NIS2 Implementation Fails
In his commentary, Jörg Schumann analyzes the background and consequences of the failed NIS2 implementation for businesses.
The bill to implement the NIS2 Directive into German law has so far failed to gain a majority in the Bundestag. As a result, the legislative process is delayed until at least autumn. In his commentary, Jörg Schumann, Managing Director of IT service provider Net-D-Sign, analyzes the background and implications of this development for businesses.
Key points at a glance
- The NIS2 Directive was adopted by the European Parliament in 2022 but has not yet been implemented in Germany.
- Implementing Regulation (EU) 2024/2690 has been directly applicable law in all EU member states since 7 November 2024.
- Providers of digital infrastructure must already comply with NIS2 requirements.
- Belgium, Denmark, and Italy have already transposed NIS2 into national law.
- Companies risk losing contracts if they fail to meet cybersecurity standards within supply chains.
“As early as December 2022, the European Parliament adopted the NIS2 Directive. The current German Bundestag was unable to pass the so-called NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) before the snap elections. Likewise, the planned KRITIS umbrella act, which was meant to include further regulations for critical infrastructure, is now delayed.”
While countries such as Belgium, Denmark, and Italy have already transposed the NIS2 Directive into national law, implementation in Germany will drag on further—only after the federal elections can the legislation re-enter the political process.
“Despite political gridlock, companies must not underestimate the urgency of this issue. On one hand, the threat landscape facing businesses of all sizes is currently greater than ever. This alone makes it essential to strengthen cyber resilience—a goal for which the NIS2 Directive provides valuable guidance.”
On the other hand, the Implementing Regulation (EU) 2024/2690 on the NIS2 Directive has been in force since 7 November 2024, setting specific requirements for cybersecurity measures for companies operating in digital infrastructure.
“This regulation is directly applicable in all EU member states—regardless of national implementation. Providers of digital infrastructure and services are therefore already bound by NIS2 provisions. Additionally, supply chain dependencies play a growing role. Large companies increasingly demand that their business partners also meet cybersecurity standards. Those who fail to act proactively risk losing contracts.”
Even though the exact legal framework for implementing the NIS2 Directive in Germany remains unclear for now, companies must take action.
“Anyone who believes they can wait until the law is officially passed is making a serious mistake. NIS2 will likely be transposed into national law during the course of this year, probably by autumn 2025. Once enacted, the law will most likely apply immediately—without a transition period. Companies must not simply wait. They need to invest in cybersecurity measures now, establish risk management processes, and align themselves with the existing EU requirements.”
Frequently Asked Questions
When did the NIS2 Delegated Regulation enter into force?
The Delegated Regulation (EU) 2024/2690 entered into force on November 7, 2024. It is directly applicable in all EU member states.
Why is NIS2 relevant for companies in Germany now?
Although national implementation has been delayed, the EU Delegated Regulation already applies directly. Moreover, large companies are increasingly demanding security standards from their partners.
Which countries have already implemented NIS2?
Belgium, Denmark, and Italy have already transposed the NIS2 Directive into national law. Germany is still in the implementation process.
Is there a grace period for NIS2 implementation in Germany?
It is likely that the NIS2UmsuCG in Germany will apply without a transition period. Companies should therefore not wait.
What consequences can arise from non-compliance with NIS2 requirements?
Companies risk legal sanctions and loss of contracts, especially due to requirements imposed by major business partners in supply chains.
Reading Tips from the Editorial Team
- API-First: Why modern cloud architectures succeed or fail based on API design
- Pretext: Can a JavaScript library solve the 30-year browser problem—or is it just hype?
- AWS vs. Azure vs. Google Cloud 2026: The honest comparison for DACH companies
More from the MBF Media Network
SecurityToday | MyBusinessFuture | Digital Chiefs
Header image source: Unsplash / hoch3fotografie


