Germany Germany BSI cybersecurity NIS2 implementation

Germany's NIS2 Registration Gap Is a Scoping Problem, Not Defiance, and Fines Would Punish the Wrong Thing

About 10,000 of 29,500 in-scope German entities are unregistered after the BSI grace period. The €500,000 fine ceiling, not the headline €10M, is what applies.

Germany's NIS2 Registration Gap People of Internet Research · Germany 19,000+ Registered by July 31 Of an estimated 29,500 in-scope en… ~11,500 Registered by March deadline Statutory deadline was 6 March 202… €500,000 Max fine: not registering Cap for § 33 violations under § 65… peopleofinternet.com
Germany's NIS2 Registration Gap People of Internet Research · Germany 19,000+ Registered by July 31 ~11,500 Registered by March deadline €500,000 Max fine: not registering peopleofinternet.com

Key Takeaways

The BSI's informal grace period for NIS2 registration ended on 31 July 2026. According to zfk, more than 19,000 of an estimated 29,500 in-scope German entities had registered by then. The agency called that volume "fundamentally satisfactory" but reserved the right to take fines-based measures. Roughly a third of the target population is still missing, and the enforcement debate now begins.

What the numbers say

The statutory deadline was 6 March 2026, three months after the implementation law took effect, as § 33 BSIG requires. By that date only about 11,500 entities had registered, according to BornCity's summary of BSI figures. About 18,500 had registered by the end of May. The grace period therefore added roughly 7,500 registrations over five months. Reported counts differ slightly by source (one puts the total at 18,845), so treat all of these as approximate.

The grace period was forbearance, not a legal extension. The statutory obligation never lapsed, so every unregistered in-scope entity has been technically non-compliant since March.

The strongest case for enforcing now

The case for fines is serious. A registry is the foundation of supervision: the BSI cannot warn, audit or coordinate incident response with entities it cannot see. Voluntary compliance also collapses if the deadline is visibly optional, since the firms that registered on time bore real costs and would reasonably resent free-riders. Germany was also late transposing the directive, and a soft start prolongs the exposure of essential services.

Correcting the headline penalty

Much coverage repeats "up to €10 million or 2% of turnover" as if it applied to the registration gap. It does not. Under § 65 BSIG, failure to transmit registration information under § 33 falls in the tier capped at €500,000. The €10 million (or 2% of global turnover) ceiling for particularly important entities, and €7 million for important entities, applies to breaches of other provisions such as risk-management and reporting duties.

The distinction matters. A firm reading the headline figure might either panic or dismiss the whole regime as implausible. The accurate message is narrower: registration is a low-cost administrative duty with a moderate, bounded penalty. It is the door to a much heavier set of obligations.

Manager liability is similarly often overstated. § 38 BSIG requires management to approve and oversee risk-management measures and to complete training. It makes managers liable to their own company for damage caused by negligent breach, under corporate-law rules. It does not create a direct administrative fine on individuals.

Why the gap is a scoping problem

The evidence points to confusion, not evasion. The Association of Municipal Enterprises (VKU) told zfk that the difficulty of assessing whether a firm is affected, especially multi-sector municipal utilities, was in its view the main reason registrations were hesitant. NIS2's sector lists, size thresholds and group-structure rules are complicated enough that competent firms in good faith cannot tell whether they are "important" or "particularly important" entities.

The estimate of 29,500 is itself a Destatis-based projection, not a census. Some unregistered entities may not be in scope at all. Fining them would penalise firms for failing to solve a classification puzzle the state itself has not resolved cleanly.

A proportionate enforcement path

Proportionate regulation does not mean no enforcement. It means sequencing sanctions to match culpability. We would suggest four steps:

The risk of a blunt approach is real. Small and mid-sized firms, including municipal utilities, manufacturers and software suppliers, bear compliance costs that large groups absorb easily. An enforcement wave aimed at paperwork failures would raise the fixed cost of operating in Germany without measurably improving resilience against threats like the state-linked campaigns currently documented by The Record.

What to watch

The BSI's next move will show whether it treats registration as a supervisory tool or a revenue and headline instrument. If it publishes scoping guidance and staged notices, the roughly 10,000 missing entities will probably shrink quickly. If it opens with fines, expect litigation over classification and more firms treating NIS2 as something to contest rather than absorb. A regulator that wants a working registry should make it easy to join and reserve its penalties for those who refuse.

Sources & Citations

  1. § 65 BSIG (fine tiers)
  2. § 38 BSIG (management duties and liability)
  3. zfk: NIS2 grace period expired
  4. BornCity: BSI sets last deadline
  5. The Record: WaterPlum campaign