Germany Germany BSI cybersecurity NIS2 implementation

Berlin's NIS2 Grace Period Is an Admission That Its Own Rollout Failed First

BSI gave firms until July 31 to register under NIS2 after Germany itself took 13 months longer than the EU deadline to pass the law.

Germany's NIS2 Registration Gap People of Internet Research · Germany ~30,000 Entities in scope German organizations across 18 sec… ~18,500 Registered by end of May Still short of full compliance mon… €500,000 Late-registration fine exposure Maximum penalty under §65 BSIG for… 13+ months Germany's own transposition delay Time between the EU's Oct 17, 2024… peopleofinternet.com
Germany's NIS2 Registration Gap People of Internet Research · Germany ~30,000 Entities in scope ~18,500 Registered by end of May €500,000 Late-registration fine exposure 13+ months Germany's own transposition de… peopleofinternet.com

Key Takeaways

A deadline that wasn't really a deadline

Germany's Federal Office for Information Security (BSI) has spent the summer quietly rewriting its own enforcement calendar. The statutory registration deadline under the NIS2UmsuCG — the law transposing the EU's NIS2 cybersecurity directive — expired on March 6, 2026, three months after the act entered into force on December 6, 2025. By the BSI's own account, in a letter to industry associations obtained by heise online, only a fraction of the roughly 30,000 in-scope entities had registered on time. By the end of May, about 18,500 facilities had signed up — leaving well over 10,000 organizations still outside the system months after the legal cutoff, according to industry estimates compiled by compliance advisory LocateRisk.

Rather than trigger the enforcement machinery §65 BSIG provides for — fines of up to €500,000 for a missed registration alone, rising to €10 million or 2% of global turnover for deeper compliance failures — BSI told the associations it now "assumes" all outstanding registrations will be complete by July 31, 2026. Heise's reporting is explicit that this is not a new statutory deadline: it is administrative forbearance, a decision by the regulator to hold its fire while it waits for the backlog to clear.

The steelman: a regulator managing a real gap sensibly

BSI's approach deserves credit before it draws criticism. Germany's Federal Office for Information Security has a genuinely difficult scoping problem: roughly 30,000 entities across 18 sectors, many of them mid-sized firms with no prior cybersecurity compliance function, were asked to self-identify as in-scope and register through a new portal within three months of a law most of them had barely heard of. A regulator that immediately opened 10,000+ enforcement files — rather than using discretion under its existing statutory tools — would have converted a rollout problem into a litigation crisis, diverting BSI's own limited supervisory capacity away from the higher-risk entities NIS2 actually exists to protect. Communicating a clear, public expectation to industry associations, rather than acting unpredictably case by case, is exactly the kind of proportionate signaling that good regulators use to convert non-compliance into compliance without needless punishment. That is a defensible use of prosecutorial discretion, not a failure of nerve.

Why the sequencing still matters

The steelman doesn't fully answer the sequencing problem, though. Germany missed the EU's own NIS2 transposition deadline of October 17, 2024 by more than a year — the European Commission opened an infringement procedure against Germany and 22 other member states on November 28, 2024, and the NIS2UmsuCG did not clear the Bundestag until the collapse of the previous coalition and a fresh legislative push produced a law that entered into force only on December 6, 2025. The government that is now signaling patience toward industry was, on the same compliance clock, over a year late itself.

That asymmetry is the real story here, not the three-week news cycle around a letter to trade groups. A regulator that took 13 months longer than its own EU-mandated deadline to write the rules is on thin ground demanding strict, court-enforceable adherence to a three-month registration window from the businesses those rules bind — while simultaneously holding a €500,000 fine in reserve as the stated consequence for missing it. BSI's own registration portal page now simply states that the statutory deadline has passed and urges immediate registration — with no acknowledgment on the page itself that enforcement is currently paused by informal agreement rather than by law.

The proportionate fix is legislative, not discretionary

The better remedy isn't a quiet letter to associations that leaves the formal fine exposure technically intact for anyone unlucky enough to draw scrutiny before July 31. It's a published, legally binding grace period — an actual statutory instrument, not prosecutorial mood music — paired with a tiered compliance ramp that treats first-time registration lapses differently from substantive risk-management failures. Discretion exercised informally creates exactly the kind of legal uncertainty NIS2 was meant to reduce: firms cannot rely on a letter to trade associations the way they can rely on a gazetted rule, and a change in BSI leadership or political pressure could reactivate the €500,000 exposure for anyone still unregistered on August 1 with no further notice.

Germany's overall direction on NIS2 — mandatory registration, tiered risk-management duties, incident reporting — is a reasonable and proportionate response to a genuine rise in nation-state and criminal targeting of critical infrastructure operators. But regulators asking industry to internalize compliance discipline should hold themselves to the same standard of punctual, transparent process. A government thirteen months behind its own deadline granting itself informal discretion over everyone else's is not a confidence-building precedent for the rest of NIS2's implementation across the EU's 27 member states, several of which are watching Berlin's rollout as a template.

Sources & Citations

  1. BSI — NIS-2-regulierte Unternehmen
  2. European Commission — infringement notice on NIS2 transposition
  3. heise online — NIS2 reminder, BSI sets new deadline
  4. LocateRisk — NIS2 BSI registration deadline analysis