InfoSec

NIS2 in Germany: Where Companies Stand and What the BSI Plans Next

Almost half of the companies surveyed are still at the start. In Q4 2026, the BSI launches an enforcement initiative.

Author
Catherine Higginson
Date
Updated on
10.10.2026
NIS2 in Germany: Where Companies Stand and What the BSI Plans Next

Key Takeaways

  • The Kertos NIS2 Readiness Study 2026 surveyed 51 companies based in Germany with 50 to 1,000 employees, all operating in sectors listed in Annex I of the NIS2 Directive. Fieldwork ran from August 3 to September 4, 2026.
  • 27% of the companies surveyed report that they are registered with the BSI, Germany's Federal Office for Information Security. 49% have not started NIS2 implementation or are still checking whether it applies to them.
  • In 63% of the companies, the head of IT is responsible for NIS2, and in 41% it is the only role named. 84% have neither an in-house nor an external CISO.
  • Tagesspiegel Background, midrange, it-daily.net, atp magazin, and ad-hoc-news.de reported on the study between October 1 and 8, 2026.
  • According to Tagesspiegel Background, the BSI will launch an enforcement initiative against unregistered entities in Q4 2026. From Q1 2027, it plans to order selected essential entities to undergo audits.

NIS2 implementation in Germany is moving more slowly than lawmakers intended. Our NIS2 Readiness Study 2026 shows it, and several German trade and business media picked up the findings in the first week of October. This article covers who reported on the study, which figures each outlet highlighted, and what the BSI's newly announced plans mean for your company.

Who reported on the study

Between October 1 and 8, 2026, five German-language outlets covered the study, from the industrial trade press to a policy briefing service. Each chose a different focus; the underlying figures are the same. Headlines are given in the original German with an English translation.

Outlet Date Headline Focus
midrange (Carmen-Doreen Kauz) October 1, 2026 NIS2-Studie: Viele Unternehmen stehen bei Registrierung und Umsetzung noch am Anfang (NIS2 study: many companies are still at the start of registration and implementation) Responsibility resting with the head of IT, and the link between deadline awareness and progress
it-daily.net October 2, 2026 NIS2 bleibt für viele Unternehmen eine offene Baustelle (NIS2 remains unfinished business for many companies) NIS2 as an organizational problem, and why laggards have not started
atp magazin (Jonas Völker) October 6, 2026 NIS2-Umsetzung: Erst knapp ein Viertel der Unternehmen beim BSI registriert (NIS2 implementation: only just under a quarter of companies registered with the BSI) Industrial mid-sized manufacturers, evidence processes, and clear ownership
ad-hoc-news.de October 6 and 7, 2026 NIS-2-Readiness: Nur 27 Prozent von 51 Betrieben beim BSI registriert (Only 27 percent of 51 companies registered with the BSI); NIS2-Richtlinie: 84 Prozent der befragten Firmen ohne Sicherheitsverantwortlichen (84 percent of companies surveyed have no security lead) A certified ISMS as proof of compliance, and pressure on internationally connected suppliers
Tagesspiegel Background IT und Cybersicherheit (Benjamin Stiebel) October 8, 2026 NIS-2-Umsetzung: Wie ernst wird es jetzt? (NIS2 implementation: how serious is it getting now?) The BSI's enforcement initiative and the agency's staffing

midrange writes for IT leaders at German mid-sized companies, atp magazin for process and manufacturing automation, and Tagesspiegel Background for decision-makers in policy and public administration. Together they reach the companies that Germany's NIS2 Implementation Act has covered since December 6, 2025. What the directive requires in detail is covered in our guide to the NIS2 Directive.

NIS2 implementation in Germany: registration and progress

In the five weeks after the registration grace period ended on July 31, 2026, 27% of the companies surveyed reported that they were registered with the BSI. Almost half, 49%, had not started implementation or were still checking whether NIS2 applies to them.

The 49% breaks down into two groups: 18% have not started, and 31% are still assessing whether they are in scope. 24% are already implementing risk management measures, and 4% report that they have fully implemented NIS2 and completed registration.

Two registration figures appear side by side in the coverage. atp magazin's headline says "just under a quarter," while midrange and ad-hoc-news.de report 27%. Both numbers come from the study, but they measure different things. The question on current status allowed only one answer: 24% chose "registered with the BSI," and another 4% chose "fully implemented and registered." Together that is 14 of 51 companies, or 27%. Whether the 24% implementing measures are also registered cannot be read from this question. The full breakdown is in our press release on the NIS2 Readiness Study.

One small group deserves its own attention. Six companies believe NIS2 does not apply to them, and all six operate in sectors the directive covers. The survey cannot tell whether each falls below the size thresholds. Even so, any company in an NIS2 sector should be able to justify "this doesn't apply to us" in writing.

Ownership: why the coverage focused on the head of IT

The finding nearly every outlet picked up concerns responsibility. 63% of the companies surveyed name the head of IT as responsible for NIS2 and information security, and in 41% it is the only role named. 22% name the managing directors, and 20% the data protection officer.

14% of the companies have an in-house CISO and 2% an external or virtual CISO, so 84% have neither. ad-hoc-news.de made that figure its headline; Tagesspiegel Background framed it the other way around: only 16% have appointed a CISO.

The law places responsibility elsewhere. Section 38 of the German BSI Act (BSIG) requires the management body to implement the risk management measures and oversee their implementation. In the companies surveyed, the work still sits mostly with IT. What managing directors are personally obliged to do is summarized in our NIS2 checklist for managing directors.

Kertos co-founder and CEO Dr. Kilian Schmidt put the finding in context in the press release on the study, and midrange and it-daily.net both quoted him:

"In most of the companies we surveyed, the head of IT carries NIS2 alone, on top of running operations. Anchoring information security at board level is not a question of company size. It is a decision about who sets the priority and who monitors that the measures are implemented."

Dr. Kilian Schmidt, co-founder and CEO of Kertos

Kilian Schmidt sets out the duties of management, and where implementation tends to stall in practice, in more detail in his guest article for Security-Insider (in German) from October 8, 2026.

Awareness and obstacles: what is holding laggards back

53% of respondents knew that NIS2 has been in force in Germany since December 2025. 49% knew the registration date of July 31, 2026. 37% knew neither.

midrange and atp magazin highlighted a pattern that runs through the data: awareness and progress go together. Of the nine companies that have not started, seven knew neither date. Of the 26 companies that are registered or implementing measures, only four knew neither.

It would be tempting to put the delay down to budget. The study does not support that. 25 companies have not started or are still assessing whether they are in scope. Of these, seven are waiting for more regulatory clarity, seven say the topic is not currently a priority, six believe they are not covered, and six cite a lack of in-house expertise. Only one of the 25 names a lack of budget or staff.

Across all 51 respondents, the obstacles look somewhat different:

Biggest obstacle to NIS2 implementation Share of respondents
Overlapping regulations such as GDPR, the AI Act, and NIS2 39%
Limited budget 25%
Unclear requirements 24%
Lack of support from management 22%
Skills shortage 20%
Manual, spreadsheet-based processes 16%
Keeping evidence audit-ready 16%
Supplier and supply chain management 6%

Respondents could choose more than one answer. Overlapping frameworks top the list. Companies that already work to ISO 27001, or plan an ISMS, can cover a large share of the NIS2 measures through it. Where the two frameworks overlap and where they do not is covered in our article on NIS2 and ISO 27001 overlap. Supply chain management is named least often, even though supply chain security is one of the ten areas of measures under Section 30 BSIG.

What Tagesspiegel Background adds: the BSI announces enforcement

Tagesspiegel Background placed the study in a wider context. According to its October 8, 2026 report, the BSI had counted 20,373 registered entities by the end of the third quarter. The government's draft of the NIS2 Implementation Act had estimated 29,850 entities. The gap between the two figures is large, although the estimate itself is now disputed.

The news is an announcement by Timo Hauschild, head of the BSI's division for cybersecurity in the economy, speaking to Tagesspiegel Background. In Q4 2026, the BSI will launch an enforcement initiative, starting with entities that obviously should have registered. The process begins with a hearing and can end in a fine.

From Q1 2027, the BSI also plans to order individual entities to have their IT security audited and to submit evidence. Essential entities in the sectors with the greatest need will come first. The audits are to have a thematic focus, such as business continuity management.

The report could also be read as a sign that the BSI lacks the staff to enforce across the board. The government draft had budgeted 476 additional positions. In 2026, the BSI received just under 80 new positions, and around 97 are planned for 2027, of which fewer than 20 are expected to go directly to NIS2. That does not mean a company without evidence will get away with it. The BSI selects entities for audit orders on a risk basis. Large customers already ask for evidence today, and after a security incident, what counts is what has been documented. In our survey, two of the 25 laggards said they did not believe NIS2 would be enforced. The BSI's announcement settles that question.

Take a machinery manufacturer with 220 employees that falls under the law as an important entity. The head of IT handles NIS2 alongside day-to-day operations, and the company has not registered yet. If a letter from the BSI arrives, the process opens with a hearing. If an automotive customer asks about the status of its risk management measures in the same week, the same person has to answer both. What to do after a missed registration is covered in our article on the NIS2 registration deadline.

How Kertos supports NIS2 implementation

The study points to two bottlenecks: responsibility is not distributed, and knowledge of obligations and deadlines is missing. Kertos addresses both. The Kertos platform maps the NIS2 requirements to measures, assigns each one an owner, and collects the evidence an audit or a large customer asks for. Companies that already work to ISO 27001 reuse their existing controls for NIS2 instead of maintaining them twice.

Kertos experts support companies from the scoping assessment through registration to ongoing operations. In the Pro and Premium packages, a Kertos expert takes on the role of external CISO. Responsibility under Section 38 BSIG stays with the management body, which gets a structure it can use to oversee implementation. 400 companies use Kertos. Every company Kertos has taken into an audit has passed it.

The full results, including the questionnaire wording and methodology, are available in the NIS2 Readiness Study 2026.

Customers on G2 single out the personal support:

"The Personal support when going through the certification process. It helps you structure the certification process and not get lost."

Verified User in Computer Software, Small-Business (50 or fewer emp.), G2

If you want to know where your company stands on NIS2, we can show you in a demo how implementation works with Kertos.

Frequently asked questions

How many companies in Germany are affected by NIS2?

The BSI puts the number at around 29,500 companies and institutions covered by Germany's NIS2 Implementation Act. The government's draft bill estimated 29,850 entities. By the end of Q3 2026, the BSI had counted 20,373 registered entities, according to Tagesspiegel Background.

How far along is NIS2 implementation in German companies?

In the Kertos NIS2 Readiness Study 2026, 27% of the 51 companies surveyed report being registered with the BSI. 49% have not started implementation or are still checking whether NIS2 applies to them. Only 4% report having fully implemented NIS2.

Who is responsible for NIS2 implementation in a company?

Under Section 38 BSIG, the management body must implement the risk management measures and oversee their implementation. In practice, the work often sits with IT: in 63% of the companies surveyed, the head of IT is responsible, and in 41% it is the only role named.

What happens if a company does not register with the BSI?

According to Tagesspiegel Background, the BSI will launch an enforcement initiative in Q4 2026 against entities that obviously should have registered. The process begins with a hearing and can end in a fine. Section 65 BSIG provides for fines of up to 500,000 euros for a missed registration.

Do you need a CISO for NIS2?

The BSIG does not require a CISO; it obliges the management body to implement and oversee the measures. In practice, that is hard to do without someone who steers information security professionally. 84% of the companies surveyed have neither an in-house nor an external CISO.

‍

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Catherine Higginson

Catherine Higginson

Senior Content Marketing Manager

Catherine is a content marketer with several years of experience across DACH and European SaaS, drawn to the challenge of making complex, regulated technology, healthcare, fintech, compliance, make sense to the people who have to buy it. She's built go-to-market strategy from the ground up, translated technical depth into positioning that lands with both engineers and commercial buyers, and worked directly with founders and product

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check