Germany's NIS2 rollout has produced an awkward number: 39 percent. That is roughly the share of the estimated 29,500 companies and public bodies covered by the country's NIS2 Implementation Act (NIS2UmsuCG) that actually registered with the Federal Office for Information Security (BSI) by the statutory deadline of March 6, 2026. Legal advisory Kleeberg puts the figure at about 11,500 of 29,500 registered entities when the window closed, rising only to roughly 18,500 by late spring — meaning well over a third of obligated organizations remained unregistered months after the law took effect on December 6, 2025 with no transition period at all.
Faced with a compliance gap that size, the BSI did not extend the legal deadline — it cannot; only the legislature can do that. Instead it announced administrative forbearance: late registrations would be tolerated, and enforcement action withheld, through July 31, 2026. The distinction matters legally but not practically — as Kleeberg's alert stresses, "die gesetzliche Registrierungspflicht nach NIS-2" (the statutory registration duty) remained fully in force throughout the grace period. The BSI's own public tracker, "NIS-2 in Zahlen," shows 17,729 total registrations as of June 30, 2026 — split between 11,501 "important" and 6,215 "especially important" entities. Even with the extension, several thousand entities were still missing days before the new cutoff.
The case for what BSI is doing
The steelman here is straightforward. NIS2 exists because European critical infrastructure — energy grids, hospitals, water utilities, digital infrastructure, public administration — has been chronically underinvested in cybersecurity relative to the risk it carries, a gap Russian and criminal-affiliated intrusions into European utilities and health systems have repeatedly exposed. A registration regime with teeth is how a regulator finds out who it is actually responsible for supervising; you cannot audit a sector you cannot see. Given that, extending grace by less than five months rather than indefinitely, while explicitly keeping the underlying legal obligation intact, is a reasonable way to avoid punishing a rushed rollout without abandoning the deadline altogether. And the enforcement powers now coming into use — audits, fines up to €10 million or 2 percent of global turnover for "besonders wichtige Einrichtungen" under the tiered penalty schedule, and up to €7 million or 1.4 percent for "wichtige Einrichtungen" — are not arbitrary; they mirror the ceilings the EU's NIS2 Directive itself contemplated, and Germany's transposition largely tracks that framework rather than gold-plating it.
Where the design still falls short
The harder question is why compliance stalled at 39 percent for a law with zero transition period. Part of the answer is process friction that the BSI's own architecture created: registration runs through a two-step chain — first an ELSTER-based "Mein Unternehmenskonto" account, which several advisories note can take five to ten working days to issue, then a separate BSI portal that only opened on January 6, 2026, a month after the law was already binding. A company trying to comply in good faith in December 2025 had, quite literally, nowhere to register. That is a regulator-side bottleneck, not corporate foot-dragging, and it should inform how the BSI now uses its audit and fine powers.
This is where the enforcement pivot needs a proportionality filter that current reporting suggests may be missing. Personal liability for management under §38 BSIG — allowing the BSI to hold executives accountable for supervisory failures, with professional bans available for persistent non-compliance — is a serious escalation, appropriate for entities that have simply ignored the law. It is a poor fit for a mid-sized manufacturer still working through an ELSTER backlog it did not create. The €500,000 fine ceiling for registration failure alone (separate from the much larger substantive-security fines) should, in practice, be reserved for entities that ignored outreach and missed both the March and July windows, not deployed as a blunt instrument against the residual population still catching up through a process the BSI itself only fully stood up in stages.
The fix is not weaker enforcement — critical-infrastructure operators that never engage with NIS2's risk-management obligations deserve the fines the law provides for. It is enforcement that is calibrated to genuine non-compliance rather than process backlog: the BSI should be transparent about how many of the roughly 11,000 still-missing entities have at least initiated an ELSTER application, and weight early audit and fine activity toward entities showing no engagement at all. Germany's broader cybersecurity posture benefits from NIS2 landing credibly. A rollout remembered mainly for portal delays and a scramble to beat two consecutive deadlines works against that credibility more than a few extra months of good-faith tolerance would have.