Skip to content

NIS2: the 31 July checkpoint

Germany’s NIS2 implementation act has been in force since 6 December 2025. The registration duty fell due on 6 March 2026 and roughly a third of affected organisations still had not registered by the end of May. The BSI expects full implementation by 31 July 2026 — this is administrative forbearance, not a new legal deadline.

Diese Seite auf Deutsch

NIS2UmsuCG in force
6 Dec 2025
Statutory registration deadline
6 Mar 2026
Organisations in scope in Germany
~30,000
Registered by end of May 2026
~18,500
BSI expects full implementation
31 Jul 2026

Where things actually stand

The 31 July 2026 date is frequently reported as an extension. It is not. The statutory registration deadline was 6 March 2026, and organisations that missed it have been in default since. What the BSI has signalled is that it expects registration and implementation to be complete by 31 July, which is a supervisory posture rather than a change in the law.

The practical reading: registering late is better than not registering, and the exposure does not reset on 1 August. Late registration alone is subject to a separate penalty band.

The 10-point checklist

Ten questions worth answering before the end of July. Most take minutes; the ones that do not are the ones worth knowing about now rather than during an incident.

  1. Confirm whether you are in scope

    Scope follows sector plus size thresholds across the sectors named in the act — and it is self-assessed. Nobody sends you a letter. If you are a supplier to an in-scope organisation, read point 10 as well.

  2. Register with the BSI

    Registration runs through the BSI registration portal. If you missed 6 March, register anyway — the exposure grows with the delay, it does not expire.

  3. Name the responsible management

    NIS2 attaches duties and personal liability to management. Record who holds them, and that they have been briefed.

  4. Document your risk-management measures

    The act sets out a defined catalogue of risk-management measures. The point of the documentation is that it exists before you need it, not that it is perfect.

  5. Be able to detect a significant incident

    The reporting duties assume detection. A duty to report within 24 hours is unmeetable if you learn about the incident from a customer a week later.

  6. Rehearse the 24-hour early warning

    The reporting cadence runs early warning within 24 hours, an update at 72 hours, and a final report within a month. Know who writes them and what evidence they attach.

  7. Cover external attack surface, not just internal systems

    A cloned login page on a lookalike domain is outside your perimeter and squarely aimed at your users, customers, and staff. It is external attack surface you are expected to be aware of.

  8. Keep evidence you can hand over

    Screenshots, DNS and certificate records, timestamps, and a verdict trail. An incident report backed by evidence is a different conversation from one backed by recollection.

  9. Check business-continuity and crisis contacts

    Reachability at 2am matters more than the document. Verify the contacts, not the file.

  10. Ask what your customers will ask you

    In-scope organisations must address security in their supply chain. If you sell into one, expect the questionnaire — and expect domain impersonation to be on it.

Where domain-impersonation monitoring fits

Impersona is not a NIS2 compliance suite and does not claim to make you compliant. It covers one specific slice — the part where somebody registers a domain that looks like yours and stands up a page against your users.

ReferenceDutyWhat monitoring contributes
§ 30 BSIGRisk-management measuresContinuous certificate-transparency and newly-registered-domain monitoring of your brand’s external attack surface, with a documented verdict per finding.
§ 32 BSIGReporting duties — early warning within 24 hoursDetection at the point the certificate is issued rather than at the point a customer complains, plus an evidence pack (screenshot, DOM similarity, DNS and certificate records, timestamps) to attach to the report.
Supply-chain securityAddressing security among direct suppliersA monthly report you can hand to a customer who asks how you monitor for impersonation of your own brand.

See your own exposure first

Run a free check on your domain. It returns the lookalike domains that exist right now, their status, and a verdict on the ones that matter. No account needed to see the result.

Questions

Did the NIS2 registration deadline move to 31 July 2026?
No. The statutory registration deadline was 6 March 2026. The BSI has indicated it expects registration and implementation to be complete by 31 July 2026, which is administrative forbearance rather than a change to the deadline. Organisations that missed 6 March have been in default since that date.
How many German organisations are affected?
Roughly 30,000 organisations across the sectors named in the act. About 11,500 had registered by the original 6 March 2026 deadline and about 18,500 by the end of May 2026, leaving on the order of 10,500 still unregistered.
What are the penalties?
The act sets fines of up to €10 million or 2% of worldwide annual turnover for essential entities, and up to €7 million or 1.4% for important entities. Late registration carries its own separate penalty band. Management bears personal responsibility for the risk-management duties.
Is a lookalike domain a reportable incident?
It depends on impact, and that judgement is yours to make — a parked lookalike domain is usually not a significant incident, while a live credential-harvesting clone of your login page targeting your customers may well be. Either way, the reporting duties presuppose that you can detect it and evidence it, which is the part monitoring addresses.
Does Impersona make my organisation NIS2 compliant?
No, and we would not claim it. NIS2 spans governance, supply chain, business continuity, incident handling, and more. Impersona covers external domain-impersonation monitoring and the evidence trail for it — one input to the risk-management and reporting duties, not the whole obligation.

Sources

This page is information, not legal advice. Facts were verified against the sources above on the date shown; NIS2 supervision is evolving, so re-check before relying on any of it. For your own obligations, talk to counsel. (2026-07-26)