Skip to main content
Back to overview

Germany's NIS2 Deadline Has Passed — and Thousands of Entities Are Still Not Registered

By NIS2Certify
NIS2GermanyBSIenforcementcompliancedeadlinecybersecurity

A letter arrives from the BSI — Germany's federal cybersecurity authority. Your company was required to register by 6 March 2026. You didn't. The BSI now has the legal authority to audit your organisation, issue binding orders and impose fines: up to €500,000 for the missed registration alone, and up to €10 million if you have not taken the required security measures. And under § 38 of the new BSIG, managing directors who neglect their duties are liable to the company for the damage.

This is not a hypothetical scenario. It is happening right now in Germany, and it is a preview of what is coming across the rest of the European Union.

What Happened on 6 March 2026

Germany's NIS2 implementation law — the NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG) — entered into force on 6 December 2025. It gave organisations in scope exactly three months to register with the BSI through its dedicated portal.

That deadline was 6 March 2026.

The BSI estimates that about 29,500 companies fall under the law. By 30 June 2026, four months after the deadline, 17,729 had registered in the BSI portal, according to the BSI's own figures. Measured against that estimate, close to 12,000 organisations are still missing: in breach of a legal obligation before they have even started working on their actual cybersecurity measures.

NIS2 transposition by country

  • AustriaIn force
    • In force since October 1, 2026
    • Act: NISG 2026 (BGBl. I Nr. 94/2025)
    • Registration due December 31, 2026

    Authority: Federal Office for Cybersecurity · Source

  • NetherlandsIn force
    • In force since August 15, 2026
    • Act: Cyberbeveiligingswet (Stb. 2026, 187)
    • Registration required, no transition period

    Authority: NCSC (MijnNCSC) · Source

  • LuxembourgIn force
    • In force since May 10, 2026
    • Act: Law of 5 May 2026
    • Registration due July 10, 2026

    Authority: ILR (CSSF for finance) · Source

  • PolandIn force
    • In force since April 3, 2026
    • Act: UKSC (Dz.U. 2026 poz. 252)
    • Registration due October 3, 2026
    • Measures due April 3, 2027

    Authority: Minister Cyfryzacji (Wykaz KSC) · Source

  • PortugalIn force
    • In force since April 3, 2026
    • Act: Decree-Law 125/2025 (RJC)

    Authority: CNCS · Source

  • BulgariaIn force
    • In force since February 13, 2026
    • Act: Cybersecurity Act amendment (State Gazette No 17/2026)

    Authority: Ministry of e-Government · Source

  • MaltaIn force
    • In force since January 23, 2026
    • Act: S.L. 460.41

    Authority: Critical Infrastructure Protection Department · Source

  • SwedenIn force
    • In force since January 15, 2026
    • Act: SFS 2025:1506

    Authority: NCSC-SE · Source

  • EstoniaIn force
    • In force since January 1, 2026
    • Act: Cybersecurity Act (KüTS) amendment
    • Registration within 3 months

    Authority: RIA · Source

  • GermanyIn force
    • In force since December 6, 2025
    • Act: NIS2UmsuCG
    • Registration due March 6, 2026
    • 17,729 registered by June 30, 2026

    Authority: BSI · Source

  • CzechiaIn force
    • In force since November 1, 2025
    • Act: Act No 264/2025 Coll.
    • Registration within 60 days

    Authority: NÚKIB · Source

  • DenmarkIn force
    • In force since July 1, 2025
    • Act: NIS 2 Act No 434 of 6 May 2025
    • Registration due October 1, 2025

    Authority: Danish Agency for Societal Security · Source

  • SloveniaIn force
    • In force since June 19, 2025
    • Act: ZInfV-1 (OG 40/25)
    • Registration within 30 days

    Authority: URSIV · Source

  • CyprusIn force
    • In force since April 25, 2025
    • Act: Law 60(I)/2025

    Authority: Digital Security Authority · Source

  • FinlandIn force
    • In force since April 8, 2025
    • Act: Cybersecurity Act 124/2025
    • Registration due May 8, 2025
    • Measures due July 8, 2025

    Authority: Traficom (NCSC-FI) · Source

  • HungaryIn force
    • In force since January 1, 2025
    • Act: Act LXIX of 2024

    Authority: SZTFH · Source

  • SlovakiaIn force
    • In force since January 1, 2025
    • Act: Act No 366/2024 Coll.
    • Registration within 60 days

    Authority: NBÚ · Source

  • RomaniaIn force
    • In force since December 31, 2024
    • Act: GEO 155/2024 (Law 124/2025)
    • Registration within 30 days

    Authority: DNSC · Source

  • GreeceIn force
    • In force since November 27, 2024
    • Act: Law 5160/2024 (Gazette A' 195)

    Authority: National Cybersecurity Authority · Source

  • BelgiumIn force
    • In force since October 18, 2024
    • Registration due March 18, 2025

    Authority: CCB · Source

  • LithuaniaIn force
    • In force since October 18, 2024
    • Act: Law No XIV-2902

    Authority: NCSC (MoND) · Source

  • ItalyIn force
    • In force since October 16, 2024
    • Act: D.Lgs. 138/2024
    • Baseline measures due by October 2026 (entities listed in 2025)

    Authority: ACN · Source

  • LatviaIn force
    • In force since September 1, 2024
    • Act: National Cybersecurity Law

    Authority: National Cybersecurity Centre · Source

  • CroatiaIn force
    • In force since February 15, 2024
    • Act: Cybersecurity Act (OG 14/2024)

    Authority: NCSC (SOA) · Source

  • FranceNot yet transposed
    • Senate adopted the law on March 12, 2025
    • Regulator published its framework on March 17, 2026
    • Referred to the Court of Justice on July 8, 2026
    • Pre-registration open

    Authority: ANSSI · Source

  • SpainNot yet transposed
    • Draft bill approved on January 14, 2025
    • Referred to the Court of Justice on July 8, 2026
    • The NIS1 regime still applies

    Authority: CCN / INCIBE · Source

  • IrelandNot yet transposed
    • Referred to the Court of Justice on July 8, 2026
    • Bill not yet enacted

    Authority: NCSC Ireland · Source

Status as of September 28, 2026. Other member states: see the country-by-country timeline.

The BSI's message to anyone still missing is blunt: the deadline has passed, so register in the BSI portal immediately. Germany is the first major EU Member State to reach this enforcement milestone — and the numbers are striking.

Why So Many Companies Missed It

Three patterns explain the gap.

Many organisations still do not know they are in scope. The NIS2 Directive applies to companies with 50 or more employees, or fewer than 50 with both annual turnover and balance sheet total above €10 million, operating in 18 designated sectors. Germany's Mittelstand — the backbone of its industrial economy — includes thousands of mid-sized manufacturers, logistics providers, and IT service companies that had never previously dealt with cybersecurity regulation.

The timeline was compressed. Three months from law to registration deadline left little room for companies that were still assessing whether NIS2 applied to them. Many were waiting for final clarity on sector classifications and thresholds.

Supply chain companies were caught off guard. Under Article 21(2)(d), NIS2 entities must manage cybersecurity risks in their supply chains. This means suppliers who are not directly in scope are receiving compliance demands from their customers — but the registration obligation applies to the NIS2 entity, not the supplier. The confusion between direct obligations and indirect supply chain pressure slowed decision-making.

What the BSI Can Do Now

The BSI's enforcement powers under the new BSIG are substantial:

Proactive audits. For essential entities — energy, transport, healthcare, digital infrastructure, banking — the BSI can conduct audits without waiting for an incident. It can request documentation, inspect security measures, and demand evidence of Article 21 compliance.

Binding orders. If the BSI identifies deficiencies, it can issue legally binding instructions to remediate within a specified timeframe. Non-compliance with a binding order escalates the severity of enforcement.

Fines. In Germany, particularly important entities face fines of up to €10 million and important entities up to €7 million (§ 65 BSIG). For a company with a total turnover above €500 million, the cap becomes 2% or 1.4% of worldwide turnover. A missed registration alone can cost up to €500,000. These are not theoretical maximums — they are the framework national authorities across the EU are now empowered to apply.

Director liability. § 38 of the BSIG requires managing directors to implement the cybersecurity risk management measures and to supervise their implementation. Directors who breach these duties are liable to their company for the damage caused. This mirrors Article 20 of the NIS2 Directive, which establishes management body accountability across all Member States.

NIS2 Penalty Escalation — Beyond the Fine

!

Trigger event

Non-Compliance Detected or Incident Occurs

A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements

Authorities can impose
▼
Non-Monetary Penalties
1

Compliance orders with binding deadlines

2

Mandatory security audits at your expense

3

Public disclosure of violations

4

Binding instructions on specific security measures

Escalates to
▼
Operational & Personal Consequences
1

Suspension of certifications or operating licences

2

Temporary ban on management functions for individuals

3

Public naming of responsible natural persons

Trigger
Non-monetary
Operational / personal

Temporary management bans. In serious cases of sustained non-compliance, the BSI can request that managing directors be temporarily suspended from their functions. This is the sharpest enforcement tool in the NIS2 toolkit and Germany has explicitly implemented it.

What This Means for the Rest of Europe

Germany is not an isolated case. It is the leading indicator.

Belgium has been enforcing its NIS2 transposition since late 2024 — the first EU country to do so. Italy (ACN) and Croatia have their frameworks in place. France (ANSSI) launched its ReCyF reference framework in March 2026 and is building its enforcement infrastructure. The Netherlands expects its Cyberbeveiligingswet (Cbw) in Q2 2026, with the RDI as supervisor.

The pattern is clear: every EU Member State is moving from legislation to enforcement. The implementation timeline varies by country, but the direction is uniform.

If Germany's experience teaches anything, it is this: the gap between "the law exists" and "companies are ready" is enormous. And regulators are not waiting for the gap to close before they start enforcing.

Does NIS2 Apply to Your Organisation?

1

Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?

Yes ↓No →
2

Does your organisation have 50 or more employees, or both an annual turnover and a balance sheet total exceeding €10 million?

Yes ↓No →
3

Is your organisation a critical infrastructure provider or a qualified trust service provider?

Yes ↓No →
✗

NIS2 does not directly apply to your organisation.

✓

NIS2 applies to your organisation as an Essential or Important Entity.

!

NIS2 may apply to your organisation — seek legal advice to confirm your status.

Applies
Possibly applies
Does not apply

What You Should Do This Week

Whether your organisation is in Germany or another EU Member State, the BSI deadline is a signal to act.

1. Determine if NIS2 applies to you. Check your employee count, turnover, and sector classification. The criteria are consistent across the EU — if you have 50 or more employees (or fewer than 50 with both annual turnover and balance sheet total above €10 million) and operate in a covered sector, you are almost certainly in scope.

2. Register with your national authority. Germany's deadline has passed, but other countries are still opening their registration portals. The Netherlands (via mijn.ncsc.nl), France (via MesServicesCyber), and Italy (via ACN) all have registration processes in place or forthcoming.

3. Start on Article 21. Registration is just the entry point. The real obligation is implementing the ten cybersecurity measures prescribed by Article 21: risk analysis, incident handling, business continuity, supply chain security, network security, vulnerability management, and more.

4. Brief your board. NIS2 is a governance obligation, not an IT project. Article 20 requires management bodies to approve cybersecurity measures and undergo training. If your board has not discussed NIS2, that conversation is overdue.

5. Assess your current position. You don't need a consultant to start. A structured readiness scan can tell you where you stand against NIS2 requirements in minutes — and show you exactly where the gaps are. Start the free NIS2 readiness scan to find out where your organisation stands today.

The Window Is Closing

Germany's unregistered companies are now learning what enforcement looks like in practice. Every other EU Member State is following the same path — the only variable is timing.

The organisations that act now, before their national deadline arrives, will have the advantage of preparation rather than the pressure of enforcement. The ones that wait will face the same situation Germany's Mittelstand is facing today: a regulator with the authority to audit, fine, and hold directors personally accountable — and a compliance programme that should have started months ago.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.