NISG 2026 course All courses

Lesson 1.1 · 6 min

What the NISG 2026 does, and since when

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

The act

The Network and Information System Security Act 2026 (Netz- und Informationssystemsicherheitsgesetz 2026, NISG 2026) implements Directive (EU) 2022/2555, the NIS2 Directive § 48 no. 1 NISG 2026. It sets out measures to achieve a high level of cyber security, in particular among essential and important entities § 2 NISG 2026. It was published on 23 December 2025 in Federal Law Gazette I No. 94/2025.

Since when it applies

Its provisions entered into force on the first day of the month after nine months from publication, that is on 1 October 2026. At the same time §§ 2 to 31 of the 2018 NISG, the 2019 NIS Regulation and the regulation on qualified bodies ceased to apply § 51(2) NISG 2026.

What is being protected

A "network and information system" is not just the server. It means § 3 no. 1 NISG 2026:

A cyber security incident is an event that compromises the availability, authenticity, integrity or confidentiality of such data or services § 3 no. 30 NISG 2026.

The duties at a glance

DutyIn shortLesson
Registerwithin three months of 1 October 2026, in the USP § 292.1, 2.2
Managementensure and oversee the measures, training § 313.1, 3.2
Risk managementappropriate and proportionate measures, at least ten elements § 324.1–4.6
Reportsignificant incidents within 24 hours, 72 hours and one month §§ 34, 355.1–5.3
Proveself-declaration, an audit on request § 336.1, 6.2

Who is in charge

The competent authority is the Federal Office for Cyber Security (Bundesamt für Cybersicherheit), an authority directly under the Minister of the Interior with nationwide competence § 3a NISG 2026. Incidents are reported to a computer emergency team (CSIRT). Since 1 October 2026 there have been the GovCERT for the public administration, the HealthCERT for healthcare and the national CSIRT for everyone else (Federal Office, CSIRTs).

Who checks whether you're covered

You do. The Federal Office states that checking whether an entity is covered, including whether it must register, is up to the entity itself; the authority does not classify businesses (Federal Office, FAQ). Only in special cases does it classify an entity by formal decision § 26 NISG 2026. Lessons 1.2 to 1.4 go through this check step by step.

Checklist

Quiz

Who decides whether a business falls under the NISG 2026?

  1. The competent CSIRT
  2. The Federal Office for Cyber Security, with a letter to every business
  3. The business itself
  4. The Chamber of Commerce
Show the answer

The answer is C: The business itself. The entity checks for itself whether it is covered (Federal Office, FAQ). A formal decision exists only in the special cases of § 26 NISG 2026.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.