Today's deadline is not in the law
The BSI's grace period for NIS2 registration ends on 31 July. The statutory deadline was 6 March. Why that difference matters, and why the actual obligations never depended on registration in the first place.
Today the BSI's grace period for NIS2 registration ends. In many posts over recent weeks this sounded like the date on which the obligations begin. It is not, and the difference is more than quibbling over words.
Two dates worth keeping apart
The German NIS2 implementation act took effect on 6 December 2025, with no transition period. Section 33 BSIG requires registration no later than three months after first falling within scope. For everyone already in scope when the act took effect, that deadline expired on 6 March 2026. Today's date is something else: a grace period set by the BSI for outstanding registrations. That is a statement about enforcement practice, not a change in the law.
In practice: whoever registers today is not on time. They are roughly five months late. That is no reason to skip it, but it is a reason to know your own chronology before the supervisory authority asks.
The obligations never depended on registration
This is the part that gets lost in the deadline debate. Registration is a notification that you are in scope. It is not the switch that turns the obligations on. Risk management under section 30 BSIG and the reporting duties under section 32 BSIG have applied since the act took effect, regardless of whether an organisation was registered.
For the reporting duties this is uncomfortably concrete. Section 32 works in three stages: an early warning within 24 hours, a notification within 72 hours and a final report after one month. Anyone who suffered a significant security incident in spring and was not registered was still subject to those deadlines. The missing registration did not suspend the duty to report; it merely meant nobody reminded them of it.
So what the grace period closes, and what it does not
It closes a formality. It does not close the gap that opened in December. The honest question on the day after registration is therefore not "are we registered" but: since when have we been obliged, what happened in the meantime, and could we evidence it? A reporting path used for the first time during a real incident rarely meets 24 hours.
How isidaten runs the part after registration
The platform brings together exactly the areas that remain once the entry is made. Incident reporting manages cases with the stages and deadlines from section 32, so the 24 hours are not spent hunting for who is responsible. The risk register links risks to measures and their effectiveness review instead of letting them end in an assessment spreadsheet. Supplier management and the asset inventory provide the basis, because neither supply chain security nor risk management can be run without a reliable inventory.
Product-related context, not legal advice. The authoritative information on registration and deadlines is published by the BSI. More on implementation on the NIS2 solution page; why registration and implementation are two different states was covered here earlier.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.