Germany NIS2: Grace Deadline Expired, Enforcement Begins

The grace window has closed. On 31 July 2026, the final registration deadline that Germany's Federal Office for Information Security (BSI) had extended to NIS2-regulated entities expired. Every in-scope organization that has not yet registered is now, in the regulator's eyes, in breach of a duty that carries a six-figure fine, and the German NIS2 regime has shifted from patient onboarding into its enforcement phase.
For IT leaders at regulated companies, and for the managed service providers who support them, this is the moment the German NIS2 story stops being about future obligations and starts being about exposure that exists today.
How Germany Got to This Point
Germany's NIS2 implementation act, the NIS2UmsuCG, was promulgated in the Bundesgesetzblatt on 6 December 2025 and, notably, entered into force without any transition period. From day one, the amended BSIG imposed registration, risk-management, and reporting duties on the organizations it covers. There was no phase-in year, no soft launch, and no formal notification letter telling companies they were in scope. Entities are expected to assess their own status and act.
The statutory registration deadline fell three months after entry into force, on 6 March 2026. When large numbers of entities missed it, the BSI opted for pragmatism over immediate sanction and communicated a final grace deadline of 31 July 2026. German advisers described it plainly as a last chance to register without consequences. That last chance has now passed.
A Registration Gap Measured in Thousands
The scale of the remaining gap is striking. According to BSI figures reported in the German trade press, roughly 29,500 entities fall within the scope of the new law, but only around 18,500 had registered by the end of May 2026. Even allowing for a surge of late filings ahead of the July cutoff, that arithmetic suggests thousands of regulated organizations entered August unregistered.
Some of that gap is deliberate delay, but much of it is genuine uncertainty. NIS2 dramatically widened the circle of regulated sectors compared with Germany's earlier critical-infrastructure rules, pulling in mid-sized manufacturers, food producers, waste-management firms, digital providers, and many others that have never dealt with the BSI before. Because the law works on self-identification, a company can be in scope for months without realizing it. The BSI operates official information pages and the registration portal, including guidance to help organizations determine whether they qualify as an important or particularly important entity. If your organization has not run that assessment, it is overdue.
What Enforcement Can Cost
The fine framework in the amended BSIG gives the BSI real leverage. As German coverage of the framework sets out, registration failures alone can draw fines of up to EUR 500,000. For essential entities that breach core duties under the law, the ceiling rises to EUR 10 million or 2 percent of global annual turnover.
Enforcement rarely opens with maximum penalties, and the BSI has signaled cooperation over confrontation throughout the registration period. But a missed registration is the easiest possible violation to detect: it is a binary check against the register, requiring no audit, no on-site inspection, and no technical assessment. Organizations that stayed silent through two deadlines have made themselves the lowest-hanging fruit a regulator could ask for. The rational move for anyone still unregistered is to file immediately. Registering late is a far better posture than being found absent, and demonstrable good faith tends to shape how sanction decisions unfold.
Registration Is the Floor, Not the Finish Line
It is worth being clear-eyed about what registration actually achieves: it puts your name on a list. The substantive obligations live elsewhere in the law, above all in Section 30 BSIG, which requires regulated entities to implement risk-management measures across areas such as incident handling, supply-chain security, and access control. Those measures explicitly include cyber hygiene practices and security awareness training for staff, mirroring Article 21(2)(g) of the NIS2 directive itself.
That means an entity that registers on time but has no structured training program is still non-compliant on a core duty, one of the categories where the larger fines apply. And unlike registration, training obligations are evidence-driven: when the BSI asks, you will need dated completion records, a documented curriculum, and proof that the program actually runs, not a statement of intent. Platforms like empowsec generate exactly that trail, pairing security awareness training and phishing simulations with the compliance evidence German supervision will expect. For a detailed breakdown of what the directive expects from awareness programs, see our earlier guide to NIS2 security awareness training requirements.
The MSP Opportunity and Obligation
For managed service providers, the expired deadline cuts two ways. Many MSPs are themselves in scope as digital or ICT service providers and must sort out their own registration and Section 30 measures. At the same time, the enforcement phase makes MSPs the natural first responders for thousands of clients who are late, confused, or both.
A practical client playbook looks like this: run a scope triage across the client base using the BSI's criteria; register any in-scope client immediately, even though the grace deadline has passed; stand up the Section 30 baseline, with awareness training among the fastest measures to deploy and document; and build the evidence file as you go, because in an enforcement phase, undocumented compliance is indistinguishable from non-compliance.
Key Takeaways
- The final deadline has passed. The BSI's grace deadline of 31 July 2026 followed the statutory date of 6 March 2026; unregistered in-scope entities are now exposed.
- The gap is large. BSI figures reported in the German trade press put scope at roughly 29,500 entities, with only about 18,500 registered by the end of May 2026.
- Fines are substantial. Registration failures can draw up to EUR 500,000; core-duty breaches by essential entities can reach EUR 10 million or 2 percent of global turnover.
- Register late rather than never. A late filing with demonstrable good faith is a far stronger position than silence in an enforcement phase.
- Do not stop at registration. Section 30 BSIG requires cyber hygiene and security awareness training for staff, and supervisors will expect dated records that prove the program runs.


