Germany Germany BSI cybersecurity NIS2 implementation

BSI's Soft Deadline on NIS2 Registration Shows Germany Built Enforcement Before It Built Clarity

With two-thirds of covered firms unregistered past the statutory deadline, BSI's grace period admits the rollout outpaced businesses' ability to comply.

Germany's NIS2 Registration Gap People of Internet Research · Germany ~29,500 Entities covered by NIS2 BSI's own estimate of affected com… ~11,500 Registered by statutory deadline Registrations as of the March 6, 2… 19,058 Registered by July 31 soft deadline Total registrations after BSI's in… Up to €500K Fine for registration failure alone Penalty under §65 BSIG, separate f… peopleofinternet.com
Germany's NIS2 Registration Gap People of Internet Research · Germany ~29,500 Entities covered by NIS2 ~11,500 Registered by statutory deadli… 19,058 Registered by July 31 soft dea… Up to €500K Fine for registration fai… peopleofinternet.com

Key Takeaways

Germany's Federal Office for Information Security (BSI) sent a letter to industry associations on June 12, 2026, asking them to remind members that outstanding NIS2 registrations should be completed by July 31, 2026. The letter was explicit that this was not a legal extension: the statutory registration deadline of March 6, 2026, set under §33 BSIG, had already passed, and fines have technically been possible since that date. BSI simply signaled that it would treat July 31 as the point past which its patience — and its enforcement discretion — runs out.

The numbers explain why BSI felt compelled to write the letter. Of the roughly 29,500 entities BSI itself estimated fall under the NIS2 Implementation Act (NIS2UmsuCG), which entered into force December 6, 2025, only about 11,500 had registered by the March deadline — well under half. By the end of May the figure had crept to roughly 18,500. By the July 31 soft deadline, registrations reached 19,058, meaning close to 10,000 covered entities remained unregistered even after BSI's public prodding.

Steelmanning BSI's approach

Before critiquing the leniency, it's worth taking BSI's own justification seriously. The agency acknowledged in its letter that "in individual cases, unresolved questions can lead to further delay in registration" — a reference to the genuinely difficult scoping exercise NIS2 imposes. Determining whether a mid-sized manufacturer, hospital network, or logistics firm counts as a "particularly important" or "important" entity requires threading together sector annexes, headcount and revenue thresholds, and supply-chain classifications that even specialist law firms describe as unsettled. A regulator that fined tens of thousands of confused-but-good-faith companies on day one of a brand-new, EU-wide compliance regime would be optimizing for headlines over actual security uptake. Registration data quality also matters more than registration speed: a rushed, wrong submission is arguably worse than a late, accurate one, since BSI uses the registry to route incident-reporting obligations and prioritize supervisory attention. Giving firms room to get the classification right, rather than filing defensively, is a defensible regulatory instinct.

Where the leniency argument runs out

But the scale of the shortfall — two-thirds of covered entities still missing three months after the statutory deadline, and roughly a third still missing five months after — is not a story about a handful of edge cases. It's a story about a compliance timeline that never matched institutional and market reality. NIS2UmsuCG gave entities exactly three months from the law's entry into force to register, with no phase-in by sector or company size. That is an aggressive runway for a regime affecting companies with 50+ employees or over €10 million in revenue across 18 sectors — many of which, unlike traditional KRITIS operators, have never had a cybersecurity regulator to report to before. Security researchers Dennis-Kenji Kipker and Stefan Hessel have publicly criticized BSI's soft-touch approach as insufficiently "determined," arguing that a regulator which keeps moving the informal goalpost teaches regulated industry that deadlines are negotiable — undermining the credibility of the next one.

Both critiques can be true at once, and that's the actual policy failure here: Germany wrote a statute with a hard three-month clock and essentially no capacity buffer, then discovered — as the numbers rolled in — that it had to choose between mass non-enforcement or punishing good-faith confusion at scale. BSI chose the former, correctly, but only after the statutory deadline had already lapsed and firms had already spent months exposed to a €500,000 fine merely for failing to register, separate from the much larger penalties (up to €10 million or 2% of global turnover for "particularly important" entities, up to €7 million or 1.4% for "important" ones) that attach to substantive risk-management failures.

What proportionate implementation would have looked like

A better-designed rollout would have built the grace period into the statute from the start — a staggered registration window by sector or entity size, similar to how several other EU member states phased their NIS2 transpositions — rather than forcing the regulator to improvise an unofficial extension through a trade-association letter five months after the fact. That approach gives businesses predictability without gutting deterrence: firms would know upfront, in writing, exactly how much runway they have and exactly when the clock starts counting against them, rather than discovering after the fact that the "real" deadline is whatever BSI decides to tolerate this quarter.

The stakes are not abstract. NIS2 exists to close a well-documented resilience gap — Germany's own KRITIS sector has weathered ransomware and state-linked intrusions in recent years, and the registration database is what lets BSI route incident reports and target supervisory attention where it's needed. A registry that's one-third empty limits exactly that visibility. Germany does need the underlying policy; what it lacked was an implementation clock calibrated to the compliance burden it created. As enforcement now shifts to the roughly 10,000 firms still outside the system past July 31, BSI would do well to signal clearly and in advance rather than repeat the ad hoc extension — proportionality is not just about penalty size, it's about giving regulated parties a deadline they can actually trust.

Sources & Citations

  1. §33 BSIG — Registration Obligation (gesetze-im-internet.de)
  2. BSI Press Release — NIS-2 Portal Launch
  3. heise online — NIS2 Registration Deadline Expires March 6, 2026
  4. borncity.com — BSI Sets Final Deadline for 29,000 Firms
  5. BDO — BSI Expects Outstanding Registrations by End of July 2026