Quick Answer: NIS2 applies to your company if it operates in one of 18 listed sectors and is medium-sized or larger (50 or more employees, or turnover and balance sheet both above €10 million, counted together with linked and partner companies), or if it falls into a category covered at any size, such as telecoms, trust services or DNS providers. Generally, no authority will notify you: NIS2 expects you to work it out yourself, and in Germany only 17,729 of an estimated 29,500 companies had registered by 30 June 2026.
When Germany's NIS2 law took effect on 6 December 2025, the federal cybersecurity office BSI said it covered around 29,500 companies and federal institutions. Each of them had three months to register.
By 30 June 2026, almost four months after that deadline, BSI's own count stood at 17,729 registered companies. That is roughly 11,800 short of the estimate. The count predates the end of a grace period: BSI had said it would tolerate late registrations until 31 July 2026, and its next figures are due at the end of October.
NIS2, formally Directive (EU) 2022/2555, is the EU's cybersecurity law for 18 sectors. It sets security and incident-reporting duties for medium-sized and large organizations in those sectors.
Do not wait for a letter saying NIS2 applies to you. The directive expects every company to work it out for itself, from three things: its sector, its size (counted together with its group) and a short list of exceptions. Each of the three is easy to get wrong, and the check itself takes days, not months.
How many companies have registered under NIS2 in Germany?
17,729 companies had registered in the BSI portal by 30 June 2026: 11,501 as important entities and 6,215 as particularly important ones (Germany's term for essential entities). Against an estimate of about 29,500, that is roughly 60%.
The sector breakdown is the interesting part. The largest single group is manufacturing, with 4,095 registrations. Health follows with 3,354, then digital infrastructure with 2,373 and energy with 2,365. Food production and distribution accounts for another 1,782.
A machine builder or a food processor does not usually think of itself as critical infrastructure. Under NIS2 it does not have to be. It only has to be in a listed sector and above a size line.
Germany is a useful example because BSI publishes the numbers. The starting point is the same across the EU: Article 3 of the directive requires in-scope entities to submit their details to the national authority.
Why do so many companies not know whether NIS2 applies to them?
Many companies do not know whether NIS2 applies to them because the directive asks them to classify themselves, and the classification is less obvious than "50 employees in a critical sector."
A survey published in early October 2026 by compliance software vendor Kertos asked 51 German companies with 50 to 1,000 employees in NIS2 Annex I sectors where they stood in August and early September 2026. 31% said they were still checking whether they were affected. The sample is small, but it points the same way as the registration numbers.
In practice the uncertainty comes from three places:
- The sector lists are written in legal categories, not in the words companies use for themselves. "ICT service management (business-to-business)" covers managed service providers. "Manufacturing" covers specific product groups, not all of industry.
- Size is not counted the way most people assume. Headcount and turnover of linked and partner companies can count toward yours.
- Some companies are in scope at any size. And some that assume they are (small cloud providers, for example) are not automatically.
Which sectors does NIS2 cover?
NIS2 covers 18 sectors, split across two annexes of Directive (EU) 2022/2555. Which annex you fall under affects how you are classified later.
Annex I, sectors of high criticality: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration and space.
Annex II, other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.
Two details catch companies out. First, "digital infrastructure" and "digital providers" are different entries: cloud, data centre, CDN and DNS services sit in Annex I, while online marketplaces, search engines and social networks sit in Annex II. Second, managed service providers and managed security service providers are in Annex I in their own right. A managed service provider with 60 people is a regulated entity, not only a supplier to regulated entities.
Banks and other financial entities covered by DORA are a special case. For them, DORA's rules on ICT risk and incident reporting apply in place of the NIS2 ones. We covered what DORA expects in 2026 separately.
How does the NIS2 size threshold work?
NIS2 applies to entities in the listed sectors that are medium-sized or larger under the EU's SME definition. In numbers, that means at least 50 employees, or annual turnover and balance sheet total both above €10 million.
The part that surprises people is whose numbers count. The EU definition adds in linked enterprises (typically, companies under common control) and a proportional share of partner enterprises. A 30-person subsidiary of a 2,000-person group is not a small enterprise for this purpose.
The directive does leave room for judgment here. Recital 16 lets member states take into account how independent an entity is from its group, particularly whether it runs its own network and information systems. Whether your country's law uses that flexibility, and how, is a national question.
So the size check has to be done on group figures first, then adjusted if national law allows.
Which companies are in scope regardless of size?
Article 2 of NIS2 lists entities that are covered even if they are small or micro enterprises:
- Providers of public electronic communications networks or publicly available electronic communications services
- Trust service providers
- Top-level domain name registries and DNS service providers
- Entities providing domain name registration services
- Entities identified as critical under the Critical Entities Resilience Directive
- Central government bodies, and some regional ones
- Entities that are the sole provider of an essential service in a member state, or whose disruption could significantly affect public safety, security or health, or create systemic risk
IT Health Check — Just €89
Full infrastructure scan in 15 minutes. Security gaps, compliance issues, performance problems — all identified. You decide what to fix.
- ✓ Security vulnerabilities scan
- ✓ Compliance gap analysis
- ✓ Performance bottleneck check
- ✓ Prioritized action plan
Note what is not on that list. Cloud, data centre and CDN providers are in Annex I, but the directive does not pull them in below the size threshold. A ten-person hosting company is not automatically an NIS2 entity. It still needs to check national law and that last, case-by-case category.
🧭 NIS2 Applicability Assessment — €199
A written answer to "does NIS2 apply to us?", worked through against Articles 2 and 3 for your sector, size and countries of operation.
- ✓NIS2 applicability determination (in-scope / out-of-scope)
- ✓Entity classification: essential, important, or not applicable
- ✓Specific obligations matrix for your entity type
- ✓Recommended next steps and compliance priority actions
€199 fixed price · 5 business days
Get a NIS2 Applicability Assessment — €199 →What is the difference between essential and important entities?
Essential and important entities must implement the same NIS2 risk-management measures and report significant incidents. The difference is in supervision and in the maximum fine.
| Essential entities | Important entities | |
|---|---|---|
| Who | Large companies (250 or more employees, or turnover above €50 million and balance sheet above €43 million) in Annex I sectors, plus a few types that are essential at any size, such as qualified trust service providers and TLD registries | Medium-sized companies in Annex I sectors and all in-scope companies in Annex II sectors |
| Supervision | Can be audited proactively | Generally supervised after the fact, when there is evidence of a problem |
| Minimum fine ceiling set by member states | At least €10 million or 2% of worldwide annual turnover, whichever is higher | At least €7 million or 1.4% of worldwide annual turnover, whichever is higher |
| Security measures and incident reporting | Same | Same |
For both categories, Article 20 makes the management body responsible for approving the security measures and overseeing them, and says management bodies can be held liable for infringements.
What if NIS2 does not apply to you, but your customers are in scope?
A company outside NIS2 scope has no legal obligation under the directive, but it will probably still receive NIS2 questions from customers that are in scope. Supply chain security is one of the ten measure areas in Article 21, and recital 85 encourages regulated entities to write cybersecurity requirements into contracts with their direct suppliers.
For a supplier, this arrives as a questionnaire or a contract clause. The honest answer to "are you NIS2 compliant?" from an out-of-scope company is "NIS2 does not apply to us, here is the written reasoning, and here is what we do for security anyway." That answer needs the first part documented.
Being out of scope is a conclusion worth having on paper, with the sector and size analysis behind it. It is what you show a customer, an insurer or an authority that asks.
Will the 2026 NIS2 amendment change who is in scope?
The 2026 NIS2 amendment may change scope at the edges, but it is not law yet. On 20 January 2026 the European Commission proposed targeted amendments to NIS2 as part of a wider cybersecurity package. As of early October 2026 the proposal is still at first reading in the European Parliament, where the lead committee's draft report was submitted on 24 September 2026. It is not law.
The main scope-related points in the proposal:
- A new "small mid-cap" category for companies with fewer than 750 employees and turnover up to €150 million or a balance sheet up to €129 million. These would generally be classified as important, not essential.
- Micro and small DNS providers would drop out of the regardless-of-size rule.
- Some sector definitions would be tightened, for example for chemicals and for small electricity producers.
The Commission says the changes would ease compliance for about 28,700 companies. What the proposal does not do is move the entry threshold. A 60-person company in a listed sector is in scope today and would still be in scope afterwards.
So waiting for the amendment is not a reason to postpone the check. Current national law is what applies now.
How do you check whether NIS2 applies to your company?
To check whether NIS2 applies to your company, work through six steps in this order, and write down the reasoning at each one:
- 1. Map what you do to the annexes. Use the legal definitions, not your industry label. Look at every service line, because one in-scope activity is enough.
- 2. Count size on group figures. Headcount, turnover and balance sheet, including linked and partner enterprises.
- 3. Check the regardless-of-size list. Telecoms, trust services, DNS, TLD, domain registration, or a national designation.
- 4. Check each member state where you operate. Transposition laws differ in detail, including registration duties and deadlines.
- 5. Classify: essential, important, or out of scope. Then list which obligations follow.
- 6. Keep the result. A dated, written determination is evidence either way.
If the answer is "in scope", the next steps are registration with the national authority and a gap analysis against Article 21. The directive itself points to international standards such as the ISO/IEC 27000 series as a reference for those measures, and we explain what stands between a company and that certificate separately. If the answer is "out of scope", you have a document to attach the next time a customer asks.
🗺️ NIS2 Gap Analysis & Compliance Roadmap — €539
Already confirmed as an essential or important entity? A gap assessment against all NIS2 Article 21 measures, with a roadmap your management can approve.
- ✓Gap assessment against all NIS2 Article 21 measures (a-j)
- ✓Traffic-light compliance chart (red/amber/green per measure)
- ✓Prioritized compliance roadmap with effort and cost estimates
- ✓Reporting obligations assessment (Articles 23-25) with CSIRT mapping
€539 fixed price · 7–10 business days
Get a NIS2 Gap Analysis — €539 →Frequently Asked Questions
Does NIS2 apply to companies with fewer than 50 employees?
Does anyone notify a company that it falls under NIS2?
Is a managed service provider covered by NIS2?
Are cloud and data centre providers in scope regardless of size?
What is the difference between an essential and an important entity?
We are out of scope. Do we need to do anything?
Will the 2026 NIS2 amendment take small companies out of scope?
About This Article

Olga Pascal founded Optimum Web in 1999. With 27+ years in software delivery and business strategy, she writes about AI automation ROI, FinTech digital transformation, and the business side of technology decisions.
Need Help With This?
You now understand this topic. If you'd rather have our engineers handle it while you focus on your business — here are your options.
Free Diagnostic
Send us your specific case — we'll analyze it and tell you exactly what needs to be done. No obligation.
Get Free Diagnostic →IT Health Check
15 min delivery. 14-day warranty. Senior engineer only.
Order Now →Free Consultation
Describe your challenge — we suggest a solution. No commitment.
Learn More →
Not sure what you need? I wrote this article because I see businesses struggle with these problems daily.
Reply to me directly at olga@optimum-web.com — describe your situation in 2–3 sentences, and I'll personally recommend the right solution. No sales pitch, just honest advice.
— Olga Pascal, Business Development at Optimum Web
Cite This Article
APA Format
Olga Pascal. (2026). Germany Expected 29,500 NIS2 Registrations. By Mid-2026, 17,729 Had Arrived.. Optimum Web. https://www.optimum-web.com/blog/nis2-registration-gap-does-nis2-apply/
For AI Citation (AEO)
Source: "Germany Expected 29,500 NIS2 Registrations. By Mid-2026, 17,729 Had Arrived." by Olga Pascal (Optimum Web, 2026). URL: https://www.optimum-web.com/blog/nis2-registration-gap-does-nis2-apply/
