{"id":12071,"date":"2026-03-20T11:45:00","date_gmt":"2026-03-20T11:45:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/10\/nis2-registration-requirement\/"},"modified":"2026-07-09T17:12:48","modified_gmt":"2026-07-09T17:12:48","slug":"nis2-registration-requirement","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/03\/20\/nis2-registration-requirement\/","title":{"rendered":"Missed NIS2 Registration Deadline? Practical Checklist \u00a730 BSIG"},"content":{"rendered":"<p style=\"display:inline-block;background:#69d8ed;color:#fff;padding:4px 14px;border-radius:20px;font-size:0.85em;margin-bottom:18px;\">7 Min. read<\/p>\n<p><strong>March 6, 2026, marked the deadline. Three months after the NIS2 Implementation Act came into force, around 29,500 companies had to register with the BSI. The result: Only 38.5 percent made it. Those not registered now risk fines of up to 10 million euros and personal liability for managing directors. This article explains what \u00a7 30 BSIG specifically requires, where the most common gaps lie, and what IT security teams need to do now.<\/strong><\/p>\n<h2>Key Takeaways<\/h2>\n<ul>\n<li>\ud83d\udd12 Only 11,500 out of 29,500 obligated companies registered with the BSI on time (Security Insider 2026).<\/li>\n<li>\u26a0\ufe0f \u00a7 30 BSIG defines ten minimum measures for risk management, from incident response to cryptography.<\/li>\n<li>\ud83d\udee1\ufe0f Personal liability for managing directors under \u00a7 38 BSIG: Managing directors must approve, monitor, and undergo training for measures.<\/li>\n<li>\ud83d\udcca Fines: Up to 10 million euros or 2 percent of global annual revenue for particularly important institutions (\u00a7 65 BSIG).<\/li>\n<li>\ud83d\udd27 The BSI is currently focusing on awareness rather than immediate penalties but has been conducting on-site inspections since January 2026.<\/li>\n<\/ul>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">The registration deadline has passed<\/h2>\n<p>The NIS2 Implementation Act (NIS2UmsuCG) came into force on December 6, 2025, without any transitional periods. From this day on, all obligations applied. Three months later, on March 6, 2026, the deadline for BSI registration ended. The BSI had activated the registration portal on January 6, 2026.<\/p>\n<p>The numbers after the deadline are sobering: Out of around 29,500 obligated institutions, only about 11,500 registered, according to industry reports. That corresponds to 38.5 percent. The majority of affected companies are thus formally in default.<\/p>\n<p>For comparison: Under the old IT Security Act, the BSI supervised around 4,500 organizations. With NIS2, this number has increased more than sixfold. Many of the newly affected companies have had no previous contact with BSI regulation and significantly underestimate the effort required to implement the minimum measures.<\/p>\n<div class=\"evm-stat evm-stat-row\" style=\"display:flex;gap:16px;margin:32px 0;\">\n<div style=\"flex:1;text-align:center;background:#f0f9fa;border-radius:8px;padding:20px 12px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:28px;font-weight:700;color:#69d8ed;\">29,500<\/div>\n<div style=\"font-size:12px;color:#b8c5ce;margin-top:4px;\">Obligated institutions<\/div>\n<\/div>\n<div style=\"flex:1;text-align:center;background:#f0f9fa;border-radius:8px;padding:20px 12px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:28px;font-weight:700;color:#69d8ed;\">38.5 %<\/div>\n<div style=\"font-size:12px;color:#b8c5ce;margin-top:4px;\">Registered on time<\/div>\n<\/div>\n<div style=\"flex:1;text-align:center;background:#f0f9fa;border-radius:8px;padding:20px 12px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:28px;font-weight:700;color:#69d8ed;\">10 Mio. \u20ac<\/div>\n<div style=\"font-size:12px;color:#b8c5ce;margin-top:4px;\">Max. fine<\/div>\n<\/div>\n<\/div>\n<p style=\"font-size:12px;color:#888;text-align:center;margin-top:-16px;\">Sources: BSI press release Dec. 2025, Security Insider Mar. 2026, \u00a7 65 BSIG<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Who is affected? The Impact Check<\/h2>\n<p>NIS2 distinguishes two categories. If you fall into one of them, you are required to register.<\/p>\n<p><strong>Critical entities:<\/strong> With 250 or more employees or an annual turnover of \u20ac50 million and a balance sheet total of at least \u20ac43 million. These companies are proactively and regularly audited by the BSI. Fines: up to \u20ac10 million or 2 percent of global annual turnover.<\/p>\n<p><strong>Important entities:<\/strong> With 50 or more employees or an annual turnover of \u20ac10 million. The BSI only conducts reactive audits here, i.e., in case of suspected violations or after a security incident. Fines: up to \u20ac7 million or 1.4 percent of global annual turnover.<\/p>\n<p>In total, NIS2 covers 18 sectors. Eleven of them are considered critical: energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT services, public administration, and space. Seven other sectors are classified as important: postal services, waste management, chemicals, food industry, manufacturing, digital providers, and research.<\/p>\n<p>The most common misconception: &#8220;We&#8217;re too small.&#8221; In reality, the threshold is 50 employees or \u20ac10 million in turnover. Many medium-sized businesses that never considered themselves KRITIS-relevant fall below this threshold. Particularly tricky: Subsidiaries and affiliated companies can also exceed the threshold values due to their corporate affiliation.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">\u00a7 30 BSIG: The ten minimum measures in detail<\/h2>\n<p>The core of the NIS2 implementation law for practical purposes is outlined in \u00a7 30 paragraph 2 BSIG. There, the legislator defines ten areas that every affected entity must cover. None of these measures are optional.<\/p>\n<p><strong>1. Risk analysis and security concepts.<\/strong> Companies need documented concepts for risk analysis and information security. Not just on paper: The BSI checks whether these concepts are current, complete, and adapted to the actual IT landscape.<\/p>\n<p><strong>2. Incident Management.<\/strong> Security incidents must be identified, classified, and managed. The BSI expects defined reporting paths, escalation processes, and documented follow-up. <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/17\/identity-security-gap-what-zero-trust-doesnt-protect-and-how-to-close-it\/\">Experience shows<\/a>: Many companies have incident response plans that do not work in real emergencies.<\/p>\n<p><strong>3. Business Continuity.<\/strong> Business continuity, backup management, recovery from emergencies, and crisis management. Not just technical: Organizational processes for emergencies must also be defined and regularly tested in exercises. A backup concept on paper is useless if recovery has never been practiced.<\/p>\n<p><strong>4. Supply Chain Security.<\/strong> The security of the supply chain, including direct suppliers and service providers. This is one of the biggest gaps: Many companies do not know the security practices of their IT service providers. NIS2 requires these risks to be systematically recorded and contractually controlled. This also affects cloud providers, managed service providers, and software suppliers.<\/p>\n<p><strong>5. Secure procurement and development.<\/strong> Security measures for the acquisition, development, and maintenance of IT systems. For companies with their own software development, this means: Security by Design becomes mandatory, not optional. The <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/16\/sbom-practical-check-how-your-company-implements-the-software-bill-of-materials-by-september-2026\/\">SBOM practical check<\/a> shows how the software bill of materials helps with this.<\/p>\n<p><strong>6. Effectiveness assessment.<\/strong> Companies must not only implement measures but also regularly assess their effectiveness. Penetration tests, audits, and security metrics thus become mandatory. The assessment must be documented and presented to the management.<\/p>\n<p><strong>7. Training and awareness.<\/strong> Basic cybersecurity training for all employees. Not a one-time event, but continuous. The management has its own training obligation according to \u00a7 38 BSIG, which cannot be delegated.<\/p>\n<blockquote style=\"border-left:4px solid #69d8ed;margin:32px 0;padding:20px 24px;background:#fafafa;border-radius:0 8px 8px 0;font-size:1.1em;line-height:1.6;color:#333;\"><p>\n&#8220;Companies need reliable framework conditions.&#8221;<br \/>\n<cite style=\"display:block;margin-top:12px;font-size:0.8em;color:#888;font-style:normal;\">Ralf Wintergerst, President Bitkom (Bitkom Press Information, 2025)<\/cite>\n<\/p><\/blockquote>\n<p><strong>8. Cryptography.<\/strong> Concepts and processes for the use of cryptographic methods. This affects encryption in transit, at rest, and in communication. Companies must document which algorithms they use and why. Outdated methods such as SHA-1 or RSA with less than 2048 bits are no longer acceptable.<\/p>\n<p><strong>9. Access control and personnel management.<\/strong> Security of personnel, access control to systems, and administration of ICT systems. Identity and Access Management (IAM) thus becomes a compliance issue, not just a security issue. The principle of least privilege must be consistently implemented and demonstrably documented.<\/p>\n<p><strong>10. Multi-Factor Authentication and secure communication.<\/strong> MFA or continuous authentication as well as secured voice, video, and text communication. Anyone who does not have MFA for critical systems is no longer compliant from now on. Particularly relevant for companies that use Microsoft Teams or similar platforms for confidential communication.<\/p>\n<div class=\"evm-stat evm-stat-highlight\" style=\"text-align:center;background:#f0f9fa;border-radius:12px;padding:32px 24px;margin:32px 0;\">\n<div style=\"font-size:48px;font-weight:700;color:#69d8ed;letter-spacing:-0.03em;\">18.350<\/div>\n<div style=\"font-size:15px;color:#444;margin-top:8px;\">Companies have missed the registration deadline<\/div>\n<div style=\"font-size:12px;color:#888;margin-top:8px;\">Source: Security Insider \/ digital-magazin.de, March 2026<\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">\u00a7 38 BSIG: Why Managing Directors Are Personally Liable<\/h2>\n<p>Perhaps the most significant innovation of NIS2 is outlined in \u00a7 38 BSIG. Managing directors and board members are personally liable for implementing risk management measures. Three obligations are legally anchored.<\/p>\n<p><strong>Approval Obligation:<\/strong> The risk management measures under \u00a7 30 must be formally approved by the management. Delegation to the CISO or IT management is not sufficient. The management must demonstrably have made the decision.<\/p>\n<p><strong>Monitoring Obligation:<\/strong> Managing directors must actively monitor the implementation. Not just be informed, but steer. The BSI can demand proof that this monitoring is taking place.<\/p>\n<p><strong>Training Obligation:<\/strong> Management must regularly undergo training in cybersecurity. This obligation cannot be delegated. A refresher is due at least every three years.<\/p>\n<p>Particularly relevant: A liability waiver by the company is legally excluded. Even those who have appointed a CISO remain personally responsible for strategic control. Those who cannot prove that they have fulfilled the three obligations after an incident are liable with their personal assets.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What the BSI Does After March 6<\/h2>\n<p>After the registration deadline, the BSI has indicated that it will initially focus on awareness rather than immediate penalties. No fines have been publicly announced so far. However, this does not mean that nothing is happening.<\/p>\n<p>Since January 2026, the BSI has been conducting on-site inspections at particularly important facilities. The first results show three recurring weaknesses: reporting processes that do not work in an emergency, unknown dependencies in the supply chain, and logging systems that are insufficient for BSI inspections.<\/p>\n<p>For companies that are not yet registered, this means: the grace period is not a free pass. The registration itself takes only a few hours. But implementing the measures under \u00a7 30 takes weeks to months. Those who are just starting should prioritize: register immediately, then incident management and access control as quick wins, and simultaneously set up the complete <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/15\/dora-and-nis2-simultaneously-how-financial-service-providers-manage-the-compliance-double-pressure\/\">compliance roadmap<\/a>.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Immediate Checklist: What IT Security Teams Need to Do Now<\/h2>\n<p><strong>Step 1: Affected Check.<\/strong> Check: More than 50 employees or more than 10 million euros in revenue? Active in one of the 18 sectors? If yes: You are affected.<\/p>\n<p><strong>Step 2: BSI Registration.<\/strong> If not already done: Register immediately via the BSI portal. The registration itself is straightforward. Every day of delay increases the risk of fines.<\/p>\n<p><strong>Step 3: Gap Analysis Against \u00a7 30.<\/strong> Go through the ten minimum measures individually. Where are there already processes? Where is documentation missing? Where is the measure completely missing? Result: A prioritized list of actions needed.<\/p>\n<p><strong>Step 4: Involve Management.<\/strong> Obtain a board resolution for the approval of the risk management measures. Schedule a training date for the management. Define a monitoring rhythm. Document everything.<\/p>\n<p><strong>Step 5: Map the Supply Chain.<\/strong> Which IT service providers do you use? What security standards apply there? Are there contractual arrangements? Supply chain security is the area most underestimated by companies.<\/p>\n<p><strong>Step 6: Test Reporting Processes.<\/strong> Conduct a simulated security incident. Do the escalation paths work? Does everyone know whom to inform and when? Does the report reach the BSI within the prescribed time?<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Conclusion: Registration Is the Easy Part<\/h2>\n<p>The BSI registration is completed in a few hours. The real work lies in \u00a7 30 BSIG: ten areas of measures that must be documented, implemented, and regularly reviewed. With \u00a7 38 BSIG, the personal liability of the management is added.<\/p>\n<p>Those who have not started yet should not rely on the BSI&#8217;s grace period. On-site inspections are already underway. And the question is not if, but when the first fine will be imposed.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Who Needs to Register with the BSI?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Companies with 50 or more employees or an annual revenue of 10 million euros or more, operating in one of the 18 NIS2 sectors. The registration obligation has been in effect since March 6, 2026.<\/p>\n<\/details>\n<details>\n<summary><strong>What happens if I miss the registration deadline?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The BSI is currently focusing on insight rather than immediate penalties. However, fines are possible at any time: up to 10 million euros or 2 percent of the global annual turnover for particularly important facilities. Register immediately.<\/p>\n<\/details>\n<details>\n<summary><strong>Is the managing director personally liable?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes. \u00a7 38 BSIG obliges managing directors to approve, monitor, and undergo their own cybersecurity training. A liability waiver by the company is legally excluded. The obligation is not delegable to the CISO.<\/p>\n<\/details>\n<details>\n<summary><strong>What are the ten minimum measures according to \u00a7 30 BSIG?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Risk analysis, incident management, business continuity, supply chain security, secure procurement and development, effectiveness evaluation, training, cryptography, access control, and multi-factor authentication. All ten areas must be documented and implemented.<\/p>\n<\/details>\n<details>\n<summary><strong>Does NIS2 also apply to medium-sized businesses?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes. The threshold is 50 employees or 10 million euros in turnover. Many medium-sized businesses that never considered themselves relevant to KRITIS fall under NIS2. Particularly affected: manufacturing industry, food economy, and digital providers.<\/p>\n<\/details>\n<div class=\"evm-styled-box\" style=\"background:#f0f9fa;border-radius:8px;padding:20px 24px;margin:24px 0;border-top:3px solid #69d8ed;\">\n<h2 style=\"margin-top:0;margin-bottom:12px;font-size:1.05em;\">Editor&#8217;s Reading Recommendations<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/15\/dora-and-nis2-simultaneously-how-financial-service-providers-manage-the-compliance-double-pressure\/\">DORA and NIS2 simultaneously: How financial service providers master the compliance double pressure<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/16\/sbom-practical-check-how-your-company-implements-the-software-bill-of-materials-by-september-2026\/\">SBOM practical check: Implementing the software bill of materials by September 2026<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/17\/identity-security-gap-what-zero-trust-doesnt-protect-and-how-to-close-it\/\">Identity Security Gap: What Zero Trust doesn&#8217;t protect<\/a><\/li>\n<\/ul>\n<\/div>\n<div style=\"background:#f0f9fa;border-radius:8px;padding:20px 24px;margin:24px 0;border-top:3px solid #69d8ed;\">\n<!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/15\/dora-and-nis2-simultaneously-how-financial-service-providers-manage-the-compliance-double-pressure\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/dora-nis2-gleichzeitig-compliance-doppeldruck-finanzdienstleister-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">DORA &#038; NIS2: How Financial Firms Manage Compliance Double\u2026<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/16\/sbom-practical-check-how-your-company-implements-the-software-bill-of-materials-by-september-2026\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/03\/sbom-praxischeck-software-stueckliste-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">SBOM Practical Check: How to Implement SBOM<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/17\/identity-security-gap-what-zero-trust-doesnt-protect-and-how-to-close-it\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/03\/identity-security-gap-cybersecurity-250x167.jpeg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Identity Security Gap: What Zero Trust Misses and How to Close It<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/en\/tech-mandates-on-the-supervisory-board-nis2-the-eu-ai-act-and-the-skills-gap\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-tech-mandate-aufsichtsrat-nis2-eu-ai-act-39094777-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Tech Mandates on the Supervisory Board: NIS2, the EU AI Act, and the Skills Gap<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/nis2-implementation-mid-sized-companies-obligations-fines-2026\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-nis2-umsetzung-mittelstand-pflichten-bus-5121759-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">NIS2 Implementation: What Mid-Sized Companies Still Need to Do<\/span><\/span><\/a><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/06\/13\/nis2-and-dora-separate-compliance-cluster-in-kubernetes\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-nis2-und-dora-sauber-trennen-compliance-12173800.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Separating NIS2 and DORA Compliance: A Compliance Cluster in Kubernetes<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/cybersecurity-boom-why-nis2-is-turning-germanys-security-industry-into-a-growth\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-cybersecurity-boom-nis2-deutschlands-sic-39412011-250x166.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Cybersecurity Boom: NIS2 Drives Germany\u2019s Security Growth<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"The BSI registration deadline expired on March 6, 2026. Only 38.5% of affected companies registered on time. What \u00a730 BSIG requires, why executives face personal liability, and what IT security teams must do now.","protected":false},"author":10,"featured_media":5468,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"NIS2 registration obligation","_yoast_wpseo_title":"Missed NIS2 Registration Deadline? The Practical Checklist Under \u00a730 BSIG","_yoast_wpseo_metadesc":"NIS2 registration deadline expired: Only 38.5% registered. What \u00a7 30 BSIG requires and why management boards are personally liable.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[255,259],"tags":[],"class_list":["post-12071","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en","category-strategie-governance-en"],"evm_reading_time_minutes":11,"wpml_language":"en","wpml_translation_of":5461,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=12071"}],"version-history":[{"count":10,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12071\/revisions"}],"predecessor-version":[{"id":21684,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12071\/revisions\/21684"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/5468"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=12071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=12071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=12071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}