Germany Germany BSI cybersecurity NIS2 implementation

Germany's NIS2 Rollout Shows the Cost of Registration Without a Legal Deadline to Enforce It

BSI's July 31 letter to industry pressed 29,500 firms to register under the new BSIG, but only ~64% complied — exposing a gap between statute and enforcement.

Germany's NIS2 Registration Gap People of Internet Research · Germany ~29,500 Entities required to register Federal Statistical Office project… ~39% Registered by original deadline About 11,500 of 29,500 had registe… 18,845 Registered by extended deadline 6,490 "particularly important" and… €500,000 Max fine for non-registration Standalone penalty under § 65 BSIG… peopleofinternet.com
Germany's NIS2 Registration Gap People of Internet Research · Germany ~29,500 Entities required to register ~39% Registered by original deadline 18,845 Registered by extended deadline €500,000 Max fine for non-registration peopleofinternet.com

Key Takeaways

A deadline with no formal teeth, and a compliance gap it couldn't close

Germany's Federal Office for Information Security (BSI) has spent 2026 trying to solve a problem the NIS2 Implementation Act (NIS2UmsuCG) created for itself: a statutory registration deadline that came and went with barely a third of affected companies compliant. The law, which entered into force on 6 December 2025 and transposed the EU's NIS2 directive into the new Federal Office for Information Security Act (BSIG), gave roughly 29,500 companies and public bodies three months — until 6 March 2026 — to register as regulated entities with the BSI (BSI press release, 1 June 2026). By that deadline, only around 11,500 had done so — roughly 39% (Locate Risk).

Rather than open with enforcement, the BSI opened with a letter. On 12 June 2026 it wrote to German industry associations stating it "expects" every still-unregistered entity to complete registration by 31 July 2026 — a date the agency itself describes as an administrative expectation, not a new statutory deadline (BDO). That distinction matters: the legal obligation to register lapsed in March, and every day since has technically been a fineable violation. The July letter was a grace period offered informally, by an agency that lacks the statutory authority to simply move its own deadline.

The numbers the BSI didn't want

The grace period produced improvement, not resolution. By the extended date, 18,845 entities — 6,490 "particularly important" facilities and 12,355 "important" ones — had registered, per BSI figures reported by heise online (heise, "Riddle about missing NIS2 registrations"). That's about 64% of the projected 29,500 — a projection the federal government itself derived from a Federal Statistical Office estimate when the implementing law passed. Whether the remaining roughly 10,600 entities are still working through registration, have concluded (rightly or wrongly) that NIS2 doesn't apply to them, or are simply ignoring the law is, per heise's framing, genuinely unclear even to the BSI. That ambiguity is itself a data point: a regulator four months past its own compliance deadline still can't say with confidence who in its regulated population exists.

What's actually at stake for stragglers

Germany's BSIG, unlike many national NIS2 transpositions, treats registration failure as its own distinct offense — separate from, and smaller than, the penalties for substantive cybersecurity failures. Under § 65 BSIG, failing to submit required registration information (§ 33) is punishable by a fine of up to €500,000, addressed to the entity rather than to individual managers (§ 65 BSIG, gesetze-im-internet.de). That sits well below the headline numbers for risk-management or incident-reporting violations, which reach €10 million or 2% of global annual turnover for "particularly important" facilities and €7 million or 1.4% for "important" ones. Company leadership additionally carries internal liability under § 38 BSIG for culpable breaches of duty, even though the § 65 fine itself lands on the organization.

The two-tier structure is a sensible piece of proportionate design: it lets the BSI treat an administrative lapse (not filing a form) differently from a substantive one (running unpatched, unmonitored critical infrastructure). That's the right instinct, and one worth crediting the German legislature for building in rather than lumping every NIS2 failure into a single maximal fine bracket.

Steelmanning the BSI's approach — and where it still falls short

The case for the BSI's soft-landing strategy is real. NIS2's scope-determination exercise is genuinely difficult — the directive pulls in mid-sized manufacturers, logistics firms, and food producers that have never before had a cybersecurity regulator, and getting that self-assessment wrong in either direction has consequences. The BSI has acknowledged as much, telling associations it expects registration within six weeks of any open interpretive question being resolved, and it has so far prioritized awareness campaigns and on-site guidance over fines (Security Today, 20 March 2026). A regulator standing up an entirely new compliance regime for 29,500 entities in under a year, without a mass wave of punitive fines against confused first-time filers, is not obviously wrong to prioritize onboarding over enforcement.

But proportionality cuts both ways. An informal letter with no legal force, sent three months after the actual deadline lapsed, signals to the remaining third of obligated entities that the March deadline was soft — which is precisely the incentive structure that produces a second missed deadline. If the BSI wants voluntary compliance to keep working, the smarter fix isn't harsher fines; it's giving the registration deadline itself statutory flexibility (a formal extension mechanism, tied to genuine interpretive uncertainty) rather than running an unofficial grace period that undermines the credibility of the law's own timeline. Germany got the tiered-penalty design right. It has not yet gotten the deadline-credibility problem right, and until it does, this cycle will repeat with every future compliance milestone NIS2 sets.

Sources & Citations

  1. BSI: NIS-2 registration portal press release (1 June 2026)
  2. § 65 BSIG — administrative fine provisions
  3. BSI: NIS-2 obligations overview
  4. heise online: Riddle about missing NIS2 registrations
  5. BDO: BSI expects outstanding registrations by end of July 2026
  6. Security Today: Missed NIS2 registration deadline checklist