German Firms Face Crunch Time as NIS2 Registration Deadline Looms
Published on 07/30/2026 at 08:21 | Redaktion boerse-global.de
Just 11,500 out of an estimated 29,500 companies have registered with Germany’s Federal Office for Information Security (BSI) ahead of the 31 July 2026 deadline. That leaves roughly 18,000 businesses — many of them mid-sized — exposed to fines that can reach millions of euros.
The NIS2 implementation law has been in force since 6 December 2025. It applies to any company with at least 50 employees or annual revenue of €10 million. The original March 2026 cut-off was pushed back once, yet the extension appears to have done little to spur action.
While cybersecurity is a growing regulatory focus, workplace safety compliance carries its own legal weight. Many employers underestimate the documentation gap in their risk management processes. A free toolkit with 41 ready-to-use checklists and templates helps you systematically identify and record workplace hazards. Download the free Risk Assessment Toolkit
Compliance Gaps and Operational Headaches
Under § 30 BSIG, affected firms must implement ten minimum measures, including risk management and supply-chain security. Industry observers say the sluggish registration rate signals a deeper problem: cybersecurity still isn’t treated as a priority in the Mittelstand.
A study by Plusserver found that only 34 percent of companies have fully met NIS2 requirements. Nearly half of those surveyed described the process as difficult. The main bottleneck? Ageing operational technology. In the industrial sector, 48 percent of firms cite legacy OT systems as a barrier. Older equipment often cannot support modern security architectures and rarely receives regular updates. Experts recommend a phased approach using network segmentation and zero-trust identity management to block attackers from moving laterally across networks.
New Rules for Hardware Makers
NIS2 is not the only regulation bearing down on German business. The EU’s Cyber Resilience Act (CRA) adds obligations for manufacturers of products with digital components. On 27 July 2026, the European Commission published a guideline listing 67 examples of the new duties.
From 11 September 2026, initial reporting obligations kick in: manufacturers must send an early warning to CSIRT and ENISA within 24 hours of discovering actively exploited vulnerabilities or serious security incidents. Full CRA compliance is due by 11 December 2027. Companies such as the Shelly Group, which took full control of its development arm Shelly Tech in late July 2026, are already streamlining internal processes to meet the timeline.
Heavy Penalties and Personal Liability
The financial stakes are high. NIS2 violations can draw fines of up to €10 million or 2 percent of worldwide annual turnover. Under § 38 BSIG, company directors face personal liability. CRA penalties are even steeper — up to €15 million or 2.5 percent of turnover.
Sectors deemed critical face extra scrutiny. Water utilities must comply with specific industry standards (B3S) and DVGW regulations. Financial services have been subject to the DORA regulation since January 2025.
The same principle of documented compliance applies to hazardous substances in the workplace. Over 37,000 UK businesses already use a free COSHH toolkit with 43 customisable templates and toolbox talks to meet their legal duties for dangerous substance risk assessments. Get the free COSHH Toolkit
Because more than 80 percent of security incidents involve employee actions, experts urge firms to combine technical safeguards — such as anomaly detection in OT environments — with regular security-awareness training. The Federal Ministry for Economic Affairs also provides funding for companies to introduce ISO 27001-certified information security management systems.
Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.
