diamond_full diamond diamond_half diamond_euro search-icon menu chat-icon close-icon envelope-icon smartphone-call-icon
Blog & News

NIS-2 Registration: New Deadline of 31 July 2026 - What Companies Need to Know

Applicability assessment, registration process, and sanctions: what companies need to know about the NIS-2 grace period until 31 July 2026.

July 9, 2026

preview-image for NIS-2 Registration: New Deadline of 31 July 2026

Germany’s Federal Office for Information Security (BSI) has set a new deadline for NIS-2 registration: by 31 July 2026, all affected companies should have clarified their status and completed their registration. The reason is clear. Of the roughly 30,000 affected entities in Germany, only about half had registered by the end of May 2026. For everyone who missed the original deadline, this is the opportunity to catch up.

What lies behind the new NIS-2 deadline

Since the NIS-2ImplementationAct (NIS2UmsuCG) came into force on 6 December 2025, significantly more companies are subject to statutory cybersecurity obligations for the first time. The statutory registration deadline already ended on 6 March 2026, three months after the act took effect. The BSI’s registration portal has been available since 6 January 2026.

Reality fell short of expectations. By the time the statutory deadline expired, only around 11,500 entities had registered. By the end of May, that number had risen to roughly 18,500 - which still left about 10,500 organizations outstanding. In a letter to industry associations, the BSI subsequently communicated that it expects full implementation by 31 July 2026.

Important: The extended deadline is not a genuine extension

One point is crucial and easily misunderstood: 31 July 2026 is not a new statutory date, but a signal of leniency in enforcement. Legally, registration was already due on 6 March 2026. Anyone who missed it has been in default ever since. The registration obligation under the BSI Act remains unchanged.

The extended deadline therefore buys time, but it does not retroactively remove the original obligation. For companies, this means: completing registration now is the right and necessary step. It signals to the BSI that you have recognized your obligation and are taking active steps.

Who is affected by NIS-2?

The NIS-2 Directive reaches well beyond the classic critical-infrastructure sectors. A far broader range of companies is affected today than in the past, and many of them have not been counting on it. Whether your company falls within scope comes down to two questions: which sector do you operate in, and what size do you reach?

Sectors and thresholds

The starting point is the sector and the size of the company. As a rule, an entity falls under NIS-2 if it operates in one of the 18 regulated sectors and has at least 50 employees, or more than 10 million euros in annual turnover and balance sheet total.

The sectors are broadly defined. They range from energy, transport and drinking water through the health, financial and insurance sectors to digital infrastructure, public administration, waste water, postal and courier services, and food production. Anyone who has never operated in the world of critical infrastructure should therefore not assume too quickly that they are out of scope.

“Essential” or “important” entity - where the difference lies

The BSI Act (BSIG), as amended by the NIS-2 Directive, divides affected companies into two categories, and this classification has concrete consequences. Two factors are decisive above all: the size of the company and the criticality of the sector.

Essential entities are generally large companies in the sectors of high criticality (Annex 1), meaning those areas whose failure would hit society most directly, such as energy, transport, finance or health. This refers to entities with at least 250 employees, or more than 50 million euros in annual turnover and more than 43 million euros balance sheet total. In addition, operators of critical installations (KRITIS operators) are always categorized as essential entities.

Important entities are the remaining affected companies that meet the basic thresholds. These include small and medium-sized companies in the sectors of Annex 1 and Annex 2, as well as large companies in the other critical sectors. The latter are listed in Annex 2 and cover areas such as postal and courier services, waste management, chemicals, food and manufacturing. The relevant thresholds here are 50 employees, or an annual turnover and balance sheet total exceeding 10 million euros.

This classification determines how closely the BSI supervises an entity and how high potential fines may be. Essential entities are subject to proactive supervision, whereas important entities are reviewed on a case-by-case, ex-post basis. The requirements for risk management and incident reporting, however, apply equally to both categories.

If you are unsure whether your company is affected, the BSI’s non-bindingonlinecheck provides a first orientation. However, only a legal applicability assessment can deliver a final, reliable evaluation. We support you with a legalassessmentofNIS-2applicabilitybyaspecializedattorney .

The three central NIS-2 obligations

Being in scope gives rise to three closely interlinked obligations. These elements are interconnected and must be considered as a cohesive whole.

Registration obligation

Essential and important entities must register with the BSI no later than three months after they first become affected. If the registered data changes, the update must be submitted through the BSI portal without undue delay, and at the latest within two weeks.

Reporting obligation

Significant security incidents must be reported to the BSI, in staggered deadlines: an early warning within 24 hours of becoming aware of the incident, a more detailed incident notification within 72 hours, and a final report within 30 days. The report includes an assessment of the incident covering its severity, impact and indicators of compromise.

Implementing and documenting risk management

Risk management sits at the core. Companies must take and document appropriate, proportionate and effective technical and organizational measures. The BSI Act sets out at least ten areas for this, and they all come back to one simple question: will your company stay operational when something goes wrong?

In practice, that means knowing your risks before they materialize and reviewing the effectiveness of your own measures on a regular basis. It means staying able to respond when it matters, through robust incident response processes, contingency plans and functioning crisis management that keeps operations running. It means securing your own access points and data by technical means, such as encryption, access control and multi-factor authentication. And it means looking beyond your own systems, because NIS-2 explicitly extends the responsibility to supply chain security and to your own workforce.

One point is decisive here: responsibility for implementing and monitoring these measures rests explicitly with the management.

Sector-specific special provisions

Companies in certain sectors, in particular finance, telecommunications and energy supply, as well as operators of critical installations, are subject to additional sector-specific requirements, exemptions and obligations.

How NIS-2 registration works, step by step

Registration follows a two-stage procedure. It requires a German tax number, which is used to apply for the necessary ELSTER organization certificate. You should allow several working days of lead time for this certificate, as the application takes time to process. Preparing it early keeps you from ending up under unnecessary time pressure later on.

Step 1: Registering with “Mein Unternehmenskonto” (MUK)

The first step runs through the digital “Mein Unternehmenskonto” (MUK) business account service, which is based on the established ELSTER technology and serves as a central gateway to digital administrative services. The first user takes on the role of administrator and can invite additional people and assign roles.

Step 2: Registering in the BSI portal

This is followed by the mandatory registration in the BSI portal. Among the details recorded are the name and address of the entity, its legal form, sector and entity type, company size, the competent supervisory authorities, a NIS-2 contact point and a contact person, as well as publicly reachable IP address ranges. The same portal later serves as the central reporting point for significant security incidents.

The sanctions for non-compliance

With NIS-2, cybersecurity is anchored explicitly at management level, and that comes with tangible consequences. For a failure to register, the law provides for fines of up to 500,000 euros. For breaches of the risk management and reporting obligations, the potential sanctions are considerably higher and depend on the category: up to 10 million euros or 2 percent of worldwide annual turnover for essential entities, and up to 7 million euros or 1.4 percent for important entities.

On top of this comes the personal responsibility of management. Executives are directly accountable for implementing and monitoring the security measures and can be held personally liable in the event of a breach of duty.

Registration is only the first step

Registration initially demonstrates just one thing: that a company has recognized it is affected. The real work begins afterwards. Risk management, incident response processes, supply chain security and reliable reporting channels have to be built up, documented and demonstrated when it matters. To implement this through a structured process, establishing an Information Security Management System (ISMS) is recommended. We are happy to support and guide you through this. You can find more information here .

None of this can be fully implemented within a few weeks. In the time that remains, however, you can establish where your company stands and which measures take priority. A structured look at the current maturity of your information security lays the groundwork for that. It reveals where governance, IT and operations do not yet mesh consistently, and that is precisely where effectiveness is later decided.

NIS-2: Moving Forward with SCHUTZWERK

NIS-2 is more than a formal registration obligation. The real goal of the regulation is lasting, resilient digital operations. For companies, that means planning early, clarifying responsibilities, building structures and documenting measures.

We are happy to support you across the various phases and topics of NIS-2:

Throughout, we involve you early, in planning, execution and evaluation. That keeps measures transparent and ensures they are implemented sustainably.

Contactus to plan the next steps for your company together.

You May Also Be Interested In:

Free Consultation