NISG 2026 course All courses

Lesson 2.1 · 6 min

Registering by the end of 2026: where, and with what

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

Who registers

Essential and important entities register with the cyber security authority § 29(2) NISG 2026, on their own initiative and without being asked (Federal Office, FAQ). Each legal person that carries out a covered activity registers; there is no registration for a group as a whole, but authorised people in the USP can register several entities (FAQ).

By when

Within three months of entry into force § 29(3) NISG 2026. In its FAQ the Federal Office names the period from 1 October to 31 December 2026; on its registration page it notes that the period ends in principle on 1 January 2027 and, because of § 33(2) of the General Administrative Procedure Act (AVG), on 4 January 2027 at the latest (Federal Office, registration). Plan for 31 December 2026; the holidays fall in between.

A business that meets the conditions only later, for instance because it grows or takes up a covered activity, registers as soon as possible and within three months at the latest § 29(3) NISG 2026.

Where

Through the "NIS2-Services" application in the business service portal (Unternehmensserviceportal, USP); reports later go through the same application (Federal Office, registration). Settle beforehand who may act for your business in the USP. Entities without an establishment in the EU register with a separate representative form.

The information

To be sent in structured form over a secure channel § 29(2) NISG 2026:

  1. the entity's name;
  2. its address and current contact details, and its representative where there is one;
  3. its sector, subsector and type of entity under Annex 1 or 2;
  4. the EU member states in which it provides services;
  5. its IP address ranges, where applicable;
  6. the address of its main establishment and its other establishments in the EU;
  7. the information on the size thresholds and whether it is essential or important.

IP address ranges means static public ranges only; domain names can be added (FAQ).

The contact point

A contact point for exchanging cyber security information with the authority must be set up, with at least a phone number and an email address § 29(6) NISG 2026. The explanatory notes recommend that it be reachable outside business hours too, so that the authority has a direct line during an incident (notes on § 29). A role address such as security@ is better than the address of a person who goes on holiday.

Checklist

Quiz

Which IP address ranges must be given when registering?

  1. All internal addresses of the company network
  2. The addresses of all laptops
  3. None; IP addresses aren't asked for
  4. Only static public IP address ranges
Show the answer

The answer is D: Only static public IP address ranges. § 29(2) no. 5 NISG 2026 asks for "the IP address ranges, where applicable"; according to the Federal Office (FAQ, registration) only static public ranges are meant.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.