NIS2 Registration: The 31 July 2026 Deadline Has Passed – Why Businesses Should Now Complete Their BSI Registration Without Delay
The BSI grace period ended on 31 July 2026 – yet the registration obligation remains in force. What applies now, and why registering immediately is the only sensible step.
Update, 11 August 2026: The grace period communicated by the BSI expired on 31 July 2026. We have fully revised this article – it now describes the legal situation after the deadline. The key message up front: the registration obligation remains in force by law. Anyone who has missed it should register without delay.
Germany's NIS2 implementation law (NIS2UmsuCG) has been in force since 6 December 2025. With it came the statutory registration obligation with the Federal Office for Information Security (BSI) – with an original deadline of 6 March 2026. The BSI subsequently stated – communicated via a letter to the industry associations – that it expected all outstanding registrations to be completed by 31 July 2026 at the latest. That grace period has now passed as well.
What matters now: the obligation did not lapse with the deadline. The registration obligation under § 33 BSIG continues to apply unchanged – it is only fulfilled once the registration has actually been completed. The BSI itself puts it this way on its website: the statutory registration deadline "has already expired" – combined with a call to all affected entities to register "immediately in the BSI portal" now (our translation).
Note: This article is not legal advice. It provides an overview of the current legal situation and recommended next steps. Please consult a specialist lawyer or certified IT security advisor for your individual situation. Last updated: 11 August 2026.
Anyone who keeps waiting now does not improve their position – on the contrary: the failure to register is subject to fines and continues with every day that passes without registration. Registering late is the only way to end the violation.
Who needs to register with the BSI?
The registration obligation under § 33 BSIG applies to particularly important entities and important entities. The thresholds:
- Particularly important entities: from around 250 employees or €50M turnover and a €43M balance sheet – in sectors such as energy, water, transport, healthcare, finance, and digital infrastructure.
- Important entities: from around 50 employees or €10M turnover – in sectors such as logistics, machinery, food production, chemicals, postal and courier services, and digital services.
The BSI assumes around 29,500 affected companies and federal administration bodies in Germany. At the end of the deadline on 31 July 2026, the BSI reported 18,845 registered entities to trade media (6,490 particularly important, 12,355 important) – measured against the BSI estimate, around a third were still missing; the Federal Ministry of the Interior is currently having that estimate reviewed by the Federal Statistical Office. The BSI had communicated the grace period via the industry associations and asked them to remind their members of the obligation. So do not wait for an individual letter – the obligation exists regardless.
What applies now, after 31 July 2026?
Three points stand out:
1. The registration obligation remains in force A statutory obligation does not disappear because its deadline has passed. § 33 BSIG requires the registration details to be submitted – anyone who has failed to do so must make up for it, without delay. Late registration ends the ongoing violation and documents to the BSI that the entity takes its obligations seriously.
2. Failure to register is subject to fines Anyone who, contrary to § 33 BSIG, fails to submit the required information, or does not do so correctly, completely or on time, commits an administrative offence (§ 65 (2) no. 6 BSIG). The law provides for a fine of up to €500,000 for this. The frequently cited higher ranges – up to €10 million for particularly important entities and up to €7 million for important entities, or, for entities with annual turnover above €500 million, 2% and 1.4% of total turnover respectively – apply to more serious violations, such as breaches of the risk management and reporting obligations. After the deadline, the BSI told trade media that it had so far refrained from enforcement measures and was monitoring developments closely. Speculating that this will remain the case would be the wrong strategy: a fine does not require a security incident, and anyone who has completed the late registration is better off in every scenario than anyone who remains inactive.
3. Management duties under § 38 BSIG § 38 BSIG obliges management to implement the prescribed risk management measures and to monitor their implementation; they must also regularly attend training. If they culpably breach these duties, they are liable to their entity for the damage under the applicable rules of company law. A managing director who knows the obligations and still remains inactive bears that risk.
The two-step BSI registration process
Registering with the BSI is not a simple online form. It runs in two steps – and both need lead time:
Step 1: Apply for an ELSTER business account (MUK)
The first step is identification via the ELSTER business account (MUK). If your company does not yet have a valid ELSTER certificate, apply for it now at www.elster.de. Experience shows that postal delivery of the activation data takes up to two weeks. Without a certificate there is no access to the BSI portal – so this step determines how quickly you can complete the late registration.
Step 2: Register in the BSI portal
The registration portal at portal.bsi.bund.de has been open since 6 January 2026. There you enter master data, sector, and category. Have the following information ready:
- Company master data and trade register number
- Assignment to the applicable KRITIS sector (several, if your business operates across sectors)
- Contact details of the security point of contact (SPOC) – a specific, reachable person, not a shared mailbox
- ELSTER certificate for secure identification
Registration is not the same as compliance
Registering in the BSI portal is mandatory – but only the beginning. NIS2 additionally requires:
- Risk management measures: risk analysis, security concept, access controls, MFA, encryption, patch management.
- Reporting obligations: significant security incidents must be reported to the BSI within 24 hours (initial report) and within 72 hours (preliminary report).
- Supply chain security: affected companies are obliged to pass security requirements on to their suppliers and service providers – this also affects SMBs below the thresholds if they work for NIS2-obligated customers.
- Documentation: all measures must be verifiable.
In short: anyone who is registered but has no tested backups, no current security concept, and no MFA remains non-compliant.
Typical mistakes that cost time now
In practice, many businesses trip over the same points:
- ELSTER certificate still missing: The application takes up to two weeks – start immediately.
- Wrong sector selected: Anyone operating in several sectors must state all applicable ones; incorrect entries can be corrected later but cost time.
- No SPOC named: The BSI expects a named, reachable contact person for security incidents.
- Confusing registration with NIS2 compliance: Portal registration fulfils § 33 BSIG – but not the substantive requirements of §§ 30–37 BSIG.
What does this mean for businesses in the Ruhr region?
The thresholds exclude most small craft businesses, retailers, and practices in Recklinghausen and the surrounding area from the direct obligation. For mid-sized companies with 50 or more employees or more than €10M in turnover – particularly in logistics, food production, chemicals, or as IT service providers – the question of whether they are covered must, however, be taken seriously.
Smaller SMBs should also know: if your major customers are subject to NIS2, these security requirements will be passed on to you by contract. The question is then no longer whether you are affected, but when the next auditor will come knocking.
Conclusion: register now – not eventually
The deadline has passed; the obligation has not. There is no way back to before 31 July – but there is a clear way forward: register without delay. Every additional day without registration prolongs the violation; late registration ends it. That is exactly what the BSI is currently and explicitly calling for.
Check first whether your business exceeds the thresholds and falls into one of the regulated sectors. If so: start the ELSTER application immediately, name a SPOC, and open the BSI portal.
Not sure whether your company is required to register – or want to combine the late registration with a solid NIS2 foundation right away? We support companies in the Ruhr region with both. Feel free to get in touch.
Note: The articles on this blog are produced with the help of AI and are editorially reviewed before publication. Editorial responsibility lies with Emre Yurtbay (see the Impressum).