NIS2: the 31 July checkpoint
Germany’s NIS2 implementation act has been in force since 6 December 2025. The registration duty fell due on 6 March 2026 and roughly a third of affected organisations still had not registered by the end of May. The BSI expects full implementation by 31 July 2026 — this is administrative forbearance, not a new legal deadline.
- NIS2UmsuCG in force
- 6 Dec 2025
- Statutory registration deadline
- 6 Mar 2026
- Organisations in scope in Germany
- ~30,000
- Registered by end of May 2026
- ~18,500
- BSI expects full implementation
- 31 Jul 2026
Where things actually stand
The 31 July 2026 date is frequently reported as an extension. It is not. The statutory registration deadline was 6 March 2026, and organisations that missed it have been in default since. What the BSI has signalled is that it expects registration and implementation to be complete by 31 July, which is a supervisory posture rather than a change in the law.
The practical reading: registering late is better than not registering, and the exposure does not reset on 1 August. Late registration alone is subject to a separate penalty band.
The 10-point checklist
Ten questions worth answering before the end of July. Most take minutes; the ones that do not are the ones worth knowing about now rather than during an incident.
Confirm whether you are in scope
Scope follows sector plus size thresholds across the sectors named in the act — and it is self-assessed. Nobody sends you a letter. If you are a supplier to an in-scope organisation, read point 10 as well.
Register with the BSI
Registration runs through the BSI registration portal. If you missed 6 March, register anyway — the exposure grows with the delay, it does not expire.
Name the responsible management
NIS2 attaches duties and personal liability to management. Record who holds them, and that they have been briefed.
Document your risk-management measures
The act sets out a defined catalogue of risk-management measures. The point of the documentation is that it exists before you need it, not that it is perfect.
Be able to detect a significant incident
The reporting duties assume detection. A duty to report within 24 hours is unmeetable if you learn about the incident from a customer a week later.
Rehearse the 24-hour early warning
The reporting cadence runs early warning within 24 hours, an update at 72 hours, and a final report within a month. Know who writes them and what evidence they attach.
Cover external attack surface, not just internal systems
A cloned login page on a lookalike domain is outside your perimeter and squarely aimed at your users, customers, and staff. It is external attack surface you are expected to be aware of.
Keep evidence you can hand over
Screenshots, DNS and certificate records, timestamps, and a verdict trail. An incident report backed by evidence is a different conversation from one backed by recollection.
Check business-continuity and crisis contacts
Reachability at 2am matters more than the document. Verify the contacts, not the file.
Ask what your customers will ask you
In-scope organisations must address security in their supply chain. If you sell into one, expect the questionnaire — and expect domain impersonation to be on it.
Where domain-impersonation monitoring fits
Impersona is not a NIS2 compliance suite and does not claim to make you compliant. It covers one specific slice — the part where somebody registers a domain that looks like yours and stands up a page against your users.
| Reference | Duty | What monitoring contributes |
|---|---|---|
| § 30 BSIG | Risk-management measures | Continuous certificate-transparency and newly-registered-domain monitoring of your brand’s external attack surface, with a documented verdict per finding. |
| § 32 BSIG | Reporting duties — early warning within 24 hours | Detection at the point the certificate is issued rather than at the point a customer complains, plus an evidence pack (screenshot, DOM similarity, DNS and certificate records, timestamps) to attach to the report. |
| Supply-chain security | Addressing security among direct suppliers | A monthly report you can hand to a customer who asks how you monitor for impersonation of your own brand. |
See your own exposure first
Run a free check on your domain. It returns the lookalike domains that exist right now, their status, and a verdict on the ones that matter. No account needed to see the result.
Questions
- Did the NIS2 registration deadline move to 31 July 2026?
- No. The statutory registration deadline was 6 March 2026. The BSI has indicated it expects registration and implementation to be complete by 31 July 2026, which is administrative forbearance rather than a change to the deadline. Organisations that missed 6 March have been in default since that date.
- How many German organisations are affected?
- Roughly 30,000 organisations across the sectors named in the act. About 11,500 had registered by the original 6 March 2026 deadline and about 18,500 by the end of May 2026, leaving on the order of 10,500 still unregistered.
- What are the penalties?
- The act sets fines of up to €10 million or 2% of worldwide annual turnover for essential entities, and up to €7 million or 1.4% for important entities. Late registration carries its own separate penalty band. Management bears personal responsibility for the risk-management duties.
- Is a lookalike domain a reportable incident?
- It depends on impact, and that judgement is yours to make — a parked lookalike domain is usually not a significant incident, while a live credential-harvesting clone of your login page targeting your customers may well be. Either way, the reporting duties presuppose that you can detect it and evidence it, which is the part monitoring addresses.
- Does Impersona make my organisation NIS2 compliant?
- No, and we would not claim it. NIS2 spans governance, supply chain, business continuity, incident handling, and more. Impersona covers external domain-impersonation monitoring and the evidence trail for it — one input to the risk-management and reporting duties, not the whole obligation.
Sources
- SCHUTZWERK — NIS-2: Registrierungsstand und Nachfrist (2026-07-26)
- secjur — NIS2: Pflichten, Fristen, Bußgelder (2026-07-26)
- BSI — NIS-2 registration portal and guidance (2026-07-26)
This page is information, not legal advice. Facts were verified against the sources above on the date shown; NIS2 supervision is evolving, so re-check before relying on any of it. For your own obligations, talk to counsel. (2026-07-26)