Law & Compliance · 2026-09-07 · 14 min read

NIS2 in the German mid-market: the BSI counts 17,729 registered entities, the legislator budgeted for around 30,000. The gap sits almost entirely with important entities

Michael Kaiser

Michael Kaiser

Co-Founder & Head of Systems, Vincency

The German BSI publishes a page called NIS-2 in Zahlen. It carries a single sentence that deserves more attention than it gets: as of 30 June 2026, 17,729 entities had registered in the BSI portal, of which 11,501 were important entities and 6,215 essential entities. Including branch and cross-border registrations the total comes to 17,945.

Taken on its own the number reads like progress. Set against what the legislator expected, it reads differently. The impact assessment behind the German NIS2 implementation act worked with roughly 30,000 entities, split into about 8,250 essential and about 21,600 important ones. Put the two sets side by side and the picture stops being ambiguous.

CategoryExpected by the legislatorRegistered as of 30 June 2026Coverage
Essential entitiesapprox. 8,2506,215approx. 75%
Important entitiesapprox. 21,60011,501approx. 53%
Total (portal)approx. 29,85017,729approx. 59%

Two remarks on the arithmetic, because precision matters more here than a clean headline. First, the two sub-figures add up to 17,716, thirteen short of the stated total of 17,729; the BSI does not break down the difference. Second, the roughly 30,000 is an estimate from the legislative process, not a register. Nobody holds a definitive list of entities in scope, which is exactly the structural problem this article is about. The coverage column should therefore be read as an order of magnitude, not as a precise quota.

What survives that caveat is the asymmetry between the two rows. Among essential entities roughly three in four have registered. Among important entities barely more than half. And important entities are, almost by definition, the German mid-market: from 50 employees upwards.

Why the gap sits where it sits

The reason is not defiance. It is a misunderstanding built into the vocabulary. German public debate has discussed cybersecurity regulation for a decade under the heading of kritische Infrastruktur, critical infrastructure. That term evokes power grids, hospitals, water utilities. A managing director of a machine tool manufacturer with 90 employees hears it and concludes, entirely reasonably, that none of this concerns them.

Under the current BSIG that conclusion is wrong, and the reason is Annex 2.

Annex 1 versus Annex 2: the distinction that decides

The BSIG works with two annexes, and they do very different jobs.

Annex 1 covers the sectors that match the intuitive picture: energy, transport, finance, health, water, digital infrastructure, space. This is where the operators of critical installations sit, and this is what most people mean when they say critical infrastructure.

Annex 2 covers something else entirely, and it is the one that catches the mid-market:

  • Postal and courier services
  • Waste management
  • Production of, manufacture of and trade in chemical substances
  • Production, processing and distribution of food
  • Manufacturing and production of goods, with mechanical engineering as an explicit sub-category
  • Providers of digital services
  • Research

Manufacturing. Mechanical engineering. Chemicals. Food. These are not edge cases of the German economy, they are its centre of gravity. A firm in any of these sectors that reaches the size threshold is an important entity under Section 28(2) no. 3 BSIG, with the full catalogue of obligations, and without ever operating anything that resembles critical infrastructure in the colloquial sense.

The thresholds, precisely

Section 28 BSIG sets out two size bands, and the connectors between the criteria matter as much as the numbers.

CategoryEmployeesFinancial thresholdApplies to
Essential entity
Section 28(1) no. 4
at least 250or turnover above 50m euros and balance sheet total above 43m eurosAnnex 1 sectors
Important entity
Section 28(2) no. 3
at least 50or turnover and balance sheet total each above 10m eurosAnnex 1 and Annex 2 sectors

Note the structure of the important entity test: 50 employees or the financial thresholds. A company of 55 people with modest turnover is in scope through the headcount alone. Conversely a company of 30 people that clears both financial thresholds is in scope without reaching the headcount. Both routes are open, and only one of them needs to be satisfied.

In the size band this firm works with most often, 10 to 500 employees, the practical dividing line therefore falls at 50. Below it the question is usually settled. Above it, in an Annex 1 or Annex 2 sector, the answer is usually yes.

The deadline has passed. That changes less than it seems

The act was promulgated in the Federal Law Gazette on 5 December 2025 and entered into force without a transition period. Section 33(1) BSIG gives entities three months from the point at which they first qualify to register with the BSI. On its page for regulated companies the BSI now states plainly that the statutory registration deadline has already expired.

Some read that as a closed door. It is the opposite. An expired deadline does not extinguish the duty, it converts an approaching obligation into a present breach that continues for as long as the registration is missing. Three consequences follow.

The breach is ongoing, not historic. Every additional week of non-registration is another week of non-compliance, not a fading past event.

The BSI can act on its own. Section 33(3) BSIG allows the federal office to carry out the registration itself where an entity fails to do so. Being registered from the outside is materially worse than registering voluntarily, because it documents that the entity did not act.

The registration is the smallest of the duties. It is an administrative act taking a few hours: an ELSTER organisational certificate via the Mein Unternehmenskonto service, then registration in the BSI portal with name, legal form, contact data, IP ranges, sector, member states served and competent authorities. The substantive obligations under Sections 30, 32 and 38 are the demanding part, and they apply whether or not anyone has registered.

What lands on management personally

Section 38 BSIG is the provision that turns NIS2 from an IT topic into a management topic. It has three subsections and each does distinct work.

Subsection 1 obliges management to implement the risk management measures under Section 30 and to supervise their implementation. The second half is what cannot be outsourced. Instructing the IT department to handle NIS2 discharges the implementation duty at best; the supervisory duty remains with the management body.

Subsection 2 governs liability for culpably caused damage. The primary route runs through the company law of the respective legal form, so for a GmbH through the managing director duties in the GmbH Act. Where company law contains no matching provision, the BSIG steps in directly, which closes the gap for legal forms that would otherwise fall through.

Subsection 3 requires management to attend regular training so as to acquire sufficient knowledge to identify and assess risks and to judge their effect on the services provided. This is a duty owed by the management body itself. Awareness training for staff, however sensible, does not discharge it.

For a managing director the practical question is not whether the firewall is current. It is whether they can demonstrate, on a specific date, that they reviewed the measures and satisfied themselves that they work. That is a documentation question long before it is a technology question.

Fines: what actually applies to the mid-market

Coverage of NIS2 reliably quotes ten million euros or two percent of worldwide turnover. The first half is right for one category. The second half is, for almost every mid-sized company, simply not applicable.

Section 65 BSIG sets absolute maxima in subsection 5: up to ten million euros for essential entities and up to seven million euros for important entities in cases of breaches of risk management and reporting duties, descending through five million, two million, one million, 500,000 and 100,000 euros for other categories of breach. A missed registration sits at the 500,000 euro level.

The turnover-based alternative appears in subsections 6 and 7, and it is conditional: two percent for essential entities and 1.4 percent for important entities, applicable to entities with total turnover above 500 million euros. Below that threshold the percentage rule does not enter the calculation at all. A manufacturer with 80 million euros in turnover cannot be fined two percent of turnover under this provision.

None of these are standard penalties. They are the upper end of a statutory range, and regulators calibrate within it. The reason to read them precisely is not comfort but proportion: exaggerated numbers produce either paralysis or dismissal, and both are worse than an accurate picture.

The supply chain: in scope without being in scope

The most underestimated provision for smaller firms is Section 30(2) no. 4 BSIG. Among the ten areas of measures it lists security of the supply chain including security-related aspects of the relationships with direct suppliers or service providers.

An entity in scope cannot discharge that duty internally. It has to reach into its supplier relationships, which means questionnaires, security annexes to contracts, evidence of measures and agreed reporting channels. Those requirements arrive at suppliers who are frequently well below any NIS2 threshold themselves.

For a supplier this produces a commercial question rather than a legal one. Being unable to answer a customer questionnaire does not trigger a fine. It puts the contract at risk, and increasingly it decides whether a firm makes the shortlist at all. Companies that can answer credibly are beginning to treat it as a differentiator, which is the more useful way to look at it.

Proportionality: the clause that makes this workable

Section 30(2) BSIG lists ten areas: risk analysis and information security policies, incident handling, business continuity including backup and crisis management, supply chain security, security in acquisition, development and maintenance of systems, assessing the effectiveness of measures, training and awareness, cryptography, personnel security and access control, and multi-factor authentication with secured communications.

Read as a list it looks like a corporate programme. What makes it workable is Section 30(1) sentence 2, an explicit proportionality clause: the extent of risk exposure, the size of the entity, the cost of implementation and the likelihood and severity of incidents are all to be weighed.

That clause is doing real work. It means a firm of 70 people owes measures appropriate to a firm of 70 people. It does not mean the areas are optional. Each of the ten has to be addressed, but the depth is calibrated. In practice this is why an exposure assessment belongs before any tooling decision, and certainly before a certification project.

The reporting chain: 24 hours, 72 hours, one month

Section 32 BSIG sets a staged reporting duty to a joint reporting office run by the BSI and the Federal Office of Civil Protection.

StageDeadlineContent
Early warningwithin 24 hours of becoming awareWhether unlawful or malicious acts are suspected and whether cross-border effects are possible
Incident reportwithin 72 hoursConfirmation and update of the early warning, severity, impact, indicators of compromise
Interim reporton request of the BSIRelevant status updates
Final reportwithin one month of the reportDetailed description, root cause, remedial measures, cross-border effects

The 24-hour clock is the operationally demanding element. It starts on becoming aware, not on completing the analysis, and it runs through weekends. Meeting it requires a decision path defined in advance: who assesses whether an incident is significant, who is authorised to report, and what happens if that person is unreachable. Firms that have to invent this during an incident will miss the window, which is why the reporting path belongs in the incident plan rather than in a policy document.

NIS2, the Cyber Resilience Act and the Data Act are three different things

Three regulatory strands are frequently conflated in board discussions because all three mention cybersecurity. Keeping them apart saves a great deal of wasted effort.

NIS2 regulates you as an operator. It asks how you secure your own operations, and it attaches to sector and size.

The Cyber Resilience Act regulates you as a manufacturer. It attaches to products with digital elements that you place on the market, irrespective of your sector. We covered its reporting obligations in a separate piece on the CRA reporting duties for the mid-market.

The Data Act regulates data access for connected products and applies from 12 September 2026, as set out in our article on the Data Act and connected products.

A machine builder can be caught by all three simultaneously and in three different capacities: as an operator under NIS2, as a manufacturer under the CRA, and as a data holder under the Data Act. The obligations do not merge, and neither do the deadlines.

What to do in the next four weeks

A sequence that works, in the order that produces answers fastest.

1. Establish exposure in writing. Sector against Annexes 1 and 2, headcount and financial figures against Section 28. The output is one page with a dated result and the reasoning. Even a documented negative finding is worth having, because the question will be asked again, by a customer or an insurer.

2. If in scope, register. The ELSTER organisational certificate is usually the longer part of the process. The BSI portal itself is quick once the certificate exists.

3. Define the reporting path before you need it. Named individuals, deputies, out-of-hours reachability, and the decision rule for what counts as significant. This is the one item that cannot be improvised.

4. Compare the ten areas against what already exists. Most firms have more in place than they think, and rarely have it documented. The gap is usually evidence, not substance.

5. Put the supervisory duty on the agenda. A dated management review of the measures, minuted. This is what Section 38(1) actually asks for, and it is the cheapest item on the list.

None of this requires a certification project. It requires a documented answer to a question that a growing number of customers, insurers and auditors are going to ask anyway.

Sources, status and methodological note:

  • BSI, NIS-2 in Zahlen (registration figures as of 30 June 2026; the BSI announces the next update for 31 October 2026)
  • BSI, NIS-2-regulierte Unternehmen (registration process, expiry of the statutory deadline)
  • BSIG, current version: Paragraf 28, 30, 32, 33, 38, 65, Annex 1, Annex 2
  • OpenKRITIS (breakdown of the roughly 30,000 entities the legislator assumed, based on the 2024 drafts; the source itself flags that the actual scope may differ considerably)
  • Status of this article: 7 September 2026. The coverage percentages are our own calculation from the two sources named above and are an order of magnitude, not an official quota. All fine amounts are statutory maxima. This article provides orientation, not legal advice.

Related service

Turning obligations into systems

This article clarifies the legal position. It gets implemented in software and processes: product inventory, reporting channel, data access, invoice format, update documentation. We take the inventory off mid-sized companies, order the obligations by deadline and effort and, if you wish, implement them.

IT strategy consulting

Frequently asked questions on NIS2, registration duty and exposure in the mid-market

Are we in scope for NIS2 even though we do not operate critical infrastructure?

Very probably yes, if you have at least 50 employees and operate in one of the sectors listed in Annexes 1 or 2 of the BSIG. Annex 2 explicitly lists manufacturing including mechanical engineering, the production of and trade in chemicals, the production and distribution of food, postal and courier services, waste management, providers of digital services, and research. The term critical infrastructure is misleading here: it describes a narrower group, namely operators of critical installations under Annex 1. A mechanical engineering firm with 60 employees operates no critical installation, yet qualifies as an important entity under Section 28(2) no. 3 BSIG with the full set of obligations.

The registration deadline has passed. Should we still register?

Yes. On its page for regulated companies the BSI itself states that the statutory registration deadline has already expired, while keeping the portal open. The duty under Section 33 BSIG does not lapse with time, it simply remains unfulfilled. Registering now ends an ongoing breach. Waiting extends it. Section 33(3) BSIG adds a further point: if an entity fails to meet its registration duty, the federal office may carry out the registration itself. Being registered from the outside is the distinctly worse option, because it puts the breach on record.

What is a realistic fine for a mid-sized company?

For a missed registration Section 65 BSIG provides a range of up to 500,000 euros. For breaches of risk management and reporting duties the range is up to ten million euros for essential entities and up to seven million euros for important entities. The alternative of two percent of worldwide annual turnover, quoted in many articles, applies under Section 65(6) and (7) BSIG only to entities with more than 500 million euros in total turnover. For the classic mid-market the percentage rule is therefore irrelevant and the absolute amounts govern. All figures are statutory maxima, not standard penalties.

Is management personally liable?

Section 38 BSIG addresses management directly. Subsection 1 obliges them to implement the risk management measures under Section 30 and to supervise that implementation. The supervisory duty is the decisive part, because it cannot be delegated to the IT department. Subsection 2 governs liability for culpably caused damage under the company law rules of the respective legal form and applies subsidiarily even where company law contains no matching provision. Subsection 3 requires regular training of the management body itself, not of the workforce.

We are out of scope, our largest customer is in scope. What reaches us?

Questionnaires, contract clauses and evidence. Section 30(2) no. 4 BSIG requires entities in scope to take measures on supply chain security including security-related aspects of the relationships with direct suppliers or service providers. Your customer can only discharge that duty by passing it on to you. In practice this means security annexes to existing contracts, disclosure of your own measures, and reporting channels for incidents that could affect them. These requirements reach suppliers regardless of their own size and regardless of whether they are themselves subject to registration.

Do we now need ISO 27001 certification?

The law does not require it. Section 30(1) sentence 2 BSIG contains an explicit proportionality clause: the extent of risk exposure, the size of the entity, the cost of implementation and the likelihood and severity of security incidents are all to be taken into account. A business with 70 employees therefore owes something different from a corporate group. Certification can be a sensible route to producing evidence, but it is neither a precondition for nor a substitute for the ten areas of measures listed in Section 30(2). Starting with a certification instead of an exposure assessment optimises the wrong thing.