In brief: Around 29,500 German companies must register their facilities with the BSI by 31 July, otherwise they face fines.
On 31 July 2024, a central registration deadline under the NIS2 Directive expires – approximately 29,500 German companies must have registered their facilities with the Federal Office for Information Security (BSI) by then.
The EU’s NIS2 Directive requires operators of critical infrastructure and providers of services in the digital sector to document their cybersecurity measures and notify their facilities to the BSI. 31 July 2024 marks the regulatory deadline for this first registration wave in Germany.
For compliance officers, this creates an immediate obligation to act: companies falling within NIS2’s scope – particularly those with more than 250 employees or annual turnover exceeding 50 million euros in relevant sectors – must have completed their registration. Failure to comply can result in administrative fines.
Registration takes place via the BSI portal and requires an accurate self-assessment of the operator’s function, the security measures implemented, and any existing certifications. The BSI provides guidance and support, but has also announced that it will review submissions after the deadline and forward any discrepancies to the competent authorities.
Source: news.google.com · Published 16 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.