Lesson 2.2 · 4 min
Keeping the details current, and what a lapse costs
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- Name, contacts, sector, countries, IP. Changes to name, address and contact details, sector and type, the EU countries and the IP address ranges must be reported within two weeks.
- Establishments and size. Changes to the establishments and the size information, including whether you are essential or important, within three months.
- Up to €50,000. Failing to register on time, knowingly giving false information or not reporting changes risks up to €50,000, and up to €100,000 if repeated.
- The district administrative authority. The Federal Office reports the suspicion; the fine is imposed by the district authority (Bezirkshauptmannschaft or Magistrat).
- Check once a year. After every set of annual accounts: are size, companies, establishments and contacts still right? One person has it in the calendar.
In detail
Reporting changes
The registration details must be kept current § 29(4) NISG 2026:
| Information | Deadline from the day of the change |
|---|---|
| name; address, contact details, representative; sector and type of entity; EU countries of activity; IP address ranges (2) nos. 1–5 | as soon as possible, within two weeks at the latest |
| main and other establishments; size information and classification as essential or important (2) nos. 6–7 | as soon as possible, within three months at the latest |
Two weeks is short. Typical triggers: a new phone number for the contact point, a change of provider with new IP addresses, a new line of business that makes you another type of entity.
Size changes slowly
Crossing the thresholds, up or down, takes effect only once it has lasted two consecutive financial years (Federal Office, FAQ on size). One strong year doesn't turn an important entity into an essential one. A business that meets the conditions for the first time has three months to register § 29(3) NISG 2026.
What a lapse costs
A fine of up to €50,000, and up to €100,000 if repeated, applies to anyone who § 45(4) NISG 2026:
- fails to register on time, or knowingly gives false or incomplete information when registering (no. 1);
- doesn't report changes within the set period (no. 2).
The district administrative authority imposes the fine; the cyber security authority reports the suspicion to it § 44(1) NISG 2026. The authority reviews its register regularly, at least every two years § 29(1) NISG 2026.
A simple routine
- One person is responsible for the registration and has a deputy.
- Whoever changes contact details, providers or sites tells them: this belongs in the procedures for telephony, IT and premises.
- After every set of annual accounts they check size, shareholdings and classification (lesson 1.3).
Checklist
- One person is responsible for the registration, and they have a deputy.
- Changes to contacts, IP addresses and sites reach this person in time.
- We know the deadlines: two weeks and three months.
- After every set of annual accounts we check size and classification again.
- We keep a record of what we reported and when.
Quiz
The contact point gets a new email address. By when must this be reported?
- Within three months
- Not at all; the Federal Office will ask
- Within two weeks
- With the next self-declaration
Show the answer
The answer is C: Within two weeks. Contact details are information under § 29(2) no. 2; changes must be reported within two weeks (§ 29(4) no. 1 NISG 2026).
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 29, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 44, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 45, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Federal Office for Cyber Security, FAQ: working out the size, in German (read on 6 October 2026)
- Federal Office for Cyber Security: measures for breaches, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.