
NIS2: the registration deadline has passed — what to do now
NIS2 registration with the BSI was due by 6 March 2026.
News
AI-generatedThe first deadline for registering with the German Federal Office for Information Security (BSI) expired on 6 March 2026. Missing it does not remove the obligation: registration still has to be made up, and the remaining duties apply regardless of whether an entity has registered.
What governs in Germany is not the EU directive itself but its transposition: the NIS2 Implementation and Cybersecurity Strengthening Act and the recast BSI Act. Both have been in force since December 2025. This still surprises companies who assumed the rules only concerned energy suppliers and hospitals.
Are we even in scope?
As a rule you are in scope if you operate in one of the sectors named in the law and meet the size criteria. Every company makes its own initial classification — a prior request from an authority is not a precondition for the duties to apply.
- Essential entities: from 250 employees, or from EUR 50 million annual turnover and more than EUR 43 million balance sheet total
- Important entities: from 50 employees, or from EUR 10 million annual turnover and balance sheet total
These thresholds are a simplified account. Whether an entity counts as "essential" or "important" also depends on which annex of the BSI Act its sector belongs to. In addition, some entities are covered regardless of size, including certain digital providers and operators of critical installations. Only the legal text — or your legal advisers — gives the binding classification.
The sector list is longer than most expect. It runs from postal and courier services through waste management, chemicals and food to parts of manufacturing: medical devices, electronics, mechanical engineering, vehicle construction. A mechanical engineering firm with 60 staff may fall under it. And companies that are not themselves covered often still feel the requirements, because affected customers pass them down to suppliers by contract.
If you want to know where NIS2 ends and the stricter critical-infrastructure duties begin, we have described both: NIS2 implementation and critical infrastructure consulting for operators.
Registration is missing — what now?
Register without delay. 6 March 2026 was the deadline for entities already covered when the law entered into force. For companies that cross the thresholds later — through growth, acquisition or a new line of business — the period starts at that point.
Registration itself is the smallest part: an administrative step with mandatory details and a duty to keep them current. The real work lies elsewhere — risk management, reporting channels, evidence, supply chain requirements. That is the part that takes time.
What happens if nothing is done?
For essential entities the fine framework reaches up to EUR 10 million or 2 per cent of worldwide annual turnover, whichever is higher; for important entities it is lower. Which framework applies depends on the specific breach. In practice, three other consequences matter more than the maximum figure.
- Orders and audits by the supervisory authority, which tie up resources
- For continuing breaches, possible prohibition of management functions
- The responsibility of the management: it must approve the risk-management measures and monitor their implementation, and it is liable where it culpably breaches that duty
The last point is the most underestimated. Operational work can be delegated to IT or to a service provider — the statutory management responsibility stays with the leadership, which must also undergo training.
Where do we start?
By establishing whether you are in scope — in writing, traceably, with a date. A documented classification makes later decisions comprehensible and is valuable even when the answer is "not in scope".
- Clarify scope and document the result with its reasoning — the legal assessment belongs with your legal advisers
- Complete the BSI registration if your classification requires it
- Take stock: which measures already run, which evidence exists?
- Close gaps, prioritised by risk rather than by effort
- Define reporting channels and rehearse them once — an untested chain is not a chain
Does ISO 27001 certification help?
Considerably. A management system built to ISO 27001 provides structures to build on: risk assessment, control catalogue, documentation, internal audits.
It is not an equals sign, though. Certification covers only its defined scope, and NIS2 sets its own priorities — among them reporting duties with fixed deadlines, the supply chain, and management responsibility. What is already covered in your organisation and what is missing only emerges from comparing the actual scope.
How long does implementation take?
That depends on the starting point, which is why serious answers give a range rather than a number. A company with maintained documentation and running patch management needs considerably less than one starting with an inventory. The first step is plannable: a position assessment delivers a gap list with effort estimates, its scope depending on size, sites and internal participation.
Our role here is that of the IT service provider: we handle technical and organisational implementation — inventory, measures, evidence, training. The legal assessment of scope and any communication with authorities belong with your legal advisers. The two interlock, and we regularly work alongside our clients’ law firms.
We work within roughly 100 kilometres of Singen — from Villingen via Konstanz into Switzerland. For Swiss companies: NIS2 is EU law and does not apply to them directly; the requirements still reach them through EU subsidiaries and through contracts with affected customers. If you are unsure where you stand, talk to us.
Status: August 2026. The deadlines, thresholds and fine frameworks named here reflect the information available at that date in simplified form. They are general information and do not replace individual legal advice; only the statutory text is binding.

Solutions in a new dimension.
One conversation is enough to find out where IT, Microsoft Cloud and AI can take real weight off day-to-day business.
Your contact: Jan Emmerich, Managing Director