NISG 2026 course All courses

Lesson 3.1 · 6 min

What the management must do

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

Who is meant

The "management body" is one or more natural persons or administrative bodies called to run an entity's business by law, articles or contract § 3 no. 11 NISG 2026. The Federal Office names managing directors and the board; heads of department, heads of IT or a CISO are not meant unless they also run the business. A trade-law managing director (gewerberechtlicher Geschäftsführer) counts only if he or she also runs the company as an officer (Federal Office, FAQ on management).

Ensure and oversee

The management bodies of essential and important entities must ensure and oversee compliance with the risk management measures under § 32 § 31(1) NISG 2026. According to the explanatory notes this includes approving the policies and rules (notes on § 31). The EU catalogue, which the NISV 2026 makes binding for all covered entities § 2 NISV 2026, spells this out (Implementing Regulation (EU) 2024/2690, Annex):

Training for the management

The management bodies must take part in cyber security training designed specifically for them § 31(2) NISG 2026. According to the Federal Office this applies to every member of the management, not just one; awareness training for staff isn't enough; attendance must be documented. The act sets no interval; how often to refresh is a risk-based decision (FAQ on management). It makes sense to train those who support the management at the same time.

Training for the team

Entities must regularly offer their staff training so that they can recognise and assess risks and understand cyber security management practices and their effect on the entity's services § 31(2) NISG 2026. Lesson 4.6 shows what this looks like.

If IT is outsourced

The entity remains responsible all the same. It must make sure its service providers implement what is needed, check this regularly and make sure incidents are reported properly; the management remains responsible for steering risk management (Federal Office, FAQ on measures).

What failures risk

Failing to provide training for the management or for staff is an administrative offence with the high fine ranges of § 45(2) and (3) § 45(1) nos. 1 and 2 NISG 2026. Lesson 3.2 shows who bears it.

Checklist

Quiz

A limited company has three managing directors. Is it enough if one of them attends the training for management bodies?

  1. Yes, if he informs the others
  2. It is enough if the head of IT attends
  3. Yes, one is enough
  4. No, every member of the management must take part
Show the answer

The answer is D: No, every member of the management must take part. § 31(2) NISG 2026; according to the Federal Office (FAQ on management) the duty applies to every natural person called to run the business.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.