The BSI's extended deadline for NIS2 registration expired on 31 July 2026. The statutory registration date had already passed on 6 March 2026. Any company that is still not registered has therefore been in breach since March, and the period of regulatory leniency is over. Late registration alone can trigger penalties of up to 500,000 euros, and breaches of other NIS2 obligations carry considerably higher ceilings.
Registering late is still the right move, and it should happen immediately. This article explains what applies now that the deadline has passed, who is actually required to register, what the consequences are and how to get from a missed registration to the continuous compliance NIS2 genuinely requires.
What applies now that the deadline has passed
31 July 2026 was never a statutory date. It was an extension. That distinction matters: the legal obligation to register existed before it and continues unchanged. What ended on 31 July was the BSI's willingness to defer enforcement.
Germany transposed the EU directive through an amended BSI Act that came into force on 6 December 2025. The legislation provides no transition period, so the obligations applied from day one. The three-month registration window closed on 6 March 2026. You can read the full text of the directive to see how little room it leaves for delay.
The numbers explain why the BSI granted an extension at all. By the end of May 2026, only around 18,500 of an estimated 29,000 to 40,000 affected organisations had registered. More than half of the companies in scope were not compliant. Faced with that gap, the authority chose a final warning over immediate sanctions. That warning has now expired.
Do not plan around a further extension. The German federal authority sets out its enforcement position plainly, and supervision tightens as the regime matures rather than loosening.
Missed the deadline: what to do now
Register immediately, even late. A voluntary late registration is treated differently from continued non-registration, and the point at which you meet your obligation forms part of how your conduct is assessed.
Document when you established that you were in scope and why registration did not happen sooner. That documentation costs you half an hour and is the difference between a traceable sequence of events and an unexplained failure.
Start the gap analysis in parallel rather than afterwards. This is the most important change compared with the situation before 31 July. While the registration window was open, registration itself was the most urgent step. Now the BSI can request evidence of your security measures and not only check whether you are registered. A company that registers today and starts on the measures in six months has met the smaller obligation and left the larger one open.
Who has to register
You are required to register if your principal activity falls within one of the 18 sectors in Annex 1 or Annex 2 of the BSI Act and your company meets the size thresholds. What counts is your actual activity, not your commercial register entry.
The thresholds should be read as "or": you fall within scope as soon as either the headcount is reached or both financial figures are exceeded together. The calculation follows the European Commission's SME definition, under which affiliated and partner companies count towards your totals. A subsidiary with 30 employees can cross the threshold of 50 through its group structure, which regularly surprises mid-sized subsidiaries that see themselves as standalone small businesses.
One detail catches many teams out: there is no official letter telling you that you are in scope. The obligation to self-identify rests entirely with you, and getting it wrong is expensive in either direction. If your company sells cloud software, operates a managed platform or supplies a regulated customer base, assume you are in scope until a proper assessment of your exposure proves otherwise.
Regardless of size, the obligations apply to certain types of entity anyway, including qualified trust service providers, DNS service providers, TLD name registries and operators of critical installations.
What the consequences are now
A company that is not registered exposes itself to fines and regulatory orders, and exposes its management to personal liability.
The financial ceiling differs by category. Essential entities risk up to 10 million euros or 2 percent of worldwide annual turnover, important entities up to 7 million euros or 1.4 percent. For late registration alone, up to 500,000 euros applies.
The financial risk is only the headline. NIS2 ties accountability explicitly to the leadership level, which means managing directors and senior officers can be held personally liable for failures in cyber risk governance. That was a deliberate legislative choice, intended to move information security from a back-office task to a board-level one. Leadership also carries a standalone obligation to undertake regular training.
Beyond fines, the BSI can issue binding orders, demand evidence of compliance and intensify supervision. For an essential entity that can mean inspections and external audits at your own expense.
There is also a quieter cost. Enterprise customers, insurers and partners now ask about NIS2 status during procurement. A missing registration becomes a deal blocker long before an authority comes knocking, and restarting a stalled enterprise contract is considerably more expensive than registering. To a regulated customer, your compliance gap is their compliance gap, which is precisely why they check.
Registration is only the beginning
Registering with the BSI discharges one obligation, but NIS2 is an ongoing programme rather than a single form. It requires continuous risk management, incident reporting, supply chain security and demonstrable governance that holds up over time.
The reporting obligation is the sharpest edge. NIS2 requires an early warning within 24 hours of becoming aware of a significant incident, followed by a fuller notification after 72 hours and a final report after one month. These deadlines cannot be improvised under pressure, which is why responsibilities, reporting paths and report templates have to be defined in advance. Our guide to the full set of NIS2 requirements walks through the complete picture.
Then there is the substance of the security measures themselves. The law expects risk analysis, access control, cryptography, supplier assessment, staff training and regular testing of how well your controls actually work. Many of these overlap closely with established standards, and reading NIS2 through the lens of ISO 27001 is one of the most efficient ways to satisfy both at once.
Supply chain security deserves particular attention, because this is where organisations most often underestimate their exposure. NIS2 makes you co-responsible for the security posture of your direct suppliers and service providers, not just your own systems. That means contractual security clauses, vendor risk assessments and a clear view of which third parties could become an entry point. If you depend on cloud providers or managed services, their weaknesses become your regulatory problem. Our guide to emergency planning and business continuity under NIS2 shows what a working plan looks like in practice.
A realistic path looks like this: establish your exposure and category, register with the BSI without delay, run a gap analysis against the security measures, close the gaps with documented policies, technical controls and supplier reviews, set up and test a 24-hour reporting process, and maintain evidence so you can demonstrate compliance at any point.
How Kertos helps you now
Kertos combines the platform with certified experts, so you can move from an unclear scope position to a defensible NIS2 programme without taking pace out of the business.
Automation mainly changes the arithmetic on effort. Kertos automates evidence collection, control mapping and documentation, compressing the manual work that otherwise stretches a NIS2 project across many months.
Just as important is treating NIS2 as continuous compliance rather than a one-off project. Once you are registered, the platform keeps your risk register, policies and incident processes current, so the 24-hour clock and the next inspection do not catch you unprepared. A tailored NIS2 readiness session maps the platform to your specific scope.
Can I still register now that the deadline has passed?
Yes, and you should do so immediately. The obligation to register did not lapse when the deadline expired, it became overdue. A voluntary late registration is assessed differently from continued non-registration.
What is the fine for missing the registration deadline?
Up to 500,000 euros applies for late registration alone. Breaches of other NIS2 obligations carry higher ceilings, up to 10 million euros or 2 percent of worldwide annual turnover for essential entities, and up to 7 million euros or 1.4 percent for important entities. Management can be held personally liable.
Will the BSI notify me if my company is in scope?
No. There is no official notification. Your organisation must assess for itself whether it qualifies as an essential or important entity. A structured scope assessment is the safest first step.
Is registration enough for NIS2 compliance?
No. Registration is one obligation among several. You also have to implement risk management measures, assess suppliers, train staff and management, maintain a reporting process that works within 24 hours, and keep that evidence current on an ongoing basis.
Will there be another extension?
Do not plan for one. 31 July was already the extension to a statutory deadline that passed in March.
The NIS2 deadline is no longer a date on the horizon, it is a date that has gone by. For companies that are not registered, the position is less comfortable than it was before the summer, but it is also unambiguous: complete the registration, document your exposure and take on the measures in parallel. The companies that act now avoid more than a fine. They build the foundation that turns NIS2 from a threat into something they can evidence.





