The BSI's informal grace period for NIS2 registration ended on 31 July 2026. According to zfk, more than 19,000 of an estimated 29,500 in-scope German entities had registered by then. The agency called that volume "fundamentally satisfactory" but reserved the right to take fines-based measures. Roughly a third of the target population is still missing, and the enforcement debate now begins.
What the numbers say
The statutory deadline was 6 March 2026, three months after the implementation law took effect, as § 33 BSIG requires. By that date only about 11,500 entities had registered, according to BornCity's summary of BSI figures. About 18,500 had registered by the end of May. The grace period therefore added roughly 7,500 registrations over five months. Reported counts differ slightly by source (one puts the total at 18,845), so treat all of these as approximate.
The grace period was forbearance, not a legal extension. The statutory obligation never lapsed, so every unregistered in-scope entity has been technically non-compliant since March.
The strongest case for enforcing now
The case for fines is serious. A registry is the foundation of supervision: the BSI cannot warn, audit or coordinate incident response with entities it cannot see. Voluntary compliance also collapses if the deadline is visibly optional, since the firms that registered on time bore real costs and would reasonably resent free-riders. Germany was also late transposing the directive, and a soft start prolongs the exposure of essential services.
Correcting the headline penalty
Much coverage repeats "up to €10 million or 2% of turnover" as if it applied to the registration gap. It does not. Under § 65 BSIG, failure to transmit registration information under § 33 falls in the tier capped at €500,000. The €10 million (or 2% of global turnover) ceiling for particularly important entities, and €7 million for important entities, applies to breaches of other provisions such as risk-management and reporting duties.
The distinction matters. A firm reading the headline figure might either panic or dismiss the whole regime as implausible. The accurate message is narrower: registration is a low-cost administrative duty with a moderate, bounded penalty. It is the door to a much heavier set of obligations.
Manager liability is similarly often overstated. § 38 BSIG requires management to approve and oversee risk-management measures and to complete training. It makes managers liable to their own company for damage caused by negligent breach, under corporate-law rules. It does not create a direct administrative fine on individuals.
Why the gap is a scoping problem
The evidence points to confusion, not evasion. The Association of Municipal Enterprises (VKU) told zfk that the difficulty of assessing whether a firm is affected, especially multi-sector municipal utilities, was in its view the main reason registrations were hesitant. NIS2's sector lists, size thresholds and group-structure rules are complicated enough that competent firms in good faith cannot tell whether they are "important" or "particularly important" entities.
The estimate of 29,500 is itself a Destatis-based projection, not a census. Some unregistered entities may not be in scope at all. Fining them would penalise firms for failing to solve a classification puzzle the state itself has not resolved cleanly.
A proportionate enforcement path
Proportionate regulation does not mean no enforcement. It means sequencing sanctions to match culpability. We would suggest four steps:
- Publish scoping tools first. A free, authoritative self-assessment from the BSI, with binding guidance on multi-sector and group cases, removes the main excuse before penalties begin.
- Send notices before fines. Use the BSI's existing power to request information and to register entities itself to contact firms it can identify from sector registries, giving a short cure period.
- Reserve fines for the knowing. Target entities that were plainly in scope, were notified, and did not respond, so the deterrent lands where deliberate non-compliance sits.
- Do not let registration crowd out substance. Security value comes from risk management, incident handling and supply-chain diligence. A perfect registry of firms with weak controls buys little.
The risk of a blunt approach is real. Small and mid-sized firms, including municipal utilities, manufacturers and software suppliers, bear compliance costs that large groups absorb easily. An enforcement wave aimed at paperwork failures would raise the fixed cost of operating in Germany without measurably improving resilience against threats like the state-linked campaigns currently documented by The Record.
What to watch
The BSI's next move will show whether it treats registration as a supervisory tool or a revenue and headline instrument. If it publishes scoping guidance and staged notices, the roughly 10,000 missing entities will probably shrink quickly. If it opens with fines, expect litigation over classification and more firms treating NIS2 as something to contest rather than absorb. A regulator that wants a working registry should make it easy to join and reserve its penalties for those who refuse.