TL;DR
- Germany's NIS2 Implementation Act took effect on 6 December 2025 and the BSI registration deadline closed on 6 March 2026.
- Scope jumped from roughly 4,500 to around 29,500 entities, yet only about 11,500 had registered by the deadline.
- Registration is a one-time process. Staying compliant means sustained risk management, supply-chain security, and incident notification and reporting.
- Supervisors now want demonstrated, continuously evidenced control effectiveness, not point-in-time paperwork.
- Annual audits break down on three fronts: lag, drift and false confidence, which is why point-in-time compliance no longer holds up.
- 6clicks delivers continuous evidence collection, AI-powered control mapping, and multi-entity oversight so you stay audit-ready every day.
For most German organisations, NIS2 stopped being a future problem in December 2025. Germany's NIS2 Implementation Act took effect on 6 December 2025, with only three months to register for affected entities. The BSI registration portal opened on 6 January 2026, and the registration deadline closed on 6 March 2026. Overnight, the regulatory perimeter jumped from roughly 4,500 to around 29,500 entities.
Here's the uncomfortable part: by the March deadline, only about 11,500 of the ~29,500 in-scope entities had actually registered, leaving roughly 18,000 exposed just as supervision begins.
Getting onto the BSI register is a one-time administrative act. Staying compliant is not. Under the amended BSI Act, in-scope entities must now sustain risk-management measures, supply-chain security, governance accountability, and strict incident reporting: an initial notice within 24 hours, a fuller report within 72 hours, and a final report within one month.
That cadence is impossible to satisfy with annual spreadsheets and point-in-time snapshots. When a supervisor knocks, the question is no longer "do you have a policy?"; it's "can you demonstrate the control was working, with evidence, on the day it mattered?"
Germany sits at the centre of Europe's digital-sovereignty push. The Berlin Summit on European Digital Sovereignty (November 2025) and the Franco-German Joint Paper on Digital Sovereignty (June 2026) framed reducing "critical dependencies" as a shared political priority, and the EU's Technological Sovereignty Package (3 June 2026) is turning sovereignty into a procurement criterion.
Being "Ready for Sovereignty" in Germany now means proving, continuously, that you control your data, your supply chain, and your security posture.
Across the global Ready for Sovereignty tour, one diagnosis resonated in every room: annual audits were built for static, deterministic systems, and today's environments are neither. For newly in-scope German entities now under BSI supervision, three failure modes explain why point-in-time compliance no longer holds up:
With NIS2 enforcement live and no transition period, this is precisely the gap German supervisors will probe. Continuous, connected evidence closes the lag, catches the drift, and replaces false confidence with proof.
The market has already moved. In 2026, continuous assurance is becoming the standard operating model. Boards, customers, and regulators no longer ask what tools you deployed; they ask whether you can prove your controls are working right now. Independent analysts expect this shift to accelerate, with the GRC software market projected to keep growing at double-digit rates, driven by board-level demand for continuous control monitoring. Assurance leaders are being told to verify control effectiveness with defensible, continuously monitored evidence, not annual attestations.
6clicks turns NIS2 from a scramble into a state you can prove, every day, not just at audit time:
Ready for Sovereignty? See how 6clicks moves you from documented to demonstrated compliance. Speak with our team.