Skip to content

NIS2: BSI grace period expires, fines move closer

In brief: After the expiry of the NIS2 grace period, the BSI is now pursuing fines against companies that have not yet registered.

The grace period set by the Federal Office for Information Security (BSI) for NIS2 registration has expired. Affected companies and entities must now expect fines if they have still not complied with their reporting obligation.

The Zeitung für kommunale Wirtschaft (ZFK) reports that the grace period granted by the BSI for registration under NIS2 has expired. Affected operators and entities that have not yet registered must now expect consequences from the authority, specifically the threat of fines.

For CISOs and security officers at companies falling under the expanded scope of the NIS2 Directive, this creates immediate pressure to act. Anyone who has so far postponed or overlooked the registration obligation risks not only formal sanctions but also increased regulatory scrutiny, which could lead to further reviews of the implementation of security measures.

In practice, affected organizations are advised to promptly review their own status regarding NIS2 applicability and to submit a late registration to the BSI without delay if this has not yet been done. At the same time, CISOs should document the status of implementation of technical and organizational security measures in order to be prepared to respond in the event of a regulatory inquiry.


Source: news.google.com · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: