Germany Germany BSI cybersecurity NIS2 implementation

Germany's NIS2 Registration Shortfall Shows the Real Problem Is Scope Clarity, Not Compliance Will

About 19,000 of 29,500 in-scope German entities registered under NIS2. The gap points to a confusing applicability test, not widespread defiance.

Germany's NIS2 Registration Gap People of Internet Research · Germany 19,000+ Entities registered Registered by the 31 July 2026 dea… ~29,500 Estimated in-scope entities BSI estimate of entities covered b… €10M Maximum fine ceiling Or 2% of global turnover, whicheve… peopleofinternet.com
Germany's NIS2 Registration Gap People of Internet Research · Germany 19,000+ Entities registered ~29,500 Estimated in-scope entities €10M Maximum fine ceiling peopleofinternet.com

Key Takeaways

The numbers

The extended deadline for registering with Germany's Federal Office for Information Security (BSI) under NIS2 expired on 31 July 2026. According to zfk's 4 August report, more than 19,000 of roughly 29,500 in-scope entities had registered, which is about two-thirds. The BSI called that "grundsätzlich zufriedenstellend" (basically satisfactory). It also said the registration duty continues and that it reserves enforcement steps backed by fines.

The headline can be read two ways, and the choice shapes what policy should do next.

The case for a hard line

The strongest argument for strict enforcement is that registration is the foundation of the whole regime. § 33 BSIG requires particularly important and important facilities to report their name, sector, contact details, IP ranges, EU member states of operation and competent authorities. The BSI cannot push warnings, vulnerability notices or incident coordination to entities it cannot identify. A third of the estimated population is missing from that map. Attackers do not wait for a grace period, and Eurobarometer research published today found that three in four EU workers recently encountered suspicious messages at work. Regulators who let a duty go unenforced also teach companies that it is optional, and that penalises the firms that complied on time.

Why the gap is probably not defiance

The same zfk report points somewhere else. Municipal utilities and multi-sector groups are struggling with the Betroffenheitsprüfung, the test of whether and how NIS2 applies to them. The municipal utilities' association VKU named it as the main obstacle. Many utilities run electricity, gas, district heating, water, waste and telecoms services under one roof, often through several subsidiaries. Each activity can fall into a different sector annex, with different thresholds for size and classification. Many have had to hire outside counsel just to decide whether they must register.

This matters because the 29,500 figure is itself an estimate. A shortfall against an estimate mixes three groups:

The BSI's own reading, "basically satisfactory", suggests it sees a large share of the gap as the second and third groups. Treating them all as violators would be poor regulation.

Proportionality in the penalty design

The fine framework is substantial. According to zfk, penalties reach up to €10 million or 2% of global turnover, and managers carry personal liability. § 65 BSIG sets out a tiered schedule, with lower ceilings for less serious infractions such as failed notifications. That tiering is sensible in principle. Fines are a poor tool for resolving genuine legal ambiguity, though. An entity that fails to register because its group structure makes the sector classification unclear is in a different position from one that ignores the law.

The BSI's stated approach points in the right direction. It describes registration as continuing, and it frames fines as a reserve power rather than an immediate response. Enforcement should follow the same order:

Registration is the easy part

Zfk also notes that registration is only the first phase. Entities still have to implement technical and organisational measures, build risk management frameworks and set up a 24-hour early-warning process for significant incidents. Those are far more expensive and demanding than filling in a form. If the first, simplest step already needs outside lawyers for some organisations, regulators should expect the substantive duties to strain smaller utilities and mid-sized firms even more.

The risk is a compliance culture built around paperwork rather than security. Firms that spend their budget on legal classification memos have less left for patching, segmentation and incident drills. The Eurobarometer survey found that 60% of EU workers received cybersecurity training in the past year, yet basic cyber hygiene is still not systematic. A regime that measures itself by registration counts misses that point. The outcome that matters is fewer successful intrusions.

What to watch

The BSI holds the stronger position. A two-thirds registration rate after an extension is a workable base, and the agency has not rushed to punish. The test is whether it resolves the classification problem before it turns to sanctions. If it does, it can build the registry through cooperation and keep fines for the genuinely non-compliant. If it does not, Germany risks a stock of registered-but-unprepared entities alongside a stock of uncertain ones, with legal risk that discourages investment in actual security.

The practical standard is simple. Enforce against entities that are clearly in scope and silent, and give clear, fast answers to those who are genuinely unsure. Proportionate enforcement of that kind also supports the open, innovative digital economy that NIS2 is meant to protect.

Sources & Citations

  1. zfk: NIS2 registration deadline passes, BSI threatens fines
  2. § 33 BSIG (registration duty)
  3. § 65 BSIG (administrative fines)
  4. Silicon Republic: Eurobarometer cyberthreat survey