News

Kertos study: only 27% of surveyed companies are registered with the BSI

49% of the 51 companies surveyed had not started NIS2 implementation or were still assessing whether they are in scope.

Author
Catherine Higginson
Date
1.10.2026
Updated on
1.10.2026
Kertos study: only 27% of surveyed companies are registered with the BSI

Munich, October 1st, 2026. In the five weeks after the grace period for registration with the BSI ended on July 31, 2026, 27% of the companies surveyed reported being registered with the BSI. 49% had not started implementation or were still assessing whether they are in scope. For the NIS2 Readiness Study 2026, Kertos surveyed 51 companies headquartered in Germany, with 50 to 1,000 employees, operating in sectors listed in Annex I of the NIS2 Directive.

Legal framework

The German NIS2 Implementation and Cybersecurity Strengthening Act recasts the BSI Act (BSIG) and has been in force since December 6, 2025. According to the BSI, around 29,500 companies and institutions in Germany fall under the act (press release of June 1, 2026). July 31, 2026 marked the end of a grace period for registration with the BSI.

State of implementation

18% of the companies surveyed had not started NIS2 implementation, and 31% were still assessing whether they are in scope. 24% reported being registered with the BSI, 24% were implementing risk management measures, and 4% reported having fully implemented NIS2 and completed registration. The question was single-select, so whether companies in implementation are also registered cannot be determined.

Ownership

63% of the companies surveyed name the head of IT as responsible for NIS2 and information security, and in 41% the head of IT is the only role named. 22% name the executive board, 20% the data protection officer, 14% a dedicated CISO, and 2% an external or virtual CISO. 84% of the companies surveyed have neither a dedicated nor an external CISO. Multiple answers were possible, and no respondent selected "not clearly assigned" or "don't know". Section 38 BSIG requires executive management to implement the risk management measures and to monitor their implementation. In the companies surveyed, the work sits with IT in practice.

Awareness

53% of respondents knew that NIS2 has been in force since December 2025, and 49% knew the July 31, 2026 registration cut-off. 37% knew neither. Awareness tracks implementation progress: of the nine companies that had not started, seven knew neither fact. Of the 26 companies that were registered or implementing measures, only four knew neither.

Reasons and constraints

25 of the companies surveyed had not started or were still assessing whether they are in scope. Of those, seven are waiting for more regulatory clarity, seven say the topic is currently not a priority, six do not consider themselves in scope, six cite a lack of in-house know-how, four do not understand the requirements, two do not expect enforcement, and one cites a lack of budget or staff. All six companies that do not consider themselves in scope operate in sectors the directive covers. Across all respondents, the most frequently named constraint is the number of overlapping regulations such as GDPR, the AI Act, and NIS2 at 39%, followed by limited budget at 25%, unclear requirements at 24%, a lack of executive support at 22%, and a shortage of skilled staff at 20%. Manual, spreadsheet-based processes and keeping evidence audit-ready are each named by 16%. The least frequently named constraint is supplier and supply chain management at 6%. Supply chain security is one of the ten areas of measures set out in Section 30 BSIG.

At a glance

  • Sample: 51 companies headquartered in Germany, 50 to 1,000 employees, sectors listed in Annex I of the NIS2 Directive
  • Fieldwork: August 3 to September 4, 2026
  • Registered with the BSI: 27%
  • Not started or still assessing scope: 49%
  • Head of IT responsible: 63%, and the only role named in 41% of companies
  • Neither a dedicated nor an external CISO: 84%
  • Kertos: founded 2021, Berlin and Munich, 400 customers, 100% audit success rate

"In most of the companies we surveyed, the head of IT carries NIS2 alone, on top of running operations. Anchoring information security at board level is not a question of company size. It is a decision about who sets the priority and who monitors that the measures are implemented."

Dr. Kilian Schmidt, Co-Founder and CEO of Kertos

About the study

The NIS2 Readiness Study 2026 is available for download here and contains the full results, the questionnaire wording, and the methodology.

About Kertos

Kertos is the European compliance partner for companies that need to get certified and stay continuously compliant. The Kertos platform and the Kertos experts work alongside customers through preparation, audits, and the ongoing work that follows. The audit success rate is 100%: every company Kertos has taken to audit has passed. Kertos GmbH was founded in 2021 by Dr. Kilian Schmidt, Johannes Hussak, and Alexander Prams, operates from Berlin and Munich, and employs more than 70 people. 400 companies use Kertos. Kertos has closed a EUR 14 million Series A. Learn more: kertos.io

‍

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Catherine Higginson

Catherine Higginson

Senior Content Marketing Manager

Catherine is a content marketer with several years of experience across DACH and European SaaS, drawn to the challenge of making complex, regulated technology, healthcare, fintech, compliance, make sense to the people who have to buy it. She's built go-to-market strategy from the ground up, translated technical depth into positioning that lands with both engineers and commercial buyers, and worked directly with founders and product

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check