In principle, the directive should be implemented by October 17, 2024, but this is not yet the case in Germany or in the majority of EU countries. The German government had presented a draft law on this - the NIS 2 Implementation and Cyber Security Strengthening Act as of October 2, 2024.
Most recently, on November 4, 2024, there was a public hearing on this topic in the Bundestag's Committee on Internal Affairs in which experts expressed possible points of criticism (https://www.bundestag.de/dokumente/textarchiv/2024/kw45-pa-inneres-cyber-1026336).
The law is generally not expected to be passed before March 2025, meaning that the regulations of the EU's NIS 2 Directive will not yet apply.
Until then, however, affected companies should not wait and prepare themselves by clarifying how they will be affected by the directive, defining resources and responsibilities and carrying out a risk analysis. Essential measures can already be identified and implemented if necessary in order to be prepared for the implementation of the law in good time. GINDAT is at its customers' side with its expertise and offers comprehensive support on request.