{"id":17793,"date":"2026-06-16T18:50:00","date_gmt":"2026-06-16T18:50:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=17793"},"modified":"2026-06-16T20:39:10","modified_gmt":"2026-06-16T20:39:10","slug":"nis2-after-the-deadline-now-the-bsi-supervision-begins","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/06\/16\/nis2-after-the-deadline-now-the-bsi-supervision-begins\/","title":{"rendered":"NIS2 after the deadline: Now the BSI supervision begins"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">6 min read<\/p>\n<p style=\"line-height:1.8;margin-bottom:20px;\"><strong>The registration deadline for NIS2 expired on 6 March 2026, marking the end of the implementation phase. Around 29,000 organisations in Germany fall under the NIS2 Implementation Act, with the BSI serving as the central supervisory authority. 2026 is therefore the year when the question is no longer whether you\u2019re registered, but whether your reported measures can withstand scrutiny. Those who set things up properly gain a maturity advantage rather than a disadvantage in the EU comparison.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">The phase shifts.<\/strong> With the registration deadline passed on 6 March 2026, the focus moves from registration to supervision. The BSI can now conduct audits, issue orders, and impose sanctions.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Liability is personal.<\/strong> For essential entities, fines can reach up to 10 million Euro or 2% of global annual turnover-whichever is higher. This is in addition to the personal accountability of management.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Early maturity pays off.<\/strong> Those who meet obligations now are prepared for the next wave of supervision and already meet the EU minimum standard.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#004a59;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/29\/nis2-vollstreckung-2026-bsi-audit-persoenliche-haftung\/\" style=\"color:#333;text-decoration:underline;\">NIS2 enforcement underway: First proceedings, personal liability<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was\/\" style=\"color:#333;text-decoration:underline;\">NIS2 enforcement impacts 29,500 German companies<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">The deadline has passed, supervision begins<\/h2>\n<p>The NIS2 Implementation Act was announced on 6 December 2025 and has been in effect without a transition period since then. The registration obligation with the BSI expired on 6 March 2026. Late registrations remain possible, but this doesn\u2019t change the key point: obligations are already in force, and the supervisory authority is operational.<\/p>\n<p><strong>What is the NIS2 supervision phase?<\/strong> The supervision phase is the period following the registration deadline, during which the BSI actively monitors compliance with legal security measures. It can request evidence, initiate audits, issue orders, and impose fines for violations. The focus shifts from formal registration to substantive review.<\/p>\n<p>For security leaders, this changes priorities. During the implementation phase, the goal was completeness of reporting. Now, it\u2019s about resilience: can the reported measures be substantiated, are reporting channels tested, and is accountability documented?<\/p>\n<div class=\"evm-stat-highlight\" style=\"text-align:center;background:#003340;border-radius:12px;padding:32px 24px;margin:32px 0;\">\n<div style=\"font-size:48px;font-weight:700;color:#69d8ed;letter-spacing:-0.03em;\">around 29,000<\/div>\n<div style=\"font-size:15px;color:#fff;margin-top:8px;max-width:430px;margin-left:auto;margin-right:auto;\">organisations in Germany fall under NIS2, spanning 18 sectors and two categories.<\/div>\n<div style=\"font-size:12px;color:#69d8ed;margin-top:8px;\">Source: BSI \/ NIS2 Implementation Act<\/div>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Why Germany\u2019s Implementation Goes Beyond the Minimum Standard<\/h2>\n<p>The NIS2 Directive sets a European framework that each member state transposes into national law. The 18 covered sectors and the two categories of entities are already defined by the EU directive. However, Germany has taken a stricter stance on one critical point: the personal accountability of management, which in severe cases can extend to the revocation of supervisory approval. This could be seen as an additional burden-but there\u2019s a more compelling interpretation.<\/p>\n<p>Companies that meet Germany\u2019s requirements inherently meet the EU\u2019s minimum standards-and often exceed them. For businesses operating across multiple EU countries, this is a practical advantage: a security level that satisfies German regulators will typically pass muster in neighboring countries as well. What might seem like extra effort becomes a common benchmark.<\/p>\n<p>This isn\u2019t a reason for complacency, but it does counter the narrative of pure regulatory burden. The maturity built now pays dividends beyond German oversight.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What the Supervisory Phase Means in Practice<\/h2>\n<p>In concrete terms, supervision means the BSI (Federal Office for Information Security) no longer has to wait for an incident to take action. It can request evidence on a case-by-case basis or proactively, depending on how an entity is classified. Security leaders should prepare three key things.<\/p>\n<p>First, *demonstrable compliance*: risk analyses, technical and organizational measures, and their effectiveness must be documented and retrievable-not just implemented. Second, the *reporting chain*: deadlines for incident notifications to the BSI are tight, and the process should be rehearsed before it matters in a crisis. Third, *governance*: since management is personally liable, security must be elevated to the executive level, not just confined to IT.<\/p>\n<p>None of these requirements are new. What *is* new is that their absence can now have immediate consequences.<\/p>\n<div class=\"evm-timeline\" style=\"margin:32px 0;border:1px solid #e5e5e5;border-radius:6px;overflow:hidden;\">\n<div style=\"background:#003340;color:#fff;padding:12px 18px;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.14em;\">NIS2 Timeline in Germany<\/div>\n<div style=\"padding:8px 0;\">\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:120px;font-weight:700;color:#69d8ed;\">06.12.2025<\/div>\n<div style=\"color:#333;line-height:1.55;\">The NIS2 Implementation Act is promulgated and takes effect without a transition period.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:120px;font-weight:700;color:#69d8ed;\">06.03.2026<\/div>\n<div style=\"color:#333;line-height:1.55;\">The registration deadline with the BSI expires; late registrations remain possible.<\/div>\n<\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;\">\n<div style=\"min-width:120px;font-weight:700;color:#69d8ed;\">from 2026<\/div>\n<div style=\"color:#333;line-height:1.55;\">Supervisory phase: The BSI reviews measures, requests evidence, and can impose sanctions.<\/div>\n<\/div>\n<\/div>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What If You Missed the Deadline?<\/h2>\n<p>Late registration with the BSI is still possible-but it doesn\u2019t provide a grace period. Legal obligations have been in force since the law\u2019s promulgation in December 2025, regardless of whether an entity registered on time. Those catching up now are only completing a formality while their substantive responsibilities have long been active.<\/p>\n<p>For latecomers, the practical steps are clear: register first, then swiftly establish demonstrable compliance. If a reportable incident occurs before measures are verifiable, a missed or delayed registration will weigh against you. The order isn\u2019t about ticking boxes-it\u2019s about managing risk.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<h3>What does the end of the NIS2 registration deadline mean?<\/h3>\n<p>The deadline to register with the BSI as an affected entity expired on March 6, 2026. However, the obligations themselves have been in force since the law\u2019s promulgation on December 6, 2025. The focus now shifts to supervision: the BSI will verify whether the reported measures have been implemented.<\/p>\n<h3>Who is affected by NIS2 in Germany?<\/h3>\n<p>Approximately 29,000 entities across 18 sectors fall under the law, divided into essential and important entities. This includes newly covered companies, operators of critical infrastructure, and certain federal institutions.<\/p>\n<h3>What Penalties Threaten in Case of Violations?<\/h3>\n<p>For particularly critical entities, fines can reach up to 10 million Euro or 2 percent of global annual turnover-whichever is higher. For important entities, the upper limit is lower. On top of that, management faces personal liability, with the possibility of losing supervisory authority in severe cases.<\/p>\n<h3>Why Is Germany\u2019s Implementation Considered Strict?<\/h3>\n<p>Germany has gone beyond the EU\u2019s minimum NIS2 requirements, particularly in holding leadership personally accountable-even to the point of revoking supervisory authority in extreme cases. Companies meeting these standards typically already satisfy the European baseline.<\/p>\n<h3>What Should Companies Prioritize Now?<\/h3>\n<p>Three key actions: ensuring traceability of security measures, establishing a tested incident reporting chain, and embedding security responsibility at the leadership level. This preparation determines whether a BSI audit proceeds without issues.<\/p>\n<h3>Editor\u2019s Reading Recommendations<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/24\/zero-trust-at-the-energy-supplier-what-the-nis2-audits-are-now-revealing\/\">Zero Trust for Energy Providers: What NIS2 Audits Are Uncovering Now<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/22\/dora-and-nis2-why-bank-audits-are-now-colliding\/\">DORA and NIS2: Why Bank Audits Are Colliding<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/25\/whatsapp-signal-nis2-requirements-management-messenger-architecture-2026\/\">Signal Communication Risks NIS2 Non-Compliance<\/a><\/li>\n<\/ul>\n<p style=\"margin:32px 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#666;\">More from the MBF Media Network<\/p>\n<div style=\"padding:14px 18px;border-left:3px solid #0bb7fd;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#0bb7fd;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">cloudmagazin<\/div>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/2026\/06\/13\/nis2-und-dora-sauber-trennen-compliance-cluster-in-kubernetes\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Keeping NIS2 and DORA Separate: Compliance Clusters in Kubernetes<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #202528;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#202528;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">mybusinessfuture<\/div>\n<p><a href=\"https:\/\/mybusinessfuture.com\/nis2-umsetzung-mittelstand-pflichten-bussgeld-haftung-2026\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">NIS2 Implementation: A Checklist for SMEs Now<\/a><\/p>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #d65663;background:#fafafa;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#d65663;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">digital-chiefs<\/div>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/tech-mandate-aufsichtsrat-nis2-eu-ai-act-governance-2026\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">NIS2 and the EU AI Act Reveal the Skills Gap<\/a><\/p>\n<\/div>\n<p style=\"font-size:.8em;color:#888;margin-top:1.5em;\">Cover image: AI-generated (June 2026)<\/p>\n","protected":false},"excerpt":{"rendered":"The NIS2 oversight has begun: the BSI registration deadline has passed, and the authority is now reviewing and imposing sanctions.","protected":false},"author":10,"featured_media":17795,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"NIS2 Supervision","_yoast_wpseo_title":"NIS2 after the deadline: Now the BSI supervision begins","_yoast_wpseo_metadesc":"NIS2 supervision begins: BSI registration deadline has passed, now authority checks and sanctions. Gain a competitive edge with early preparation.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[3,2,217,251],"tags":[],"class_list":{"0":"post-17793","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","6":"hentry","7":"category-aktuelles","8":"category-innovation","10":"category-news"},"evm_reading_time_minutes":6,"wpml_language":"en","wpml_translation_of":17785,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17793","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=17793"}],"version-history":[{"count":1,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17793\/revisions"}],"predecessor-version":[{"id":17794,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/17793\/revisions\/17794"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/17795"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=17793"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=17793"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=17793"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}