Germany's critical-infrastructure operators just lived through a second registration deadline in four months, and this time it wasn't cybersecurity. On July 17, 2026, the deadline passed for roughly 1,300 operators across eleven sectors — energy, transport, finance, health, water, wastewater, food, IT and telecoms, space, municipal waste, and public administration — to register with the Federal Office for Civil Protection and Disaster Assistance (BBK) under the KRITIS-Dachgesetz, which entered into force on March 17, 2026 (BBK; ad-hoc-news).
That deadline sits four months behind a nearly identical one for a completely different agency. Germany's NIS2 Implementation Act (NIS2UmsuCG), which folded new cybersecurity obligations into the BSI Act, took effect December 6, 2025 with no transition period, covering roughly 29,500 companies — almost seven times the 4,500 firms previously captured by the old KRITIS regime. Registration with the Federal Office for Information Security (BSI) opened January 6, 2026 and was due March 6, 2026 (BSI press release).
Two directives, two agencies, two portals
The split is not accidental. The KRITIS-Dachgesetz transposes the EU's Critical Entities Resilience (CER) Directive (2022/2557), which governs physical resilience — facility hardening, personnel vetting, all-hazards risk planning. NIS2 (Directive 2022/2555) governs cyber resilience — incident reporting, IT risk management, supply-chain security. Brussels wrote these as separate instruments with separate competent-authority models, and Germany mapped that split onto its existing institutions: BBK, historically a civil-protection agency, absorbed the physical-resilience brief; BSI, the country's cyber agency, kept the digital one. As law firm analysis of the rollout notes, entities that sit at the intersection — an energy grid operator, a hospital network, a water utility — now register twice, with two agencies, on two timelines, under two different definitions of what counts as "critical" (Jones Day).
There's a real case for this. Physical resilience and cyber resilience require genuinely different expertise — building-hardening standards and incident-response playbooks aren't produced by the same skill set, and folding both into one mega-regulator risks diluting both. BBK and BSI each bring institutional depth the other lacks; a merged agency starting from scratch might have taken even longer than the 17 months Germany needed to pass CER transposition after missing the EU's October 17, 2024 deadline for both directives.
But the compliance numbers are the tell
The steelman gets harder to sustain once you look at how NIS2 registration actually went. By the original March 6, 2026 deadline, only around 11,500 of the roughly 29,500 covered entities — about 39% — had registered in the BSI portal. Facing a two-thirds shortfall, BSI quietly signaled an informal grace period to industry associations, allowing late registration through July 31, 2026, the same week the KRITIS deadline fell (borncity.com).
A 39% on-time compliance rate for a single regime, with fines of up to €10 million or 2% of global turnover on the table for the most serious entities, is not a story about apathetic companies — it's a story about a compliance architecture that firms are struggling to even locate, let alone satisfy. Layering a second registration process, with its own portal, its own nine-month risk-analysis clock and ten-month resilience-plan deadline, and its own €500,000 penalty ceiling, onto operators who are still catching up on the first one is exactly the kind of proportionality failure this publication has flagged before in EU-derived compliance regimes: the substance of both directives is defensible, but the administrative multiplication is not free, and the people who pay for it are mid-sized utilities and hospital operators without in-house compliance departments, not the large industrials who can absorb it.
The fix is coordination, not consolidation
Germany doesn't need to merge BBK and BSI to fix this. What it needs — and what neither the KRITIS-Dachgesetz nor the NIS2UmsuCG currently provides — is a single intake mechanism for operators subject to both regimes: one registration touchpoint that routes data to both agencies, harmonized risk-analysis templates instead of two parallel ones, and a shared incident-reporting clock instead of two 24-hour windows running on different definitions of a reportable event. The EU itself anticipated this tension; CER and NIS2 both invoke cross-referencing obligations for competent authorities. Germany has so far implemented the letter of that requirement without the practical plumbing. Until it does, the 39% NIS2 registration rate is a preview of what dual-track KRITIS compliance will look like a year from now — not because operators don't take the rules seriously, but because no operator has infinite capacity to fill out the same risk assessment twice for two different government offices.