NISG 2026 course All courses

Lesson 2.2 · 4 min

Keeping the details current, and what a lapse costs

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

Reporting changes

The registration details must be kept current § 29(4) NISG 2026:

InformationDeadline from the day of the change
name; address, contact details, representative; sector and type of entity; EU countries of activity; IP address ranges (2) nos. 1–5as soon as possible, within two weeks at the latest
main and other establishments; size information and classification as essential or important (2) nos. 6–7as soon as possible, within three months at the latest

Two weeks is short. Typical triggers: a new phone number for the contact point, a change of provider with new IP addresses, a new line of business that makes you another type of entity.

Size changes slowly

Crossing the thresholds, up or down, takes effect only once it has lasted two consecutive financial years (Federal Office, FAQ on size). One strong year doesn't turn an important entity into an essential one. A business that meets the conditions for the first time has three months to register § 29(3) NISG 2026.

What a lapse costs

A fine of up to €50,000, and up to €100,000 if repeated, applies to anyone who § 45(4) NISG 2026:

The district administrative authority imposes the fine; the cyber security authority reports the suspicion to it § 44(1) NISG 2026. The authority reviews its register regularly, at least every two years § 29(1) NISG 2026.

A simple routine

Checklist

Quiz

The contact point gets a new email address. By when must this be reported?

  1. Within three months
  2. Not at all; the Federal Office will ask
  3. Within two weeks
  4. With the next self-declaration
Show the answer

The answer is C: Within two weeks. Contact details are information under § 29(2) no. 2; changes must be reported within two weeks (§ 29(4) no. 1 NISG 2026).

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.