The BSI's final registration window for NIS 2 closed on 31 July 2026. What German essential and important entities should expect now and where ISO 27001 helps.
On 31 July 2026, the last piece of leniency in Germany's NIS 2 implementation expired.
That date was never a statutory deadline. The statutory deadline was 6 March 2026 — three months after the NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG) entered into force on 6 December 2025. When only around 11,500 of an estimated 29,500 in-scope entities had registered by March, the Bundesamt für Sicherheit in der Informationstechnik wrote to industry associations and set a clear expectation: outstanding registrations completed by 31 July 2026.
That expectation has now passed. Registration remains mandatory, and remains possible — but from here on it is a late registration against a supervisor that has already entered its active phase.
If your organisation is in scope and still unregistered, this article explains where you stand. If you registered on time, it explains what the BSI is likely to ask for next, and why registration was the easy part.
The single most consequential line in that table is the third one. Germany transposed NIS 2 roughly a year late, and the legislature compensated by giving affected organisations no runway at all. The technical and organisational measures required under § 30 BSIG have been legally binding since 6 December 2025 — not since March, and not from some future date.
This produces a persistent misunderstanding. Registration is an administrative notification. It is not what the law requires you to do. An entity that registered promptly in January and has implemented nothing is in a worse position than an unregistered entity with a mature ISMS — it has simply told the supervisor where to look.
Under the amended BSIG, scope turns on two questions: which sector you operate in, and how large you are.
Essential entities (besonders wichtige Einrichtungen) are generally large organisations in the sectors of high criticality listed in Annex 1 — energy, transport, banking and financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space. "Large" means at least 250 employees, or turnover above €50 million together with a balance sheet total above €43 million. Operators of critical installations (former KRITIS operators) are always essential entities regardless of size.
Important entities (wichtige Einrichtungen) are the remaining in-scope organisations meeting the medium-size thresholds — broadly 50 or more employees, or turnover and balance sheet total above €10 million — across both Annex 1 and Annex 2 sectors. Annex 2 adds postal and courier services, waste management, chemicals, food, manufacturing (including medical devices, computers and electronics, machinery, motor vehicles), digital service providers and research organisations.
Two practical notes. First, the distinction between essential and important is not cosmetic: essential entities face ex ante supervision — the BSI can inspect proactively — while important entities face ex post supervision, triggered by indications of non-compliance. Second, the sector lists reach considerably further than most boards assume. Manufacturing and food are in scope. So is a mid-sized managed service provider. The German domain industry was pulled in by the same amendment.
Self-assessment is your responsibility, and getting it wrong in either direction is expensive. The BSI publishes a Q&A catalogue and a non-binding impact assessment to help; low registration numbers suggest that uncertainty about scope, rather than unwillingness, is the main obstacle.
Section 30 mirrors Article 21(2) of the Directive: appropriate, proportionate and effective technical and organisational measures, across ten areas.
Proportionality is explicit in § 30(1): the assessment weighs the entity's exposure, size, the likelihood and severity of incidents, and their societal and economic impact. This is a risk-based obligation, not a fixed control list — which means you must be able to justify where you landed, not merely assert it.
Alongside the measures sit three further duties that are commonly overlooked:
§ 32 — reporting. Significant incidents must be reported through a three-stage cascade: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within one month. Twenty-four hours is a process problem before it is a security problem. If your on-call engineer does not know who decides that an incident is reportable, at 03:00, on a Sunday, you do not have a compliant process.
§ 38 — management duties. Managing directors must implement and monitor the § 30 measures, and must undergo regular training. This duty is personal and cannot be delegated. Breach exposes management to internal liability.
§ 39 — proof obligation for operators of critical installations. Operators of critical installations must demonstrate implementation to the BSI through security audits, examinations or certifications, at a point set by the BSI and every three years thereafter — including disclosure of the deficiencies those audits uncovered. Note the statutory wording: Sicherheitsaudits, Prüfungen oder Zertifizierungen. Certification is one accepted route.
Sanctions scale with category. Fines reach up to €10 million or 2% of worldwide annual turnover for essential entities and €7 million or 1.4% for important entities, whichever is higher; failure to register is a separate administrative offence carrying up to €500,000 under § 65 BSIG.
NIS 2 does not mandate certification. It does require an information security management system in substance, and it requires you to prove it to a supervisor on request.
Practitioner assessments and mapping exercises consistently put ISO/IEC 27001:2022 coverage of the § 30 measure areas at roughly 70–80%, with high coverage on eight of the ten Article 21 measures. That figure is worth reading carefully in both directions.
What a certified ISMS gives you:
What it does not give you:
Two published references make this gap analysis considerably cheaper than doing it from scratch. ENISA's Technical Implementation Guidance for Commission Implementing Regulation (EU) 2024/2690 maps every Article 21 measure against ISO/IEC 27001:2022, NIST CSF 2.0, ETSI EN 319 401 and CEN/TS 18026:2024, and lists the kind of evidence an assessor expects for each point. In June 2026 the NIS Cooperation Group published its own reference document on security measures with a comparable mapping table. Both are non-binding, both are cited by authorities, and ENISA is explicit that its mapping should not be read as a statement of equivalence.
Used properly, they turn "are we NIS 2 compliant?" into a finite list of delta items against controls you already operate.
If you have not registered: register. Late registration does not cure the § 33 breach, but it demonstrates active steps toward compliance, and the alternative is being identified by the supervisor rather than identifying yourself. Budget time for the Mein Unternehmenskonto and ELSTER certificate prerequisites — organisations routinely underestimate this step.
If you have registered: stop treating registration as the milestone. Assume the next contact from the BSI is a request for evidence, and work backwards from that.
Proks Certification is DAkkS-accredited for ISO/IEC 27001:2022 (D-ZM-21753-01-00), recognised internationally through the IAF Multilateral Recognition Arrangement. Our audit approach is risk-first rather than checklist-first, which matters here: NIS 2 asks whether your measures are appropriate and proportionate to your exposure, and that is the same question a well-run ISMS audit asks.
We also offer NIS 2 readiness assessments as a special audit — a structured gap analysis against § 30 BSIG and the ENISA mapping, delivered as a prioritised findings report. This is not an accredited certification and we do not present it as one; it is a way to know where you stand before a supervisor tells you.
If you are certified to ISO 27001 and want to know what remains, or you are in scope and starting from a standing position, get in touch.
Last reviewed: 3 August 2026. This article describes the legal position in Germany and is not legal advice. Scope determination under the BSIG remains the responsibility of the entity.
Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.