nexalign
← Alle Insights
Regulatorik·6 min read

NIS2 registration: the BSI catch-up date is 31 July 2026

Of roughly 29,500 entities in scope in Germany, only about half had registered with the BSI by the end of May 2026. On 12 June 2026 the BSI told industry associations that it expects the outstanding registrations by 31 July 2026. The important nuance: this is enforcement discretion, not an extension. The statutory deadline expired on 6 March 2026.

The timeline, kept separate

17 October 2024: EU deadline for national transposition of Directive (EU) 2022/2555. Germany missed it; the Commission opened infringement proceedings in November 2024.

6 December 2025: the NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG) enters into force.

6 March 2026: end of the statutory deadline for entities in scope to register with the BSI (three months after entry into force).

31 July 2026: the date by which the BSI expects outstanding registrations. Administrative forbearance, not a new legal position. Registering now still means the statutory deadline was missed, but it avoids the appearance of persistent refusal.

Self-identification is the real hurdle

NIS2 has no official scoping decision. Every entity must assess for itself whether it falls in scope and register accordingly. Never having done the assessment is not an excuse.

The test has two steps: does the activity fall under one of the 18 sectors in Annex I or II, and are the size thresholds met (from 50 employees or EUR 10 million turnover: important entity; from 250 employees or EUR 50 million turnover: essential entity).

Frequently missed: corporate groups. For linked enterprises, headcount and turnover are aggregated following the SME recommendation. A small subsidiary inside a group can become an entity in scope that way.

Also frequently missed: ICT service providers and managed service providers are in scope as their own category, regardless of whether their customers are.

What applies the moment you are in scope

Reporting on the 24/72/one-month pattern: early warning within 24 hours of becoming aware of a significant incident, incident notification with an initial assessment within 72 hours, final report within one month.

The ten minimum measures under Article 21: risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and maintenance, effectiveness review, cyber hygiene and training, cryptography, personnel security and access control, multi-factor authentication.

There is no grace period for the Article 21 measures. They apply with scope, not with registration.

Management body liability, the underestimated part

Article 20 of the directive requires the management body to approve the risk-management measures, oversee their implementation and undergo training itself. That is a personal duty, not a delegable technical task.

In German law this sits alongside the general duties of care under sec. 93 AktG and sec. 43 GmbHG. A missing registration and a missing documented board deliberation are two separate allegations in a liability case.

Penalties: up to EUR 10 million or 2 percent of global annual turnover for essential entities, up to EUR 7 million or 1.4 percent for important entities, plus suspension of certifications and, in severe cases, a temporary management ban for responsible individuals.

What to do this week

1. Run the scoping assessment and document the result, including a negative one. The documentation is the evidence that the assessment happened.

2. If in scope, register in the BSI reporting and registration portal immediately. Required: legal entity, address, sector, contact points, IP ranges and the member states where services are provided.

3. Define the reporting chain before the first incident: who detects, who decides, who notifies, who deputises. 24 hours is very short on a Friday evening.

4. Obtain and minute a management body decision on the cyber risk strategy, including evidence of training.

5. Capture the gaps against the ten measures with an owner and a date. A documented plan with open gaps is far stronger in front of a supervisor than an unevidenced claim of compliance.

Sources

Directive (EU) 2022/2555 (NIS2). NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), in force since 6 December 2025. BSI letter to industry associations dated 12 June 2026 on the expected catch-up of registrations by 31 July 2026. The figure of roughly 29,500 entities in scope and the registration status of about half by the end of May 2026 come from BSI communications and subsequent reporting.