Germany Germany BSI cybersecurity NIS2 implementation

Germany Quietly Weakened Its Critical-Infrastructure Law Through a Paternity-Fraud Bill

Berlin deleted a KRITIS registration deadline via an unrelated family-law rider and denies any NIS2 registration gap despite a third of firms still missing.

Germany's Critical-Infrastructure Compliance Gap People of Internet Research · Germany 64% NIS2 companies registered 19,058 of an estimated 29,850 obli… Oct 17, 2024 Missed EU deadline Germany's legal transposition dead… ~18 months Template guidance delay Resilience-plan templates pushed f… peopleofinternet.com
Germany's Critical-Infrastructure Comp… People of Internet Research · Germany 64% NIS2 companies registered Oct 17, 2024 Missed EU deadline ~18 months Template guidance delay peopleofinternet.com

Key Takeaways

A rider, not a debate

On July 21, 2026, the Bundestag enacted the Gesetz zur besseren Verhinderung missbräuchlicher Anerkennungen der Vaterschaft — a law aimed at foreign nationals using sham paternity claims to secure residency. Published in the Bundesgesetzblatt on July 28, 2026 (BGBl. I Nr. 221), the law's stated subject matter is civil code, foreign nationals' law, and civil-status registration. Buried inside it, as Article 8 and Article 9, are amendments to the KRITIS-Dachgesetz (the critical-infrastructure resilience law implementing the EU's CER Directive) and the BSI-Gesetz (which implements the NIS2 cybersecurity directive) — confirmed by the official gazette entry itself, which lists "öffentliche Informationstechnik" among the law's covered domains (recht.bund.de).

There is a legitimate case for consolidating legislation: Germany's parliamentary calendar is congested, and omnibus riders attached to interior-committee bills are not unusual in the Bundestag. If the substance of the KRITIS changes were minor housekeeping, folding them into a passing vehicle would be unremarkable. It is the substance, not the vehicle, that should trouble anyone who cares about critical-infrastructure resilience.

What actually changed

The amendments did two concrete things. First, they deleted — with no replacement — the requirement that critical-infrastructure operators register with the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe (BBK) via a joint BSI portal by July 17, 2026. That deadline simply no longer exists in the statute. Second, they pushed back the BBK's obligation to publish templates and sample resilience plans: the consolidated text now requires publication only "spätestens acht Monate nach Inkrafttreten der Rechtsverordnung" — eight months after the implementing KRITIS-Verordnung takes effect (gesetze-im-internet.de) — rather than the fixed January 17, 2026 date in the original law. With that regulation not expected until autumn 2026, operators realistically will not see official guidance until mid-2027 (Born, Aug 24, 2026).

Germany already missed the EU's October 17, 2024 deadline to transpose both the CER and NIS2 directives, drawing a formal notice from the European Commission on November 28, 2024 alongside 22 other laggard member states (European Commission). Deleting a registration deadline rather than replacing it with a workable one does not close that compliance gap — it re-opens it, on a law that was already more than a year and a half late.

The NIS2 numbers Berlin says aren't a problem

The KRITIS amendment landed alongside a separate, harder-to-spin admission. Germany's BSI-Gesetz (in force since December 6, 2025) gave companies until March 6, 2026 to register as NIS2-obligated entities; compliance was so poor that BSI quietly extended the practical deadline to July 31, 2026. By July 1, 2026, only 19,058 companies had registered against an estimate of 29,850 obligated firms — roughly 64%, meaning more than 10,000 entities providing what the law defines as essential or important services had not identified themselves to the country's cybersecurity regulator.

On August 11, 2026, the federal government's response was that there is no registration gap at all: the 29,850 figure, it noted, was only a Federal Statistical Office projection built on 2019–2022 economic data, so the shortfall against it is not meaningful (Born, Aug 24, 2026). That is a fair technical point — old census-style projections are blunt instruments, and treating them as a hard denominator does overstate the shortfall's precision. But the government cannot have it both ways: if the estimate is too unreliable to establish a gap, it was also too unreliable to justify the enforcement posture built around it, and BSI's own decision to grant a four-month informal extension is itself an admission that registrations were running behind whatever the true number is.

Why the bundling matters more than either change alone

Each individual change might be defensible in isolation. Delaying a template guidance document by months is not a security catastrophe if operators already have the underlying legal obligations. Correcting an overstated compliance denominator is honest, not evasive, if the correction is transparent. What is not defensible is doing both through a rider on a bill about paternity fraud, where the interior committee — not the digital or economic committees ordinarily seized of BSI matters — made the changes with minimal public debate. Critical-infrastructure operators, auditors, and the Bundesrat itself learned about a deleted statutory deadline only after the fact, from investigative reporting rather than a dedicated legislative process.

Germany does not need less cybersecurity regulation, and it does not need more of it bolted onto unrelated bills either. A NIS2 and KRITIS regime that is proportionate and workable for the roughly 30,000 firms it touches requires stable deadlines set and changed in the open, not deleted in a rider whose header reads like family law. If Berlin believes its resilience-planning timeline needs recalibrating, or its registration estimates need revising, it should say so through the ordinary legislative process for cybersecurity law — not through the paternity registry.

Sources & Citations

  1. Bundesgesetzblatt I Nr. 221 (recht.bund.de)
  2. KRITIS-Dachgesetz consolidated text (gesetze-im-internet.de)
  3. European Commission, NIS2 transposition infringement notice
  4. Born IT- und Windows-Blog, Aug 24 2026
  5. Born IT- und Windows-Blog, Jul 30 2026