German, SMEs

German SMEs Hit by Investment Slump as NIS2 and Workplace Safety Deadlines Converge

Published on 07/14/2026 at 04:36 | Redaktion boerse-global.de

Only 52% of Mittelstand firms plan investments as NIS2 cybersecurity and ISO 45001 safety rules tighten, with fines up to €10M and government funding drying up.

German SMEs Face Twin Squeeze: Capital Spending Slump and Regulatory Deadlines
German SMEs Hit by Investment Slump as NIS2 and Workplace Safety Deadlines Converge Illustration mit AI erstellt ĂĽbermittelt durch boerse-global.de

A historic collapse in capital spending is colliding with new regulatory deadlines, putting Germany's small and midsize enterprises under a twin squeeze — they must upgrade both IT security and occupational safety while funds dry up.

A survey released Monday by DZ Bank and the BVR cooperative banking group found that only 52 percent of Mittelstand companies plan investment projects in the next six months, the lowest reading in more than three decades. Sixty-seven percent cited energy costs as the primary burden, while 57 percent pointed to raw material prices. DZ Bank board member Thomas Beismann called the figures a "clear warning signal" for Germany's competitiveness.

The timing is particularly harsh because structural improvements are now mandatory. By July 31, companies must complete registration under the NIS2 cybersecurity directive — a step many have yet to take. Non-compliance carries fines of up to €10 million or two percent of global annual turnover. At the same time, occupational safety management is shifting to the ISO 45001:2018 standard, which replaced the old OHSAS 18001. The new norm uses a High Level Structure (HLS) to integrate seamlessly with quality (ISO 9001) and environmental (ISO 14001) management systems — but only if companies invest in proper implementation.

Advertisement

As the article notes, outdated risk assessments are the most common failure in certification audits. Keeping your risk management up to date doesn't have to be a burden — a free toolkit provides 41 ready-to-use templates and checklists to help you document hazards effectively and stay compliant. Download the free Risk Assessment Toolkit

Certification audits reveal a persistent gap between documentation and practice. Outdated risk assessments remain the most common failure. A full certification cycle includes preliminary analysis, internal audits, and both initial and surveillance audits. For companies already struggling with cash flow, these recurring costs add pressure.

Government funding options are narrowing. Since July 7, the Central Innovation Programme for SMEs (ZIM) has suspended new applications due to overwhelming demand and limited budget. Businesses now must turn to alternatives such as the tax research allowance or EU support programmes.

Separate legal changes are raising the bar for personnel management. A cabinet resolution on July 2 introduced a requirement for a medical certificate from the first day of illness, effectively ending the phone-based sick note. Industry associations welcomed the move, while doctors' groups and health insurers dismissed it as symbolic politics.

Workplace safety extends beyond general rules into sector-specific obligations. In healthcare facilities, equipment such as diagnostic devices and patient monitors must be tested under the Medical Devices Operator Ordinance (MPBetreibV) — a safety-critical and resource-intensive process.

Advertisement

Beyond sector-specific requirements, a comprehensive health and safety management system can integrate all your compliance obligations. The free Health & Safety Toolkit gives you risk assessments, checklists, and toolbox talks covering COSHH, PUWER, fire safety, and more — helping you protect employees and meet legal duties under the Health & Safety at Work Act 1974. Get the free Health & Safety Toolkit

Employment lawyers urge a holistic approach. The Federal Labour Court confirmed in September 2022 (case no. 1 ABR 22/21) that employers have a fundamental duty to record daily working hours. Combining compliant occupational safety under ISO 45001 with airtight legal organisation is becoming a decisive risk factor — especially since 54 percent of Mittelstand firms operate internationally.

"The real danger is treating work safety, labour law, and IT security as separate silos," said one compliance specialist. With the NIS2 deadline days away and investment sentiment at a historic low, the German Mittelstand must reconcile ambitious regulatory demands with emptying coffers.

Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.

en | boerse | 69763237 |