← Knowledge

NIS2

Missed the NIS2 Registration? Why Now Is Still the Best Time

06 August 2026 · 5 min read · updated 24/08/2026

Late registration is still possible, and a late voluntary registration beats no registration at all in every realistic scenario — the obligation under Section 33 BSIG did not expire with the grace period that ended on 31 July 2026. Whether you are affected is yours to determine; no official notice arrives (Section 28 BSIG). And registration is the smallest part: the risk-management measures under Section 30 BSIG and management's personal obligations under Section 38 BSIG apply regardless.

Since Germany's NIS2 transposition act, new duties apply to around 29,500 companies in Germany and federal-administration bodies, among them registration with the Federal Office for Information Security (BSI) — the figure comes from the BSI itself (press release of 6 January 2026 on opening the registration portal). The grace period for that ended on 31 July 2026, and many affected organisations still haven't registered. Some don't know they're affected. Others are putting it off because they fear sanctions the moment they come forward.

Both are understandable — and both are risky. The registration obligation doesn't go away, and the regulator won't start with the companies that came forward voluntarily.

Who is actually affected

Whether you're affected comes down to two questions: Do you operate in one of the regulated sectors (among others: IT and managed services, energy, transport, healthcare, manufacturing, chemicals, food, digital services)? And do you exceed the size threshold — generally 50 employees or €10 million in annual turnover? If you answer yes to both, you are likely an “important” or “especially important” entity within the meaning of Section 28 BSIG.

Important: this classification doesn't arrive by official notice. You are yourself obliged to check whether the law applies to you — and to register if it does (Section 33 BSIG).

Missed the deadline — now what?

The uncomfortable truth first: a missed registration deadline is a regulatory-offence risk. The good news: late registration is still possible, and a late voluntary registration beats no registration at all in every realistic scenario. Supervisory authorities, by experience, draw a very clear line between “dealt with it late” and “never dealt with it”.

The process itself is manageable: document properly whether you're affected, register through the BSI portal (via “Mein Unternehmenskonto”), name a point of contact — and start on the substantive obligations in parallel, because registration is only the beginning.

Registration is the smallest part

Registering makes you visible — it doesn't make you audit-ready. Section 30 BSIG requires a bundle of risk-management measures: from risk analysis and incident handling to backup concepts and supply-chain security, through to multi-factor authentication and training. And Section 38 BSIG puts management personally on the hook: they must implement the measures, oversee their implementation, and undergo regular training themselves.

Our advice: don't tear open every construction site in a panic — prioritise instead. Registration and the reporting process first (24-hour reporting deadlines already apply), then the measures by risk. This prioritisation is exactly what our compass handles in Compliverse: interview, exposure analysis, a sorted action plan.

The next step

Want to know what applies to your company? The scope check takes thirty seconds.

Start the check

Further reading