Skip to content
All Blogs

Germany: NIS2 is live — from documented to demonstrated

Published
Germany: NIS2 is live — from documented to demonstrated
Germany: NIS2 is live — from documented to demonstrated
6:09

TL;DR

  • Germany's NIS2 Implementation Act took effect on 6 December 2025 and the BSI registration deadline closed on 6 March 2026.
  • Scope jumped from roughly 4,500 to around 29,500 entities, yet only about 11,500 had registered by the deadline.
  • Registration is a one-time process. Staying compliant means sustained risk management, supply-chain security, and incident notification and reporting.
  • Supervisors now want demonstrated, continuously evidenced control effectiveness, not point-in-time paperwork.
  • Annual audits break down on three fronts: lag, drift and false confidence, which is why point-in-time compliance no longer holds up.
  • 6clicks delivers continuous evidence collection, AI-powered control mapping, and multi-entity oversight so you stay audit-ready every day.

For most German organisations, NIS2 stopped being a future problem in December 2025. Germany's NIS2 Implementation Act took effect on 6 December 2025, with only three months to register for affected entities. The BSI registration portal opened on 6 January 2026, and the registration deadline closed on 6 March 2026. Overnight, the regulatory perimeter jumped from roughly 4,500 to around 29,500 entities.

 

Here's the uncomfortable part: by the March deadline, only about 11,500 of the ~29,500 in-scope entities had actually registered, leaving roughly 18,000 exposed just as supervision begins.

Registration was the easy part

Getting onto the BSI register is a one-time administrative act. Staying compliant is not. Under the amended BSI Act, in-scope entities must now sustain risk-management measures, supply-chain security, governance accountability, and strict incident reporting: an initial notice within 24 hours, a fuller report within 72 hours, and a final report within one month

 

That cadence is impossible to satisfy with annual spreadsheets and point-in-time snapshots. When a supervisor knocks, the question is no longer "do you have a policy?"; it's "can you demonstrate the control was working, with evidence, on the day it mattered?"

This is a sovereignty story, not just a security one

Germany sits at the centre of Europe's digital-sovereignty push. The Berlin Summit on European Digital Sovereignty (November 2025) and the Franco-German Joint Paper on Digital Sovereignty (June 2026) framed reducing "critical dependencies" as a shared political priority, and the EU's Technological Sovereignty Package (3 June 2026) is turning sovereignty into a procurement criterion. 

 

Being "Ready for Sovereignty" in Germany now means proving, continuously, that you control your data, your supply chain, and your security posture.

Lag, drift, false confidence

Why annual audits fail: lag, drift, and false confidence

Across the global Ready for Sovereignty tour, one diagnosis resonated in every room: annual audits were built for static, deterministic systems, and today's environments are neither. For newly in-scope German entities now under BSI supervision, three failure modes explain why point-in-time compliance no longer holds up:

  • Lag. Evidence is collected, then reviewed long after the fact. By the time an audit report lands, the system has already changed, so you are assuring a snapshot that no longer exists, not the control a supervisor asks about today.
  • Drift. Production environments diverge from documentation continuously. Configurations change, policies update, and AI-enabled systems widen the gap between what is written down and what is actually running.
  • False confidence. Assurance exists on paper, everyone feels safe, and then an incident starts the 24-hour reporting clock. A clean annual report is not the same as a control that was working on the day it mattered.

With NIS2 enforcement live and no transition period, this is precisely the gap German supervisors will probe. Continuous, connected evidence closes the lag, catches the drift, and replaces false confidence with proof.

 

Ready for Sovereignty 2026

From documented to demonstrated

The market has already moved. In 2026, continuous assurance is becoming the standard operating model. Boards, customers, and regulators no longer ask what tools you deployed; they ask whether you can prove your controls are working right now. Independent analysts expect this shift to accelerate, with the GRC software market projected to keep growing at double-digit rates, driven by board-level demand for continuous control monitoring. Assurance leaders are being told to verify control effectiveness with defensible, continuously monitored evidence, not annual attestations. 

How 6clicks can help you

6clicks turns NIS2 from a scramble into a state you can prove, every day, not just at audit time:


 
Ready for Sovereignty? See how 6clicks moves you from documented to demonstrated compliance. Speak with our team.
Ready to transform GRC with 6clicks?

Let’s show you how it works for your team.

awards-mobile-v3