NIS2 deadline missed as 62% of companies face fines
Published on 06/23/2026 at 05:34 | Redaktion boerse-global.de
Companies across Germany are being pushed by two pressures at once: tougher cyber rules and a rapidly expanding attack surface. In manufacturing, the share of internet-enabled products has climbed to 67 percent, while regulators are tightening expectations just as automated attack methods become more sophisticated.
The clearest warning sign so far is the NIS2 rollout. Since December 2025, the new BSI law (BSIG) has applied, bringing stricter requirements for around 29.500 companies — six times more than before. Yet implementation has fallen badly behind.
By the time the registration deadline with the BSI expired in March 2026, market observations suggested that 62 percent of affected organisations had failed to sign up. The Cyber Security Report from Schwarz Digits says almost half of companies underestimate whether NIS2 applies to them at all.
The consequences are severe. Fines of up to ten million Euro or two percent of worldwide turnover are possible, and management can also be held personally liable. Documented incident-response strategies and network segmentation are no longer optional; they are part of compliance.
Regulation is still moving. In May 2026, the Federal Ministry of the Interior presented a draft of the Kritisverordnung. It fleshes out the KRITIS-Dachgesetz and sets new thresholds, including for district cooling supply and power generation plants.
Technical deadlines are also piling up. Microsoft Secure Boot certificates from 2011 are due to expire in June and October 2026, and an automatic update is meant to move systems to new certificates from 2023.
A longer-term shift is coming from quantum security. France’s security authority ANSSI announced that from 2027 it will no longer certify security products that do not protect against quantum-based decryption attempts. The concern is simple: attackers may be collecting encrypted data now in order to break it later with quantum computers.
Fraunhofer IPMS has responded with Q-Dice, a quantum random number generator based on vacuum fluctuations. The system delivers high bit rates for cryptographic use.
Industry is also wrestling with older internal systems that slow down the digital transition. The share of IoT in industry rose from 33 percent in 2023 to 67 percent in 2026, and manufacturers are increasingly turning to subscription models and data-driven products. But more than 40 percent of manufacturers still need more than three months to calculate prices for new digital offerings because of outdated ERP systems.
In operational technology, automation is becoming more important. Rockwell Automation unveiled new AI solutions in June 2026 that identify vulnerabilities in industrial plants and secure remote access. The need is growing fast: security alliances such as the Five Eyes warn of sharply rising risks from AI-assisted cyberattacks.
Cooperation is proving useful beyond the factory floor. In mid-June 2026, the InfoSec Impact Awards recognised projects seen as models for others. The district of Gießen works with 18 municipalities on joint training and emergency systems, helping them deal each day with more than 300.000 new malware variants.
Healthcare is following a similar path. In Switzerland, hospitals, pharmacies and insurers are pushing ahead with networking efforts aimed at reducing breaks in billing and medication processes, while improving data security through dedicated service networks.
Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.
