Key Takeaways
- The Kertos NIS2 Readiness Study 2026 surveyed 51 companies based in Germany with 50 to 1,000 employees, all operating in sectors listed in Annex I of the NIS2 Directive. Fieldwork ran from August 3 to September 4, 2026.
- 27% of the companies surveyed report that they are registered with the BSI, Germany's Federal Office for Information Security. 49% have not started NIS2 implementation or are still checking whether it applies to them.
- In 63% of the companies, the head of IT is responsible for NIS2, and in 41% it is the only role named. 84% have neither an in-house nor an external CISO.
- Tagesspiegel Background, midrange, it-daily.net, atp magazin, and ad-hoc-news.de reported on the study between October 1 and 8, 2026.
- According to Tagesspiegel Background, the BSI will launch an enforcement initiative against unregistered entities in Q4 2026. From Q1 2027, it plans to order selected essential entities to undergo audits.
NIS2 implementation in Germany is moving more slowly than lawmakers intended. Our NIS2 Readiness Study 2026 shows it, and several German trade and business media picked up the findings in the first week of October. This article covers who reported on the study, which figures each outlet highlighted, and what the BSI's newly announced plans mean for your company.
Who reported on the study
Between October 1 and 8, 2026, five German-language outlets covered the study, from the industrial trade press to a policy briefing service. Each chose a different focus; the underlying figures are the same. Headlines are given in the original German with an English translation.
midrange writes for IT leaders at German mid-sized companies, atp magazin for process and manufacturing automation, and Tagesspiegel Background for decision-makers in policy and public administration. Together they reach the companies that Germany's NIS2 Implementation Act has covered since December 6, 2025. What the directive requires in detail is covered in our guide to the NIS2 Directive.
NIS2 implementation in Germany: registration and progress
In the five weeks after the registration grace period ended on July 31, 2026, 27% of the companies surveyed reported that they were registered with the BSI. Almost half, 49%, had not started implementation or were still checking whether NIS2 applies to them.
The 49% breaks down into two groups: 18% have not started, and 31% are still assessing whether they are in scope. 24% are already implementing risk management measures, and 4% report that they have fully implemented NIS2 and completed registration.
Two registration figures appear side by side in the coverage. atp magazin's headline says "just under a quarter," while midrange and ad-hoc-news.de report 27%. Both numbers come from the study, but they measure different things. The question on current status allowed only one answer: 24% chose "registered with the BSI," and another 4% chose "fully implemented and registered." Together that is 14 of 51 companies, or 27%. Whether the 24% implementing measures are also registered cannot be read from this question. The full breakdown is in our press release on the NIS2 Readiness Study.
One small group deserves its own attention. Six companies believe NIS2 does not apply to them, and all six operate in sectors the directive covers. The survey cannot tell whether each falls below the size thresholds. Even so, any company in an NIS2 sector should be able to justify "this doesn't apply to us" in writing.
Ownership: why the coverage focused on the head of IT
The finding nearly every outlet picked up concerns responsibility. 63% of the companies surveyed name the head of IT as responsible for NIS2 and information security, and in 41% it is the only role named. 22% name the managing directors, and 20% the data protection officer.
14% of the companies have an in-house CISO and 2% an external or virtual CISO, so 84% have neither. ad-hoc-news.de made that figure its headline; Tagesspiegel Background framed it the other way around: only 16% have appointed a CISO.
The law places responsibility elsewhere. Section 38 of the German BSI Act (BSIG) requires the management body to implement the risk management measures and oversee their implementation. In the companies surveyed, the work still sits mostly with IT. What managing directors are personally obliged to do is summarized in our NIS2 checklist for managing directors.
Kertos co-founder and CEO Dr. Kilian Schmidt put the finding in context in the press release on the study, and midrange and it-daily.net both quoted him:
Kilian Schmidt sets out the duties of management, and where implementation tends to stall in practice, in more detail in his guest article for Security-Insider (in German) from October 8, 2026.
Awareness and obstacles: what is holding laggards back
53% of respondents knew that NIS2 has been in force in Germany since December 2025. 49% knew the registration date of July 31, 2026. 37% knew neither.
midrange and atp magazin highlighted a pattern that runs through the data: awareness and progress go together. Of the nine companies that have not started, seven knew neither date. Of the 26 companies that are registered or implementing measures, only four knew neither.
It would be tempting to put the delay down to budget. The study does not support that. 25 companies have not started or are still assessing whether they are in scope. Of these, seven are waiting for more regulatory clarity, seven say the topic is not currently a priority, six believe they are not covered, and six cite a lack of in-house expertise. Only one of the 25 names a lack of budget or staff.
Across all 51 respondents, the obstacles look somewhat different:
Respondents could choose more than one answer. Overlapping frameworks top the list. Companies that already work to ISO 27001, or plan an ISMS, can cover a large share of the NIS2 measures through it. Where the two frameworks overlap and where they do not is covered in our article on NIS2 and ISO 27001 overlap. Supply chain management is named least often, even though supply chain security is one of the ten areas of measures under Section 30 BSIG.
What Tagesspiegel Background adds: the BSI announces enforcement
Tagesspiegel Background placed the study in a wider context. According to its October 8, 2026 report, the BSI had counted 20,373 registered entities by the end of the third quarter. The government's draft of the NIS2 Implementation Act had estimated 29,850 entities. The gap between the two figures is large, although the estimate itself is now disputed.
The news is an announcement by Timo Hauschild, head of the BSI's division for cybersecurity in the economy, speaking to Tagesspiegel Background. In Q4 2026, the BSI will launch an enforcement initiative, starting with entities that obviously should have registered. The process begins with a hearing and can end in a fine.
From Q1 2027, the BSI also plans to order individual entities to have their IT security audited and to submit evidence. Essential entities in the sectors with the greatest need will come first. The audits are to have a thematic focus, such as business continuity management.
The report could also be read as a sign that the BSI lacks the staff to enforce across the board. The government draft had budgeted 476 additional positions. In 2026, the BSI received just under 80 new positions, and around 97 are planned for 2027, of which fewer than 20 are expected to go directly to NIS2. That does not mean a company without evidence will get away with it. The BSI selects entities for audit orders on a risk basis. Large customers already ask for evidence today, and after a security incident, what counts is what has been documented. In our survey, two of the 25 laggards said they did not believe NIS2 would be enforced. The BSI's announcement settles that question.
Take a machinery manufacturer with 220 employees that falls under the law as an important entity. The head of IT handles NIS2 alongside day-to-day operations, and the company has not registered yet. If a letter from the BSI arrives, the process opens with a hearing. If an automotive customer asks about the status of its risk management measures in the same week, the same person has to answer both. What to do after a missed registration is covered in our article on the NIS2 registration deadline.
How Kertos supports NIS2 implementation
The study points to two bottlenecks: responsibility is not distributed, and knowledge of obligations and deadlines is missing. Kertos addresses both. The Kertos platform maps the NIS2 requirements to measures, assigns each one an owner, and collects the evidence an audit or a large customer asks for. Companies that already work to ISO 27001 reuse their existing controls for NIS2 instead of maintaining them twice.
Kertos experts support companies from the scoping assessment through registration to ongoing operations. In the Pro and Premium packages, a Kertos expert takes on the role of external CISO. Responsibility under Section 38 BSIG stays with the management body, which gets a structure it can use to oversee implementation. 400 companies use Kertos. Every company Kertos has taken into an audit has passed it.
The full results, including the questionnaire wording and methodology, are available in the NIS2 Readiness Study 2026.
Customers on G2 single out the personal support:
If you want to know where your company stands on NIS2, we can show you in a demo how implementation works with Kertos.
Frequently asked questions
How many companies in Germany are affected by NIS2?
The BSI puts the number at around 29,500 companies and institutions covered by Germany's NIS2 Implementation Act. The government's draft bill estimated 29,850 entities. By the end of Q3 2026, the BSI had counted 20,373 registered entities, according to Tagesspiegel Background.
How far along is NIS2 implementation in German companies?
In the Kertos NIS2 Readiness Study 2026, 27% of the 51 companies surveyed report being registered with the BSI. 49% have not started implementation or are still checking whether NIS2 applies to them. Only 4% report having fully implemented NIS2.
Who is responsible for NIS2 implementation in a company?
Under Section 38 BSIG, the management body must implement the risk management measures and oversee their implementation. In practice, the work often sits with IT: in 63% of the companies surveyed, the head of IT is responsible, and in 41% it is the only role named.
What happens if a company does not register with the BSI?
According to Tagesspiegel Background, the BSI will launch an enforcement initiative in Q4 2026 against entities that obviously should have registered. The process begins with a hearing and can end in a fine. Section 65 BSIG provides for fines of up to 500,000 euros for a missed registration.
Do you need a CISO for NIS2?
The BSIG does not require a CISO; it obliges the management body to implement and oversee the measures. In practice, that is hard to do without someone who steers information security professionally. 84% of the companies surveyed have neither an in-house nor an external CISO.





