Lesson 2.1 · 6 min
Registering by the end of 2026: where, and with what
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- By 31 December 2026. Covered businesses register within three months of entry into force. The Federal Office names 31 December 2026; legally the period ends on 4 January 2027 at the latest.
- In the USP, under "NIS2-Services". Registration is online, through the NIS2-Services application in the business service portal (USP). Without being asked by the authority.
- Seven pieces of information. Name, address and contacts, sector and type of entity, the EU countries you work in, IP address ranges, establishments and the size information.
- Each legal person on its own. There is no registration for a whole group. Authorised people in the USP can, however, register several companies.
- A contact point. At least a phone number and an email address for exchanges with the authority. Ideally reachable outside business hours too.
In detail
Who registers
Essential and important entities register with the cyber security authority § 29(2) NISG 2026, on their own initiative and without being asked (Federal Office, FAQ). Each legal person that carries out a covered activity registers; there is no registration for a group as a whole, but authorised people in the USP can register several entities (FAQ).
By when
Within three months of entry into force § 29(3) NISG 2026. In its FAQ the Federal Office names the period from 1 October to 31 December 2026; on its registration page it notes that the period ends in principle on 1 January 2027 and, because of § 33(2) of the General Administrative Procedure Act (AVG), on 4 January 2027 at the latest (Federal Office, registration). Plan for 31 December 2026; the holidays fall in between.
A business that meets the conditions only later, for instance because it grows or takes up a covered activity, registers as soon as possible and within three months at the latest § 29(3) NISG 2026.
Where
Through the "NIS2-Services" application in the business service portal (Unternehmensserviceportal, USP); reports later go through the same application (Federal Office, registration). Settle beforehand who may act for your business in the USP. Entities without an establishment in the EU register with a separate representative form.
The information
To be sent in structured form over a secure channel § 29(2) NISG 2026:
- the entity's name;
- its address and current contact details, and its representative where there is one;
- its sector, subsector and type of entity under Annex 1 or 2;
- the EU member states in which it provides services;
- its IP address ranges, where applicable;
- the address of its main establishment and its other establishments in the EU;
- the information on the size thresholds and whether it is essential or important.
IP address ranges means static public ranges only; domain names can be added (FAQ).
The contact point
A contact point for exchanging cyber security information with the authority must be set up, with at least a phone number and an email address § 29(6) NISG 2026. The explanatory notes recommend that it be reachable outside business hours too, so that the authority has a direct line during an incident (notes on § 29). A role address such as security@ is better than the address of a person who goes on holiday.
Checklist
- We know which of our companies must register.
- Someone is authorised in the USP to act for each of these companies.
- All seven pieces of information are ready, including sector, type of entity and size information.
- We have asked our provider for our static public IP address ranges.
- The contact point has a role address and a phone number that is answered outside business hours too.
Quiz
Which IP address ranges must be given when registering?
- All internal addresses of the company network
- The addresses of all laptops
- None; IP addresses aren't asked for
- Only static public IP address ranges
Show the answer
The answer is D: Only static public IP address ranges. § 29(2) no. 5 NISG 2026 asks for "the IP address ranges, where applicable"; according to the Federal Office (FAQ, registration) only static public ranges are meant.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 29, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Federal Office for Cyber Security: registration, in German (read on 6 October 2026)
- Federal Office for Cyber Security, FAQ: registration, in German (read on 6 October 2026)
- Explanatory notes to the government bill for the NISG 2026 (308 d.B. XXVIII. GP), PDF, in German
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.