A significant number of German companies are facing potential penalties and increased cybersecurity risks after failing to meet a critical registration deadline for the EU’s updated NIS-2 Directive. The directive, designed to bolster cybersecurity standards across the bloc, requires organizations in critical sectors to register with the German Federal Office for Information Security (BSI) – a process many firms appear to have overlooked. This comes at a time of escalating global cyberattacks, raising concerns about Germany’s preparedness.
The NIS-2 Directive came into effect on December 6, 2025, giving companies three months to register. That deadline passed on March 6, 2026. An analysis conducted on March 19, 2026, by the Cyber Intelligence Institute and the law firm Reuschlaw revealed a concerning trend: fewer than half of the estimated 29,500 affected companies had completed the registration process in the BSI portal. This lack of compliance underscores a broader challenge in translating EU regulations into practical security measures on the ground.
Companies with 50 or more employees or an annual revenue exceeding €10 million are subject to the novel rules. Experts point to two primary obstacles: the complexity of the legal definitions within the directive and, in some cases, a deliberate attempt by companies to avoid scrutiny. Professionals at TÜV SÜD had previously warned about the bureaucratic hurdles associated with NIS-2, noting the requirement for ongoing documentation and strict reporting timelines for security incidents.
Global Threats, Local Response
This sluggish response in Germany stands in stark contrast to the increasingly aggressive global cybersecurity landscape. In early March 2026, a major cyberattack crippled Stryker, a medical technology corporation. The attack, attributed to an Iran-linked hacktivist group, targeted Stryker’s Microsoft systems, disrupting order processing, production, and logistics worldwide. Reports from employees detailed the real-time deletion of company data, highlighting the potential for rapid and widespread damage.
The Stryker incident illustrates how quickly IT disruptions can propagate through global supply chains. Analysts observe a clear trend of geopolitical tensions fueling targeted attacks on critical infrastructure. Today’s attackers move faster than ever, traversing internal networks in seconds. In this environment, proactive cyber defense is no longer optional, but a fundamental business necessity.
From Compliance to Active Defense
Regulatory authorities are now urging companies to move beyond mere compliance and embrace robust operational defenses. The new framework mandates reporting significant incidents to the BSI within 24 hours and submitting a detailed assessment within 72 hours. Meeting these tight deadlines requires a fundamental shift in security strategy.
Experts are advocating for the widespread adoption of the “Assume Breach” principle. This approach acknowledges that perimeter defenses will inevitably fail and prioritizes the rapid detection and containment of attackers who have already infiltrated the network. This proactive stance is a departure from traditional security models focused solely on prevention.
On March 9, 2026, the BSI launched a nationwide survey to assess the actual needs of the German economy regarding digital resilience. The survey focuses on advanced concepts such as Infrastructure as Code, Software Bill of Materials, and Security Operations Centers as a Service. The goal is to transition from passive compliance to active, continuous readiness.
The Risks of Remaining Under the Radar
The decision by thousands of companies to ignore the registration requirement is strategically risky. By remaining unregistered, they exclude themselves from the BSI’s information-sharing network. Companies attempting to evade oversight lose access to early warning systems and critical threat intelligence – tools that could prevent devastating operational disruptions.
Security experts are calling on authorities to move beyond lenient transitional solutions and instead implement clear signals through targeted audits and transparent communication. The financial world is already recognizing the importance of cybersecurity, with investment analysts increasingly evaluating cyber risks as a direct driver of company value. Poor preparation for incidents and inadequate network segmentation threaten business performance, as cyberattacks drive up operating costs and impact cash flow. Strong cyber defenses are becoming a key indicator of sound corporate governance.
The BSI provides resources and guidance for companies navigating the NIS-2 Directive, including a registration portal and information on required measures. More information can be found on the BSI website.
As of March 20, 2026, the BSI is actively analyzing the results of its nationwide survey to determine the level of digital resilience within the German economy. The findings will inform future policy decisions and support programs aimed at strengthening cybersecurity across critical sectors. The next key date for companies to watch is the expected publication of the BSI’s survey results in the coming weeks.
Have thoughts on this story? Share your comments below.
Keep reading
