The numbers
The extended deadline for registering with Germany's Federal Office for Information Security (BSI) under NIS2 expired on 31 July 2026. According to zfk's 4 August report, more than 19,000 of roughly 29,500 in-scope entities had registered, which is about two-thirds. The BSI called that "grundsätzlich zufriedenstellend" (basically satisfactory). It also said the registration duty continues and that it reserves enforcement steps backed by fines.
The headline can be read two ways, and the choice shapes what policy should do next.
The case for a hard line
The strongest argument for strict enforcement is that registration is the foundation of the whole regime. § 33 BSIG requires particularly important and important facilities to report their name, sector, contact details, IP ranges, EU member states of operation and competent authorities. The BSI cannot push warnings, vulnerability notices or incident coordination to entities it cannot identify. A third of the estimated population is missing from that map. Attackers do not wait for a grace period, and Eurobarometer research published today found that three in four EU workers recently encountered suspicious messages at work. Regulators who let a duty go unenforced also teach companies that it is optional, and that penalises the firms that complied on time.
Why the gap is probably not defiance
The same zfk report points somewhere else. Municipal utilities and multi-sector groups are struggling with the Betroffenheitsprüfung, the test of whether and how NIS2 applies to them. The municipal utilities' association VKU named it as the main obstacle. Many utilities run electricity, gas, district heating, water, waste and telecoms services under one roof, often through several subsidiaries. Each activity can fall into a different sector annex, with different thresholds for size and classification. Many have had to hire outside counsel just to decide whether they must register.
This matters because the 29,500 figure is itself an estimate. A shortfall against an estimate mixes three groups:
- entities that are in scope and have not acted
- entities that have concluded, perhaps correctly, that they are out of scope
- entities whose legal analysis is still unfinished
The BSI's own reading, "basically satisfactory", suggests it sees a large share of the gap as the second and third groups. Treating them all as violators would be poor regulation.
Proportionality in the penalty design
The fine framework is substantial. According to zfk, penalties reach up to €10 million or 2% of global turnover, and managers carry personal liability. § 65 BSIG sets out a tiered schedule, with lower ceilings for less serious infractions such as failed notifications. That tiering is sensible in principle. Fines are a poor tool for resolving genuine legal ambiguity, though. An entity that fails to register because its group structure makes the sector classification unclear is in a different position from one that ignores the law.
The BSI's stated approach points in the right direction. It describes registration as continuing, and it frames fines as a reserve power rather than an immediate response. Enforcement should follow the same order:
- Publish sector-specific guidance for multi-sector groups. It should explain how to treat subsidiaries, shared services and mixed activities, with worked examples for municipal utilities.
- Offer a fast informal consultation channel. Entities could ask the BSI whether they are in scope without that contact being treated as an admission.
- Send reminders and documented warnings first. Fine proceedings should be reserved for entities that are plainly in scope and have ignored notice.
- Report the outcome. The BSI should say how many of the missing entities turn out to be out of scope, so the 29,500 estimate can be tested against reality.
Registration is the easy part
Zfk also notes that registration is only the first phase. Entities still have to implement technical and organisational measures, build risk management frameworks and set up a 24-hour early-warning process for significant incidents. Those are far more expensive and demanding than filling in a form. If the first, simplest step already needs outside lawyers for some organisations, regulators should expect the substantive duties to strain smaller utilities and mid-sized firms even more.
The risk is a compliance culture built around paperwork rather than security. Firms that spend their budget on legal classification memos have less left for patching, segmentation and incident drills. The Eurobarometer survey found that 60% of EU workers received cybersecurity training in the past year, yet basic cyber hygiene is still not systematic. A regime that measures itself by registration counts misses that point. The outcome that matters is fewer successful intrusions.
What to watch
The BSI holds the stronger position. A two-thirds registration rate after an extension is a workable base, and the agency has not rushed to punish. The test is whether it resolves the classification problem before it turns to sanctions. If it does, it can build the registry through cooperation and keep fines for the genuinely non-compliant. If it does not, Germany risks a stock of registered-but-unprepared entities alongside a stock of uncertain ones, with legal risk that discourages investment in actual security.
The practical standard is simple. Enforce against entities that are clearly in scope and silent, and give clear, fast answers to those who are genuinely unsure. Proportionate enforcement of that kind also supports the open, innovative digital economy that NIS2 is meant to protect.