-global.de
Just weeks before a key registration deadline expires, new figures reveal that two out of three German companies have no clear picture of what devices are connected to their networks. A study by security firm Armis found that 66 percent of organisations lack full control over their networked equipment, while only 29 percent have complete oversight of their 47,000-strong digital asset inventory on average.
That transparency gap is becoming a serious liability. On 31 July 2026 a grace period for companies covered by the NIS2 directive runs out in Germany. Around 11,000 firms have still not registered with the Federal Office for Information Security (BSI). Those that miss the cut face fines of up to €500,000, and management can be held personally liable.
Even tighter requirements are coming from the Cyber Resilience Act (Regulation (EU) 2024/2847), which has been in force since December 2024 but is being phased in. From 11 September 2026, manufacturers, importers and distributors of products with digital components must comply with initial reporting and vulnerability-handling obligations. Full compliance becomes mandatory in December 2027.
Under the CRA, companies have to act fast when a security incident occurs. An early warning must reach ENISA and the German CERT-Bund within 24 hours, followed by a detailed report 72 hours after detection. The final post?incident assessment is due within 14 days of the event being resolved. Penalties for breaches can hit €15 million or 2.5 percent of global annual turnover, whichever is higher. Nearly any product with a data connection is covered; only free and open?source software unrelated to a commercial activity is exempt.
The pressure is building on other fronts too. On 2 August 2026, new transparency rules under the EU AI Act come into effect, specifically around labelling AI?generated content. The Netherlands plans to pass its own national cybersecurity law (Cbw) on 15 August 2026.
The operational challenge is compounded by a persistent skills shortage. According to the latest ENISA NIS Investments Report, companies are allocating roughly 9 percent of their IT budgets to cybersecurity — a stable figure. Yet 76 percent of organisations report difficulty finding qualified staff. Meanwhile, 28 percent need more than three months to patch critical vulnerabilities, a pace that makes meeting the strict reporting windows almost impossible.
Industry players are responding with new alliances. On 17 July 2026, cybersecurity firm secunet and cloud infrastructure provider Cloudflare announced a partnership aimed at critical infrastructure operators and public authorities. The collaboration combines global cloud reach with a European operational model. Separately, IT services company CGI and law firm Heuking have joined forces to offer legal and technical NIS2 compliance advice from a single source.
Automation is also being explored. ONEKEY, a German security company, is developing AI assistants under the EU?funded CRACoWi project. These tools are intended to help manufacturers draft technical documentation and meet CRA requirements more efficiently.
How all these standards will work in practice will be debated at upcoming events. The secIT digital conference takes place on 29 and 30 September 2026 in an online format. Christoph Puppe from the BSI will update participants on “Grundschutz++,” a revised baseline security framework due to be finalised later this year. Separate CRA implementation workshops are scheduled for 6 and 8 October 2026.
Financial sector regulation is also tightening. A June report from the European Securities and Markets Authority (ESMA) on the Digital Operational Resilience Act (DORA) noted that severe ICT?related incidents must be reported within four hours of classification, with ultimate responsibility resting irrevocably with the board.
Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.
