The NIS-2 implementation act (NIS2UmsuCG) has been in force since December 6, 2025. The statutory registration deadline with the BSI expired on March 6, 2026. And the BSI had communicated that it expected the registration of affected companies to be complete by July 31, 2026 – that deadline has just passed.
An important clarification: July 31 is not a new statutory deadline, but the end of a de facto grace period in enforcement. The legal obligation has existed since March. Anyone not yet registered is not “just in time” but already in default – and should now catch up in an orderly way instead of continuing to wait.
Who is actually affected
NIS-2 does not affect every company with 50 or more employees across the board. The obligations apply only within the 18 sectors of the act’s annex – among them energy, transport, health, and digital infrastructure, but also manufacturing and chemicals. Within these sectors, the thresholds of § 28 BSIG (new version) apply:
- Important entities: from 50 employees, or more than EUR 10 million in revenue and more than EUR 10 million balance sheet total.
- Essential entities: from 250 employees, or more than EUR 50 million in revenue and more than EUR 43 million balance sheet total.
In total this concerns roughly 29,500 to 30,000 entities in Germany – by OpenKRITIS’s estimate about 8,250 essential and about 21,600 important. For comparison: under the old KRITIS regime there were about 4,500. The circle of regulated companies has thus more than sextupled. This is precisely why NIS-2 now affects many mid-sized companies that have never dealt with the BSI before.
The difference between the two categories is practically relevant: essential entities are subject to proactive supervision by the BSI, while important entities are examined on an incident-driven basis.
The deadline situation – and where companies actually stand
The BSI registration portal has been live since January 6, 2026, and the statutory deadline ended on March 6, 2026. By then only about 11,500 of the estimated 29,500 affected entities had registered – about 39 percent. By early April it was about 15,500, by the end of May just under 18,500.
Soberly viewed, this means: a substantial share of affected companies is still not registered even today. Anyone in that group should know what is at stake:
- Violations of the registration obligation can be penalized with fines up to EUR 500,000.
- Violations of the substantive obligations can cost up to EUR 10 million or 2% of worldwide revenue (essential entities), or EUR 7 million or 1.4% (important entities) – whichever amount is higher.
- Under § 38 BSIG, management is obligated to implement the risk management measures and to monitor their implementation. Operational tasks can be delegated – the responsibility for them cannot.
What the act requires in substance
At the core is § 30 BSIG (new version): a catalog of risk management measures covering, among other things, risk analysis, incident handling, backup and crisis management, supply chain security, encryption, and access control. On top of this come tiered reporting obligations for significant security incidents:
- initial report within 24 hours,
- updated report within 72 hours,
- final report within one month.
Anyone who wants to meet these deadlines in a real incident needs processes defined in advance – in the middle of an incident, no one improvises this cleanly.
Triage for latecomers: three steps in this order
1. Check whether you are affected and document the result
The BSI provides a self-assessment at betroffenheitspruefung-nis-2.bsi.de. Carry out this check – today, not in Q4 – and document the result in writing (the self-assessment is not legally binding, but it is valuable as evidence that the matter was addressed). Even a negative result is evidence: it demonstrates that management engaged with the question.
2. Register, even late
A late registration is better than none. Experience from comparable regulatory efforts suggests that proactive late reporting is assessed differently from inaction that only surfaces during an incident.
3. Gap assessment against § 30
Compare the actual state, in a structured way, against the catalog of measures. In practice the biggest gaps are usually in three areas: dependable risk management with management involvement, practiced incident handling including the reporting process, and demonstrably recoverable backups with an emergency plan. The assessment produces a prioritized action plan – not everything at once, but everything with a due date and a responsible owner.
Assessment: an obligation with a side benefit
At its core, NIS-2 demands nothing exotic, but rather solid IT security, implemented consistently and documented. Anyone who takes the measures seriously not only fulfills a legal obligation but also genuinely reduces the risk that attackers target every day. Conversely: a binder full of certificates without lived processes helps neither at the audit nor during an incident. A side note: the KRITIS evidence obligations with formal audits take effect at the earliest at the end of 2028 – the acute pressure to act now lies with registration and baseline measures.
How sector7 supports you
As an owner-led firm, we guide companies in NRW through the affected-status check, registration, and the gap assessment against § 30 – with compliance consulting on NIS-2, ISO 27001, DORA, and TISAX from a single source. The technical implementation of the measures, from network security engineering to 24/7 monitoring by our NOC, we deliver ourselves instead of passing it on. On request at flat monthly rates, so the NIS-2 implementation stays budgetable.
This article is a professional assessment and does not replace legal advice in individual cases.
Sources
- https://www.openkritis.de/it-sicherheitsgesetz/nis2-umsetzung-gesetz-cybersicherheit.html
- https://www.datenschutz-notizen.de/das-nis-2-umsetzungsgesetz-ist-in-kraft-getreten-welche-schritte-sind-nun-erforderlich-4457509/
- https://www.bdo.de/de-de/insights/digitalisierung-ki/sechs-monate-nis-2-umsetzungsgesetz-nis-2-in-deutschland
- https://www.dhpg.de/de/newsroom/blog/registrierungspflicht-nach-nis-2-bsi-portal-freigeschaltet-frist-maerz-2026
- https://www.schutzwerk.com/blog/nis-2-erweiterung/
- https://betroffenheitspruefung-nis-2.bsi.de