17.07.2026

9 Min. read time

As of late May 2026, around 11,000 affected companies in Germany still lack BSI registration-and the legal deadline expired on March 6. What’s being called a “grace period” is, according to law firms, merely regulatory forbearance until July 31, 2026: the BSI expects late filings but isn’t extending the statutory deadline. For management, Section 38 of the BSIG sets the bar: risk management must be approved, implementation monitored, and training documented. A single portal click won’t suffice.

Key Takeaways

  • Enforcement leniency until July 31. The obligation ended on March 6, 2026. The BSI anticipates late registrations until July 31-law firms interpret this as forbearance, not a cure for non-compliance. As of late May 2026, the gap stands at roughly 11,000 obligated entities.
  • Section 38 BSIG holds leadership accountable. Approval, oversight, and personal training remain the responsibility of management. Delegating to a CISO or IT leadership doesn’t shift liability.
  • Provability trumps checklists. Without logs, training records, and a documented ISMS, there’s no evidence file in a crisis-where leadership duties are binding, business discretion doesn’t apply.

RelatedSovereign AI: responsibility stays in-house  /  AI writes the code. Who’s liable?

The public debate fixates on reporting channels and portal logins. The tougher question lies elsewhere: What can be proven when an incident, regulatory scrutiny, or internal recourse targets management? Simply catching up on registration while leaving the evidence framework unaddressed swaps one visible gap for an invisible one.

Tolerance Does Not Cure Default

The legal situation is clearer than many headlines suggest. The statutory registration deadline under the BSI Act expired on 6 March 2026. The BSI itself states on its information page: The legal deadline has passed. Those affected who are still unregistered should act immediately.

What runs until 31 July 2026 is, according to widespread law firm interpretation, administrative tolerance – a form of enforcement discretion. It is not a statutory extension of the deadline. In its letter to business associations, reported by heise online among others, the BSI assumes that all outstanding registrations will be completed by 31 July 2026 at the latest. This is a statement of expectation and prioritisation; the word “tolerance” does not appear in the BSI’s letter. The BSI’s information page simultaneously states: The legal deadline has passed. Anyone registering now remains formally in default – enforcement discretion does not retroactively remedy the breach of duty. This distinction separates operational relief from legal cure.

6 March 2026
Statutory registration deadline expires. Anyone not listed in the BSI portal by this date is in default – regardless of later registration.
31 July 2026
End of the BSI’s communicated late-registration window (law firm interpretation: tolerance). After this, stricter monitoring and penalty practices are expected.

The figures explain why the authority is proceeding this way. Of around 29,500 affected companies in Germany, only about 11,500 had registered by the statutory deadline. By the end of May, the number stood at around 18,500. As of the end of May 2026, a gap of around 11,000 obligated parties remains. Enforcement discretion is thus also an admission: enforcement has encountered an economy that underestimated the timeline.

~11,000
Companies without BSI registration – calculated from around 29,500 affected and 18,500 registrations (as of end of May 2026).
Source: heise online / BSI spokesperson (as of end of May); Kleeberg, 15.07.2026

A registration violation remains subject to fines. Under Section 65 BSIG, the institution faces fines of up to 500,000 Euro. The fine targets the institution. The natural person in a leadership role is not the addressee of this fine provision. More serious for executives is the internal liability under Section 38(2) BSIG: Anyone who violates the duties under paragraph 1 is liable to their own institution for damages caused by negligence – according to the corporate law rules of the respective legal form. The registration record protects precisely in cases of recourse. The fine remains a side issue. The ability to seek recourse determines the personal risk for leadership.

What § 38 BSIG Requires from Executive Management

§ 38 BSIG places responsibility squarely on the leadership level. Executive management must approve risk management measures, monitor their implementation, and undergo training on cyber risks. BSI President Claudia Plattner puts it literally: executives are “obliged to implement risk management measures, monitor their implementation, and undergo training on the assessment and management of cyber risks.” Operational tasks can be delegated to CISOs, IT leadership, or external service providers-but ultimate responsibility remains.

Delegation does not absolve accountability. Appointing a CISO and dropping the topic from the agenda does not fulfill the duty. The obligation to approve and oversee remains. If there is no written approval, no quarterly reports to leadership, or no proof of executive training, an audit will reveal a gap-even if the data center’s technology is running smoothly.

§ 30 (1) sentence 3 BSIG requires organizations to document compliance with their risk management obligations. The focus is on proving the measures taken under this duty. In a crisis, those who cannot present documentation risk sanctions-regardless of whether much was “somehow” handled operationally. Consulting experience reveals a consistent pattern: technical controls are often in place, but records of management decisions, approvals of security concepts, and leadership training are missing.

Whether the Business Judgment Rule (BJR) offers protection in the NIS-2 context remains legally unresolved-case law is lacking. A common interpretation among law firms draws a sharp line: the BJR protects business discretion, but under this reading, it does not cover mandatory obligations under § 38 BSIG. Where § 38 BSIG explicitly requires approval, oversight, and training, there is no room for discretion-the BJR simply does not apply. Gaps in training and documentation thus constitute independent breaches of duty, whether for a sole managing director of a GmbH or a multi-member executive board.

Consultants often pitch leadership seminars and tool roadmaps. The weak spot? Proof. Leaving a workshop without a resolution protocol means you’ve attended an event-not created an audit trail. The DACH region’s reality adds pressure: works councils and data protection requirements impact monitoring and training formats. Co-determination and commissioned processing don’t block compliance, but both demand early involvement-otherwise, documentation stalls the moment protocols and attendance lists must meet formal standards.

What Can Be Proven in a Crisis

Shifting perspectives is easy to articulate but hard to execute. The critical question becomes: Which document supports which claim? Who signed it, and when? Two columns separate assertion from evidence.

Unsubstantiated Claims

  • “Security is the CISO’s responsibility” without management approval minutes
  • “We have an ISMS” without an up-to-date risk analysis and management sign-off
  • “Management is informed” without training records and attendee lists
  • “We are registered” without documented ownership for the portal and incident reporting
  • “The service provider handles it” without monitoring reports to management

Provable in a Crisis

  • Board resolution: risk management approved, scope and owner designated
  • Current risk analysis with date, methodology, and management submission
  • Training plan and executive management certificates per § 38(3)
  • BSI registration confirmation plus role concept for portal and incident reporting
  • Quarterly report to management detailing deviations, measures, and deadlines

Three risks will shape the coming months. First: Registration is completed, but the evidence file remains patchy-visibility increases, but defensibility does not. Second: Multiple managing directors share responsibility in a way that leaves no one signing off on approvals. Third: After July 31, 2026, regulators will target laggards without portal entries or documentation trails. Ownership is the scarce resource: Who maintains the evidence file? Who approves management training and record-keeping? Who escalates when the CISO reports and the agenda stays silent?

Sources don’t always align. Law firm and association briefings often mention a “grace period,” suggesting delayed compliance can be remedied. But the BSI’s wording is stricter: The legal deadline has passed, and while the authority expects late registrations by July 31, 2026 (heise online, June 17, 2026), “tolerance” is a legal interpretation of enforcement discretion-not a term found in the BSI’s statement. Digital Chiefs endorses this reading because it sharpens leadership’s decision-making: act now and build evidence in parallel. No cure for delay should be expected.

The First 90 Days: Evidence Over Checklists

The first step isn’t buying a tool. It’s compiling a file with five key elements within ninety days-driven by senior management and operationally supported by the CISO and legal teams.

Days 1–30: Status and gap mapping. Clarify or confirm your exposure. Verify your registration status in the BSI portal and complete any pending access requirements (ELSTER/MUK). In parallel: take inventory of existing documents-risk assessments, ISMS scope, incident and continuity plans, and previous board resolutions. Anything missing gets an owner and a deadline.

Days 31–60: Approval and training. Senior management formally approves the risk management framework and action plan. The minutes document the scope, exceptions, and responsible parties. Mandatory executive training is scheduled and recorded-with attendance lists and documented content. The CISO delivers the first written monitoring report to leadership.

Days 61–90: Operational rhythm. Establish a quarterly calendar for leadership reports, reporting channels, and escalation procedures. Assign roles in the BSI portal for registration and incident reporting. Address gaps from the inventory with deadlines and budget owners. Those who’ve only ticked off registration have met half their obligations. Those who maintain an evidence file can respond when it matters.

The trade-offs are real. Speed in registration without documentation quality creates a false sense of security. Perfectionism in the file without portal registration leaves the most visible obligation unmet. The smart move: use the post-registration window to build provability within the same ninety days. It’s unglamorous. But it’s what regulators and liability claims will scrutinize later.

Executives who face personal liability know the difference between “we’re handling it” and “we can prove it.” NIS-2 doesn’t treat this as a matter of style. It makes it a leadership obligation with personal risk-especially when your own organization seeks recourse.

Frequently Asked Questions

Has the NIS-2 registration deadline been extended to 31 July 2026?

No. The statutory deadline expired on 6 March 2026. According to a letter from the BSI to industry associations, the agency expects late registrations until 31 July 2026, which law firms interpret as a grace period (enforcement discretion). However, this is not a legal extension of the deadline, and late submissions do not retroactively remedy the delay.

Does appointing a CISO relieve management of liability under § 38 BSIG?

No. While operational tasks can be delegated, management remains responsible for approving risk management measures, overseeing their implementation, and completing their own training. Without documented oversight, liability risks stay firmly with the executive level.

Which documents are critical in the event of an incident?

Key documents include recorded approvals, up-to-date risk assessments, ISMS evidence, management training records, incident and continuity plans, and the BSI registration confirmation. § 30 (1) sentence 3 BSIG requires proof of compliance with risk management obligations. Missing documentation can lead to penalties-even if measures were actually in place.

What are the consequences of failing to register?

A registration violation can result in fines of up to 500,000 euros for the organization under § 65 BSIG. Additionally, management may face internal liability claims from their own company under § 38 (2) BSIG for negligent breach of duty. Once the late registration window closes, stricter enforcement is expected.

Is the Business Judgement Rule sufficient protection for management?

Unclear-and often overestimated. The Business Judgement Rule protects discretionary business decisions, but mandatory obligations under § 38 BSIG typically fall outside its scope. Without proof of training and a robust ISMS, the rule may not apply at all-and case law on NIS-2 is still lacking.

Image source: AI-generated (July 2026)

Share this article:

Also available in

More Articles

04.08.2026

Local AI: Governance Before Hardware Purchase

Benedikt Langer

10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...

Read Article
03.08.2026

AI Regulation: Up to 3 Percent of Corporate Revenue

Tobias Massow

5 min read Article 50 of the AI Act has bound providers and deployers to concrete transparency obligations ...

Read Article
31.07.2026

You are paying for the R&D of the next competitor

Benedikt Langer

4 min read You are funding the R&D of your next competitor and calling it AI transformation. Frontier ...

Read Article
29.07.2026

Model Harness Instead of Model Marriage: Who Controls the AI Chain?

Eva Mickler

6 min read The lock-in is shifting from the individual model to the orchestration layer. Those who don’t ...

Read Article
28.07.2026

Washington decides which AI is allowed to run here

Eva Mickler

6 Min. read time In just eight days, Washington has shifted the dispute over Chinese AI models from ...

Read Article
23.07.2026

Orphaned Access: The Silent Cybersecurity Gap

Benedikt Langer

5 Min. Read Time Service accounts, API keys, and AI agents often outnumber human accounts. Many of these ...

Read Article
A magazine by Evernine Media GmbH