Skip to content
Book a call
🇩🇪 Deutsch 🇬🇧 English 🇫🇷 Français
Flagships
Perstat Uptime monitoring, incident management and status pages for teams who promise availability. NextPKI Find, renew and manage certificates, whoever issued them. Databurg Audit-proof compliance documentation for companies with reporting duties.
Trust & crypto
sqlclient A native database client for macOS. Local, with no detour via someone else's servers. FoldMail An email client with encryption that is meant seriously, S/MIME and OpenPGP. Claro An app for separated parents: handovers, arrangements and costs in one place.
Bundle of the month
Reliability Bundle

Perstat + NextPKI as a single billed package. NIS2 evidence and certificate lifecycle from one cockpit.

Learn more
Learn
Blog Release notes, compliance news, roadmap. Careers
Trust
Legal & privacy DPA, sub-processor list.
Bundle of the month
Reliability Bundle

Perstat + NextPKI as a single billed package. NIS2 evidence and certificate lifecycle from one cockpit.

Learn more
Products Perstat NextPKI Databurg sqlclient FoldMail Claro
Imprint
Language
🇩🇪 Deutsch 🇬🇧 English 🇫🇷 Français
Book a call
Skip to content
NIS2 & Resilience

NIS2 Registration: Why 31 July 2026 Is the Deadline That Counts

20.07.2026 · 3 min read

The statutory registration deadline passed on 6 March 2026, and the BSI now expects outstanding registrations by the end of July. Who is in scope, how self-assessment works, and why registration is only the beginning.

The three-month registration window under the German NIS2 Implementation Act closed on 6 March 2026. Yet for many entities the more important date is a different one: 31 July 2026. By that day the BSI expects the outstanding registrations and treats late submissions with practical leniency until then. Of around 29,500 companies in scope, only about 11,500 had registered by the statutory deadline, rising to roughly 18,500 by the end of May. A substantial share is therefore still missing.

The right way to read this extension matters. It is a tolerance on registration, not a postponement of the law. The substantive obligations have applied since 6 December 2025, regardless of whether an entity has already come forward.

Registration is not an administrative act, it is self-assessment

Unlike the old KRITIS system, the BSI does not issue a notice declaring who is in scope. Every entity has to determine for itself whether it falls under the law and, if so, register actively. This self-assessment under Section 28 BSIG is the real first step, not filling in the portal form.

Broadly: important entities from 50 employees or more than 10 million euros in annual turnover, particularly important entities from 250 employees or more than 50 million euros in turnover. Membership of one of the 18 sectors also has to apply. Certain entities count regardless of size, such as qualified trust service providers, DNS and TLD operators, or providers of public electronic communications services. Anyone who assesses too narrowly and wrongly classifies themselves as out of scope carries that risk alone.

Who has to act by the end of July

In scope is anyone who meets the criteria and has not yet registered. Right now that is mainly entities that have not assessed their status, and those that have assessed it but deferred registration. Both can be caught up in the remaining days; registration itself is the smaller effort.

The larger effort is the honest stocktake behind it: does my company fall under the law, and do I already meet the obligations that have applied since December? Whoever completes the registration without answering that question has filed a form but gained little in substance.

The obligations apply independently of registration

Registration is the entry ticket, not the obligation itself. Section 30 requires risk-management measures, among them monitoring, logging, incident handling, business continuity and supply-chain security. Section 32 governs the staggered reporting duties, with an early warning within 24 hours, a notification within 72 hours and a final report within one month. Section 38 puts management on the hook, and Section 65 sets the frame with fines of up to 10 million euros.

These obligations have been running since 6 December 2025. The leniency at the BSI changes nothing here. An entity that registers on 31 July but failed to report a significant incident in June was already in default at that point.

What makes sense now

Three steps help immediately: document your scope assessment under Section 28 cleanly, so the classification is defensible if questioned; complete the registration while the BSI’s leniency applies; and set up detection so that the 24-hour early warning is realistically achievable. A single rehearsed reporting run quickly reveals where an incident chronology breaks.

In our Perstat module, monitoring, security posture and an append-only audit trail are connected so that the incident chronology required for Section 32 can be produced traceably. The point itself, though, is independent of any tool, namely to settle your own scope and not to mistake the one-off registration for the ongoing obligations.

Registration is the beginning of the duty, not its end.

Back to the blog

Datargo Datargo

Datargo GmbH, Frankfurt am Main. We build and operate our own software products on our own infrastructure in the European Union.

EU hosting, Frankfurt GDPR-native Made in Germany
Products
  • Perstat
  • NextPKI
  • Databurg
  • sqlclient
  • FoldMail
  • Claro
Company
  • Contact
  • Careers
  • Blog
  • Status page
Legal
  • Imprint
  • Privacy
© 2026 Datargo GmbH. All rights reserved.
Germany · English

Datargo® and Databurg® are registered trademarks of Datargo GmbH. All other product names, logos, and trademarks mentioned are the property of their respective owners.