A deadline that was never really a deadline

Germany's NIS2 implementation law, the BSI-Gesetz (BSIG), took effect on December 6, 2025, and required roughly 29,500 companies and public bodies across energy, health, transport and digital infrastructure to register with the Federal Office for Information Security by March 6, 2026. Registration opened through the BSI's own portal in January 2026, but by the statutory deadline only a fraction of that number had filed. Facing a compliance rate its own officials called too low to enforce, the BSI announced it would accept late registrations and refrain from sanctions through July 31, 2026 - a grace window, not a new legal date.

The BSI's own tracking page, 'NIS-2 in Zahlen,' put the count at 17,729 registered entities as of June 30, 2026, split into 11,501 'important' and 6,215 'particularly important' organizations, including 1,342 designated critical infrastructure (KRITIS) operators. Independent legal and trade reporting citing the BSI's own end-of-July figures puts registrations at roughly 18,500 to 19,000 once the grace window closed - meaning somewhere between 10,500 and 11,800 expected entities, close to a third of the total, still were not in the system when forbearance ended.

The utilities paradox

VKU, the association representing Germany's municipal utilities (Stadtwerke), told trade press that the registration gap in its sector is not a story of companies ignoring the law. Its stated view: 'the complex affiliation analysis, particularly for multi-sector companies, is in our view the primary reason registrations were so limited,' adding that the classification review 'is so complicated that it is barely possible without external professional legal assistance.' Many Stadtwerke sit simultaneously in energy, water, wastewater and sometimes telecoms, and NIS2's sector-by-sector affiliation test forces each of those lines of business through its own qualifying analysis before a single registration can be filed.

That detail matters more than a headline compliance percentage. The entities NIS2 was written to protect first - grid operators, water utilities, district heating networks - are structurally the ones most likely to trip over the law's own onboarding logic, precisely because they are multi-sector by design. A gap concentrated among generalist small businesses would be a training problem; a gap concentrated among municipal critical-infrastructure operators is a design problem in the law's own gateway.

The three-month blind spot

Here is the part the deadline coverage missed. The BSI's own figures page states its next update is 'not expected before October 31, 2026' - meaning the regulator's public registration count will sit unrefreshed for exactly the quarter in which its sanction forbearance lifted. Any German 'important' or 'particularly important' entity now has legal supply-chain obligations toward its own vendors and partners, and any EU or UK counterparty running NIS2-adjacent due diligence on a German supplier has no live source to check against - only a snapshot that was already six weeks stale on the day forbearance ended, and will be nearly four months stale before it refreshes.

Because registration itself changes nothing about an organization's actual security posture - it is a bureaucratic gateway, not a technical control - firms with the most to lose from being publicly identified as late have every reason to file quietly now rather than announce the gap. Expect Germany's public numbers to look meaningfully better by Halloween even though the intervening months contain an uncounted population of exposed entities. The practical takeaway for any business relying on a German critical-infrastructure or digital-services supplier: ask for BSIG registration confirmation directly, in writing, now - not in November, when the BSI's own number will already be out of date again.