The registration deadline with Germany's Federal Office for Information Security (BSI) expired on 6 March 2026. According to media reports, thousands of affected companies missed it. The good news: registration can still be completed. That is clearly better than waiting further.
The German NIS2 Implementation Act has applied since 6 December 2025. Affected companies had to register via the BSI portal within three months, by 6 March 2026. According to media reports citing BSI estimates, a substantial share of the roughly 29,500 companies in scope missed that deadline.
Since the deadline passed, the BSI can enforce registration with periodic penalty payments. Failure to register is also a separate infringement with fines of up to €500,000 (Section 65 of the German BSI Act). For breaches of the substantive obligations, the frameworks reach further: up to €10 million or 2% of worldwide annual turnover for essential entities („besonders wichtige Einrichtungen"), up to €7 million or 1.4% for important entities. Management is additionally personally liable under the Act.
The key perspective: a late registration is a solvable problem. Acting in a structured way now reduces the risk. Waiting further increases it.
Not every company is affected. What matters are the sector (18 sectors under Annexes I and II) and size (from 50 employees or €10 million annual turnover). The free applicability check walks through the criteria in eight questions and gives an initial assessment.
Start the free checkRegistration is done via the BSI's online portal and remains possible. The BSI has announced it will tolerate late registrations until 31 July 2026 and refrain from enforcement measures during that period. This is administrative forbearance, not an extension of the statutory deadline. Registration remains possible and advisable after that date as well.
Required details include information on the entity, its sector and a contact person. The BSI registration assistant in NIS2 Pilot (part of the NIS2-Ready package) guides you through the required details step by step so nothing is missing.
Registration is only the start: risk analysis, incident response, business continuity, supply-chain security, MFA and further measures must be implemented and made demonstrable towards the BSI. The maturity check in NIS2 Pilot shows where your company stands and which gaps to close first (basic version free, full analysis in the paid packages).
The BSI has announced it will tolerate late registrations until 31 July 2026 and refrain from measures during that period. Afterwards it can impose periodic penalty payments; in addition, the fines framework of the Act exists. How individual cases will be handled cannot be predicted in general terms. A prompt, complete late registration is likely to reduce the risk considerably and documents good faith.
Many companies share that uncertainty. Checking applicability via sectors and thresholds is the most sensible first step. The free check in the app walks through the criteria. For borderline cases (e.g. group structures, supply-chain roles) an additional legal review is advisable.
Three sets of obligations: the ten risk-management measures under Section 30 of the German BSI Act, the reporting obligations for significant incidents (24-hour early warning, 72-hour notification, one-month final report) and evidence obligations towards the BSI. Added to that is the regular training obligation for management under Section 38.
The applicability check shows for free whether NIS2 could be relevant for your company, and the maturity check shows where you stand.
Applicability check free • One-time purchase, no subscription • All data stays on your device