Cybersecurity1. August 202615 min

Missed the NIS2 Registration Deadline: What to Do Now

The statutory NIS2 registration deadline in Germany expired on 6 March 2026. The BSI tolerated late registrations until 31 July 2026 — since 1 August 2026 there is neither a deadline nor forbearance. If you are only now discovering that you are in scope and unregistered, you do not need a primer. You need triage: establish applicability, register, document, limit liability. That is what this plan delivers.

R&D

R&D Team

Alev-B Research & Development

In short

The statutory NIS2 registration deadline expired on 6 March 2026 and was never extended. The BSI's toleration of late registrations until 31 July 2026 was administrative forbearance and has now lapsed — the duty under section 33 BSIG continues unchanged. Organizations that missed it should register without delay and document the reason.

The grace period is over — the obligation never went away

Germany's act implementing the European NIS-2 directive entered into force on 6 December 2025; the BSI states this itself on its statistics page "NIS-2 in Zahlen" (see https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/NIS-2-in-Zahlen/nis-2-in-zahlen.html). Since then, important and essential entities must register with the BSI, report significant security incidents, and implement risk management measures. The statutory registration deadline expired on 6 March 2026.

What happened afterwards is still widely misread. The advisory firm Kleeberg summarises the legal position precisely in its article of 15 July 2026 (see https://www.kleeberg.de/en/2026/07/15/nis-2-registrierung-bsi-gewaehrt-nachfrist-bis-31-juli-2026/): the statutory deadline was not extended. The BSI merely announced that it would tolerate late registrations until the end of July and refrain from immediate measures during that window. In legal terms this is administrative forbearance, not a new deadline. Anyone who relied on it relied on a concession, not on a right — and that concession lapsed on 31 July 2026.

The reason for the forbearance was the registration count. According to the figures Kleeberg cites from the BSI, of around 29,500 affected companies only around 11,500 had registered by the statutory cut-off on 6 March 2026, and around 18,500 by the end of May 2026. The figure of roughly 29,500 affected companies and federal administration institutions comes from the BSI press release on the launch of the BSI portal dated 6 January 2026 (see https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2026/260601_NIS2_BSI-Portal.html). On those numbers, roughly a third of the obligated population was still missing at the end of May.

The official interim tally is even more sobering. As at 30 June 2026, the BSI reports 17,729 companies registered in the BSI portal — 11,501 important and 6,215 essential entities, of which 1,342 are operators of critical installations. Adding the 216 registered branch establishments in other EU member states, the BSI reports 17,945 NIS-2 registrations in total. Over the same period the portal received 692 initial notifications and 1,659 NIS-2 notifications in total; the BSI expects to update these figures on 31 October 2026 (see https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/NIS-2-in-Zahlen/nis-2-in-zahlen.html). What the grace period achieved is already on the record: by 31 July 2026 the BSI held 19,058 registrations — 12,354 important and 6,487 essential entities, of which 1,378 are KRITIS. The federal government reported this in Bundestag document 21/7573 of 14 August 2026 (see https://dserver.bundestag.de/btd/21/075/2107573.pdf).

On its topic page for NIS-2 regulated companies, the BSI is blunt: the statutory registration deadline has already expired, and any affected entity that has not yet registered should register in the BSI portal immediately (see https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/nis-2-regulierte-unternehmen_node.html). That is the clearest available instruction. If you are reading this because you are unsure whether you belong to that group, the next three sections answer exactly that — in order, with timings.

The statutory registration deadline expired on 6 March 2026 and was never extended. The BSI grace period until 31 July 2026 was administrative forbearance, not an extension. Since 1 August 2026 there is neither a deadline nor forbearance — only an open breach that continues to accrue.

Establish applicability in 30 minutes — without a legal opinion

The most common response to a missed deadline is to instruct a law firm with a six-week turnaround. That is rarely wrong, but it is always too slow. For the initial sort you do not need an opinion, you need two facts every managing director already knows: sector and company size. Those two get you to a defensible working hypothesis in half an hour, which makes you operational immediately — the detailed legal assessment then runs in parallel.

The logic has two stages. First, the sector question: Annex 1 of the amended BSIG lists the sectors of high criticality, Annex 2 the other critical sectors. OpenKRITIS sets out both annexes with their sub-sectors (see https://www.openkritis.de/it-sicherheitsgesetz/nis2-umsetzung-gesetz-cybersicherheit.html): Annex 1 covers energy, transport, banking and financial market infrastructure, health, water, digital infrastructure and space. Annex 2 covers postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.

Manufacturing is the quiet driver of the case numbers. According to OpenKRITIS it covers, among others, medical devices and diagnostics, computing, electrical equipment and optics (NACE C 26 and 27), machinery (NACE C 28), motor vehicles and parts (NACE C 29) and other transport equipment (NACE C 30). That explains why, in the BSI registration statistics as at 30 June 2026, manufacturing is the single largest Annex 2 line item with 4,095 registrations. If you run a mid-sized machinery business and assumed NIS2 was a topic for utilities and hospitals, this is the paragraph to stop at.

Second, the size threshold. On the OpenKRITIS reading, an essential entity under section 28(1) BSIG is a large enterprise from Annex 1 — from 250 employees, or with more than EUR 50 million turnover and more than EUR 43 million balance sheet total. An important entity under section 28(2) is a medium-sized or large enterprise from Annex 1 or 2 — from 50 employees, or with more than EUR 10 million turnover and more than EUR 10 million balance sheet total. Headcount and financial figures are alternatives, not cumulative conditions: 60 employees are enough even if turnover sits well below the threshold.

Third — and this is where most quick checks fail — the special cases. Regardless of size, OpenKRITIS lists qualified trust service providers, TLD registries, DNS services and operators of critical installations as in scope; providers of public electronic communications networks and services are in scope from medium size upwards, and trust services regardless of size. Conversely there are carve-outs: financial entities falling under DORA are excluded under section 28(5) from the core NIS2 duties in sections 30, 31, 32, 35, 36, 38 and 39; the federal administration is regulated separately in section 29. And section 28(3) permits disregarding, in the headcount and financial figures, business activities that are negligible relative to the entity's overall activity — a lever that can decide classification in group structures.

For a structured self-assessment, the BSI provides its own NIS-2 applicability check, linked from the topic page above. To see where your organization stands beyond the pure applicability question, our free NIS2 readiness check gives you a maturity score across six domains in about three minutes, no registration required.

Headcount and financial figures are alternatives, not cumulative conditions. A company with 60 employees and EUR 6 million turnover in an Annex 2 sector is therefore in scope — this is the case most frequently missed in self-assessments.

StepQuestionResult if yes
1 — Annex 1 sectorEnergy, transport, banking or financial market infrastructure, health, water, digital infrastructure, space?Go to step 3 (size decides essential vs important)
2 — Annex 2 sectorPostal/courier, waste, chemicals, food, manufacturing, digital providers, research?Go to step 3 (can only become an important entity)
3 — Large entityFrom 250 employees, or over EUR 50m turnover and over EUR 43m balance sheet?From Annex 1: essential entity (section 28(1))
4 — Medium entityFrom 50 employees, or over EUR 10m turnover and over EUR 10m balance sheet?Important entity (section 28(2)), Annex 1 or 2
5 — Size-independent special caseQualified trust service, TLD registry, DNS service, operator of a critical installation?In scope regardless of any size threshold
6 — Check carve-outsFinancial entity under DORA (section 28(5)), federal administration (section 29), telecoms regime (section 28(4))?Partly or fully exempt from NIS2 duties

The first 72 hours: register, document, resolve

If the quick check returns "in scope", one prioritisation rule applies: whatever improves your position in a supervisory procedure comes first. That is not the technical measure, it is the documented evidence that you acted in a structured way from the moment you knew. A late registration with clean documentation is a fundamentally different position from a late registration that only happens after the authority makes contact.

Expect lead time in the registration process itself that is outside your control. The BSI describes it as two-stage: first you must sign up with the digital service "Mein Unternehmenskonto", then register in the BSI portal — as set out in the press release of 6 January 2026. On its topic page the BSI specifies step one as applying for an ELSTER organisation certificate. That application is an administrative process with its own turnaround. Anyone starting today and assuming they will be done within the hour is planning wrong. So start step one immediately and run the remaining items in parallel, not afterwards.

The second block is the self-assessment. Document what you assessed and on what basis: sector allocation with reasoning, headcount and financial figures as at the reference date, special cases and carve-outs checked, sources used, and the date. This documentation is valuable even if the outcome is "not in scope" — an undocumented negative assessment is worthless when challenged, a documented one is evidence of diligence.

The third block is the management resolution. It is the one step you cannot delegate and simultaneously the cheapest. A dated resolution that acknowledges the applicability assessment, instructs registration, names an accountable individual and releases a budget costs half an hour of meeting time. Without it, every later audit is missing precisely the document that would have protected management.

  1. 1Hours 0–4: apply for the ELSTER organisation certificate via "Mein Unternehmenskonto". This is step one of the two-stage BSI registration procedure and has a turnaround you cannot influence — hence first, not last.
  2. 2Hours 0–8: put the applicability assessment in writing. Sector under Annex 1 or 2, headcount and financial figures as at the reference date, special cases checked, carve-outs checked, sources, date, author. Two pages are enough — they only have to be traceable.
  3. 3Hours 8–24: pass and minute the management resolution. Content: acknowledgement of the assessment, instruction to register without delay, designation of an accountable member of management, release of budget and resources, and a fixed reporting cadence.
  4. 4Hours 24–48: complete registration in the BSI portal as soon as the organisation certificate is available. Archive the registration confirmation, timestamps and screenshots. These records are your evidence that the catch-up was voluntary.
  5. 5Hours 48–72: establish reporting capability before you need it. Name the person authorised to report plus a deputy, store the BSI portal credentials somewhere reachable during a crisis, and prepare a notification template. A registered company without a working reporting chain has deferred the obligation, not met it.
  6. 6From day 1 in parallel: instruct external legal counsel for the definitive case-by-case assessment. The quick check in this article prioritises and makes you operational; it does not replace a legal appraisal of your specific business model.

The liability picture: what the sources actually support

On sanctions, figures circulate that get conflated because they come from different layers. Separated cleanly, the picture looks as follows — and the distinction matters for your risk assessment.

First, the European layer. Article 34 of Directive (EU) 2022/2555 (see https://eur-lex.europa.eu/eli/dir/2022/2555/oj) requires member states to provide, for essential entities infringing Article 21 or 23, fines with a maximum of at least EUR 10,000,000 or at least 2 percent of total worldwide turnover of the preceding financial year, whichever is higher. For important entities the corresponding frame is at least EUR 7,000,000 or at least 1.4 percent of worldwide turnover. Note the reference point: by their wording these frames apply to infringements of Article 21 (risk management measures) and Article 23 (reporting obligations) — not to the registration duty.

Second, the German layer. OpenKRITIS describes the sanction provisions of the German implementing act as expanded, with new offence categories and increased fines between EUR 100 thousand and EUR 20 million, partly linked to worldwide turnover. That is the overall frame of the act, not the frame for a single breach.

Third — and most relevant to your specific situation — the registration duty itself. Kleeberg states expressly in its article of 15 July 2026 that a breach remains an administrative offence punishable under section 65 BSIG with up to EUR 500,000. Anyone linking a missed registration to the ten-million figures from the directive is conflating two offences. Conversely, anyone inferring low risk from the smaller figure overlooks that registration is only the entry ticket — the substantive duties under sections 30 and 32 BSIG, with their considerably higher sanction frame, have been running independently since 6 December 2025.

Fourth, the personal layer. Kleeberg records that management is personally liable under section 38 BSIG for compliance with the NIS2 duties. OpenKRITIS lists section 38 in its duties overview as its own line, "management implementation", and marks it for both essential and important entities. In practice that means: you may hand operational implementation to IT, security or providers. Responsibility for it actually happening, and for having monitored it traceably, stays with you. That is exactly why the management resolution sits at the top of the 72-hour block, not the bottom.

The EUR 500,000 under section 65 BSIG concerns the missed registration. The frames in Article 34 of the directive — at least EUR 10m or 2 percent for essential, at least EUR 7m or 1.4 percent for important entities — attach to infringements of Articles 21 and 23, that is, risk management and reporting. Register and do nothing else, and you have closed the smaller exposure while leaving the larger one open.

LayerOffenceFrame per sourceSource
EU directiveEssential entity, infringement of Art. 21 or 23At least EUR 10,000,000 or at least 2% of worldwide turnover of the preceding year, whichever is higherArt. 34(4) Directive (EU) 2022/2555
EU directiveImportant entity, infringement of Art. 21 or 23At least EUR 7,000,000 or at least 1.4% of worldwide turnover of the preceding year, whichever is higherArt. 34(5) Directive (EU) 2022/2555
German law, overallExpanded sanction provisions of the NIS2 implementing actFines between EUR 100 thousand and EUR 20 million, partly linked to worldwide turnoverOpenKRITIS, NIS2 implementing act overview
German law, registrationMissed registration as an administrative offenceUp to EUR 500,000 under section 65 BSIGKleeberg, article of 15 July 2026
Personal liabilityManagement, compliance with NIS2 dutiesPersonal liability under section 38 BSIG, non-delegableKleeberg, article of 15 July 2026; OpenKRITIS duties overview

The 90-day catch-up plan against the NIS2 minimum requirements

The real work starts after registration. Section 30 BSIG requires essential and important entities to take appropriate, proportionate technical and organisational measures; OpenKRITIS lists section 30 in its duties overview for both entity types. The substantive template is Article 21 of Directive (EU) 2022/2555, whose catalogue runs from risk analysis through incident handling, business continuity and supply chain security to cryptography, multi-factor authentication and training.

The plan below prioritises not by technical elegance but by two criteria: what closes the largest sanction exposure, and what can realistically be finished in 90 days? Proportionality here is not a loophole but a duty to justify. A mid-sized supplier need not reach the security level of a grid operator — but it must be able to explain and document why its level is appropriate.

One sequencing note from practice: reporting capability comes before risk analysis. An incomplete risk analysis can be improved later; a missed reporting deadline cannot. The BSI figures as at 30 June 2026, with 692 initial notifications and 1,659 notifications in total, also show that the reporting procedure is already in routine operation — this is not a theoretical scenario.

If you want to assess the maturity behind these measures in a structured way rather than estimate it, the matching assessment templates are in our template catalogue; scope and terms are set out transparently on the pricing page. The full picture of the duties beyond registration is covered in our roadmap NIS2 implementation act: duties for managing directors.

WindowMeasure area (Art. 21 / sec. 30)Concrete output
Days 1–15Incident handling and reporting procedureNamed reporting officer with deputy, stored portal credentials, notification template, minuted tabletop exercise of the 24-hour early warning
Days 10–30Risk analysis and security policiesDocumented risk assessment of critical systems with date, scoring basis and formal risk acceptance by management
Days 20–45Access control, MFA and cryptographyMFA coverage report with no exemptions for the executive level, encryption of sensitive data at rest and in transit, documented key management
Days 30–60Business continuity and backup managementDefined RTO and RPO per critical system, an executed restore test with a dated record and a stated outcome
Days 45–75Supply chain securitySupplier register with risk classes, security clauses in critical provider contracts, SBOM for deployed software
Days 60–90Cyber hygiene, training and effectiveness reviewAwareness training for all staff, separate management training with attendance evidence, defined security KPIs and a first review date
Day 90Evidence layer and formal approvalMeasures matrix with owners, review cycles and evidence; formal management approval as proof of compliance with section 38 BSIG

Do not build four registers: NIS2 alongside DORA, CRA and the AI Act

The final decision determines whether the catch-up produces a durable system or a stack of paper that has to be caught up again in 2027. It is taken in the week someone proposes creating "the NIS2 risk register".

The warning has a concrete basis. The regimes acting on the same IT organization in 2026 demand largely the same capabilities in different packaging: risk management, supply chain control, time-bound incident reporting and auditable evidence. NIS2 is not even the only regime touching registration — OpenKRITIS points out explicitly that financial entities under Regulation (EU) 2022/2554 (DORA) are excluded from the core NIS2 duties via section 28(5), because DORA applies to them instead. Get that boundary wrong and you either build twice or not at all.

In practice: do not create a NIS2 risk register, create a risk register with a mapping field recording which regimes each entry touches. The same applies to the supplier register, the incident process and the evidence repository. The control "we detect, classify and report incidents on time" is built once, rehearsed once and evidenced several times. Rebuild it per regime and, in our experience, it never gets tested properly at all.

The timing is better than it feels. You are rebuilding the controls anyway — the extra effort for a regime-neutral data model is a few days during a rebuild and several months as a later retrofit. The full map of overlaps and deadlines is in our Regulatory Collision 2026; the boundary between the two regimes that overlap most often in practice is covered in DORA vs. NIS2.

  • One risk register with a regime mapping field instead of one register per regime
  • One supplier register as the shared source for NIS2 supply chain diligence, the DORA register of information and the CRA bill of materials
  • One incident process, clocked to the tightest applicable deadline, with a classification gate for the reporting decision
  • One versioned evidence repository for policies, roles, approvals and test records
  • One role matrix per business unit recording which regime applies in which role — including the DORA carve-out under section 28(5) BSIG

Four mistakes that get expensive after a missed deadline

Mistake one: waiting to see whether the BSI gets in touch. The portal is where registrations are recorded, and on its statistics page the BSI announces that it expects to update the registration and notification figures on 31 October 2026. After the end of the forbearance period, more consistent monitoring of compliance is to be expected — as Kleeberg puts it. Waiting turns a voluntary catch-up into an enforced one.

Mistake two: not documenting the negative assessment. If your check concludes you are not in scope, that is a good outcome — but only if it is on file. A verbal view expressed in a leadership meeting is not evidence in a supervisory procedure. Two pages with a date, a data basis and a signature are.

Mistake three: treating registration as the finish line. The registration duty is one of several. Sections 30 (risk management measures), 32 (reporting), 35 (customer notification) and 38 (management) BSIG have been running independently since 6 December 2025 — as the OpenKRITIS duties overview shows for both entity types. A registered company without risk management has closed the smaller sanction exposure and left the larger one open.

Mistake four: forgetting the supply chain. Even entities that turn out not to be in scope are effectively co-regulated through the supply chain requirements of affected customers. In practice the first concrete NIS2 requirement often comes not from an authority but from the largest customer — and it comes with a deadline shorter than any administrative forbearance.

Key Takeaways

  • The statutory NIS2 registration deadline expired on 6 March 2026 and was never extended; the BSI toleration of late registrations until 31 July 2026 was administrative forbearance and has now lapsed — the duty under section 33 BSIG continues unchanged.
  • Of an estimated 29,500 affected companies, only around 11,500 had registered by the cut-off according to the BSI figures reported by Kleeberg; the BSI reports 17,729 portal registrations as at 30 June 2026, and the federal government 19,058 registrations by 31 July 2026.
  • Applicability can be sorted in 30 minutes: sector under Annex 1 or 2, size threshold as an alternative test (from 50 employees or over EUR 10m turnover and balance sheet for important entities), then special cases and carve-outs such as the DORA exclusion under section 28(5) BSIG.
  • Keep the sanction layers apart: up to EUR 500,000 under section 65 BSIG for the missed registration (Kleeberg), versus at least EUR 10m or 2 percent for essential and at least EUR 7m or 1.4 percent for important entities on infringements of Art. 21 or 23 of Directive (EU) 2022/2555.
  • The first 72 hours decide your position: apply for the ELSTER organisation certificate, put the self-assessment in writing, minute the management resolution, register in the BSI portal, establish reporting capability — in that order.

Continue Reading

Frequently Asked Questions

No. The statutory registration deadline expired on 6 March 2026 and was not extended. The BSI merely announced that it would tolerate late registrations until the end of July 2026 and refrain from immediate measures in that window — legally administrative forbearance, not a change to the statutory deadline. Kleeberg makes this explicit in its article of 15 July 2026. The registration duty under section 33 BSIG has applied continuously since 6 March 2026; since 1 August 2026 there is neither a deadline nor forbearance.

On Kleeberg's account, a breach of the registration duty remains an administrative offence punishable under section 65 BSIG with up to EUR 500,000. That figure should not be confused with the considerably higher frames in Article 34 of Directive (EU) 2022/2555: the at least EUR 10,000,000 or 2 percent of worldwide turnover for essential entities and at least EUR 7,000,000 or 1.4 percent for important entities attach, by their wording, to infringements of Articles 21 and 23 — that is, risk management and reporting. On top of that comes the personal liability of management under section 38 BSIG.

In two steps. First the sector: according to OpenKRITIS, Annex 1 of the BSIG covers energy, transport, banking and financial market infrastructure, health, water, digital infrastructure and space; Annex 2 covers postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research. Second the size: essential entities are large enterprises from Annex 1 with 250 or more employees or over EUR 50m turnover and over EUR 43m balance sheet; important entities are medium and large enterprises with 50 or more employees or over EUR 10m turnover and over EUR 10m balance sheet. Then check the size-independent special cases and the carve-outs. The BSI additionally provides its own NIS-2 applicability check.

According to the OpenKRITIS overview, financial entities under Regulation (EU) 2022/2554 are excluded via section 28(5) BSIG from core NIS2 duties, specifically sections 30, 31, 32, 35, 36, 38 and 39. For operators of critical installations in the financial sector, OpenKRITIS notes an exclusion from the reporting duty under section 32. That boundary is sector- and case-specific and belongs in a legal assessment. Practically it does not mean less work but a different supervisor and a different reporting address — the underlying capabilities are the same.

The definitive answer depends on the individual case and belongs with legal counsel. Operationally, however, the bottleneck is rarely the registration itself but the upstream ELSTER organisation certificate via the "Mein Unternehmenskonto" service, which the BSI describes as step one of the two-stage procedure. You can start that step immediately without prejudging the applicability question, documenting the self-assessment in parallel. If the assessment finds you in scope, you are ready to act; if it finds the opposite, you hold a documented negative assessment rather than a verbal one.

No, it is only the entry ticket. The OpenKRITIS duties overview lists, for essential and important entities, not just registration under sections 33 and 34 but also risk management measures under section 30, reporting obligations under section 32, customer notification duties under section 35 and management duties under section 38. These have applied since entry into force on 6 December 2025, irrespective of registration status. A registered company without documented risk management and a rehearsed reporting chain has closed the smaller sanction exposure and left the larger one open.

A dated management resolution within 24 hours, in parallel with starting the ELSTER application. The resolution acknowledges the applicability assessment, instructs immediate registration, names an accountable member of management, releases budget and sets a reporting cadence. It costs half an hour of meeting time and is the only document that, in a liability case under section 38 BSIG, evidences that management acted in a structured way from the moment it knew. Everything else — risk analysis, reporting chain, supply chain — can then be worked through in a 90-day plan.

NIS2BSIGBSIRegistrierungComplianceGeschäftsleitungshaftung

Ready for Your Assessment?

Use our interactive templates to measure your IT organization's maturity — with automatic scores, AI-powered recommendations, and professional PDF reports.