German, Executives

German Executives Face Mandatory Cybersecurity Training as NIS-2 Compliance Deadline Looms

Published on 07/30/2026 at 12:24 | Redaktion boerse-global.de

German executives face mandatory cybersecurity training under NIS-2, with penalties up to €10M and personal liability for compliance failures.

German NIS-2 Cybersecurity Training Mandate for Business Leaders
German Executives Face Mandatory Cybersecurity Training as NIS-2 Compliance Deadline Looms Illustration mit AI erstellt übermittelt durch boerse-global.de

A specialized online seminar scheduled for early September will require German business leaders to complete six teaching units on cybersecurity obligations, marking a new phase in the country’s implementation of the European NIS-2 directive. The course, led by instructor Maximilian Klose, costs €420 plus VAT, with organizations such as the German Red Cross (DRK) receiving a 20 percent discount.

The training focuses on modern risk management, statutory reporting duties, and the personal liability risks facing company executives. Since the NIS-2 directive took effect in Germany on December 6, 2025, without any transition period, corporate leaders must immediately demonstrate their cybersecurity knowledge and implement protective measures within their operations.

According to the Federal Office for Information Security (BSI), only about 11,500 of an estimated 29,500 affected German companies had registered by summer 2026. The directive applies to firms in 18 sectors with at least 50 employees or annual revenue of €10 million. The original registration deadline of March 6, 2026 was extended to July 31, 2026, due to sluggish enrollment.

Missing this deadline constitutes a separate offense subject to fines. Experts view the registration gap as evidence that many executive boards have not prioritized cybersecurity sufficiently. Penalties for violations can reach €10 million or 2 percent of global annual turnover. Crucially, Section 38 of the BSI Act (BSIG) explicitly holds management personally liable for compliance failures.

A study by IT service provider Plusserver highlights implementation challenges. Only 34 percent of surveyed companies have fully met NIS-2 requirements, while 47 percent describe the process as difficult. The biggest technical hurdle, cited by 48 percent of respondents, is outdated legacy operational technology (OT) systems.

The directive’s impact extends across supply chains. Approximately 51 percent of companies report changes in business relationships with partners. Risk management requirements now cover human factors, external service providers, remote administrators, and nearshore teams.

Germany’s federal government deliberately chose “gold-plating” when transposing the EU directive into national law. As CDU lawmaker Franziska Hoppermann explained in a parliamentary response in mid-June 2026, EU minimum standards were tightened because they were deemed insufficient for strengthening cybersecurity.

These stricter rules are particularly evident in the water sector, where thresholds were lowered to include many mid-sized utilities. Obligations now include installing attack detection systems, expanded incident reporting requirements, and full management liability. While NIS-2 has been in force EU-wide since January 2023, supplementary regulations like the Digital Operational Resilience Act (DORA) for financial service providers have applied since January 17, 2025.

Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.

en | boerse | 69899803 |