Lesson 3.1 · 6 min
What the management must do
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- The managing directors, not the head of IT. The management body is whoever runs the business under law, articles or contract: managing directors or the board. Not the CISO, and not the head of IT.
- Ensure and oversee. The management must ensure and oversee compliance with the risk management measures. That includes approving the policies.
- Every member of the management. Each member must take part in cyber security training designed for management bodies. The awareness training for everyone isn't enough.
- Offer training regularly. Staff must be offered training regularly so that they can recognise and assess risks.
- The responsibility stays. Even if all IT is with a service provider, the entity remains responsible, and the management steers.
In detail
Who is meant
The "management body" is one or more natural persons or administrative bodies called to run an entity's business by law, articles or contract § 3 no. 11 NISG 2026. The Federal Office names managing directors and the board; heads of department, heads of IT or a CISO are not meant unless they also run the business. A trade-law managing director (gewerberechtlicher Geschäftsführer) counts only if he or she also runs the company as an officer (Federal Office, FAQ on management).
Ensure and oversee
The management bodies of essential and important entities must ensure and oversee compliance with the risk management measures under § 32 § 31(1) NISG 2026. According to the explanatory notes this includes approving the policies and rules (notes on § 31). The EU catalogue, which the NISV 2026 makes binding for all covered entities § 2 NISV 2026, spells this out (Implementing Regulation (EU) 2024/2690, Annex):
- the security policy carries the date of its formal approval by the management bodies, which review it at least once a year (points 1.1.1(k), 1.1.2);
- at least one person reports directly to the management on the security of network and information systems (point 1.2.3);
- the results of the risk assessment and the residual risks are accepted by the management, or by people authorised to do so who report to it adequately (point 2.1.1);
- the management is kept informed of the state of security through regular reporting (point 2.2.1).
Training for the management
The management bodies must take part in cyber security training designed specifically for them § 31(2) NISG 2026. According to the Federal Office this applies to every member of the management, not just one; awareness training for staff isn't enough; attendance must be documented. The act sets no interval; how often to refresh is a risk-based decision (FAQ on management). It makes sense to train those who support the management at the same time.
Training for the team
Entities must regularly offer their staff training so that they can recognise and assess risks and understand cyber security management practices and their effect on the entity's services § 31(2) NISG 2026. Lesson 4.6 shows what this looks like.
If IT is outsourced
The entity remains responsible all the same. It must make sure its service providers implement what is needed, check this regularly and make sure incidents are reported properly; the management remains responsible for steering risk management (Federal Office, FAQ on measures).
What failures risk
Failing to provide training for the management or for staff is an administrative offence with the high fine ranges of § 45(2) and (3) § 45(1) nos. 1 and 2 NISG 2026. Lesson 3.2 shows who bears it.
Checklist
- We know who our management body is in the sense of § 3 no. 11.
- Each of these people has attended training for management bodies, with proof.
- The management has approved the security policy, with a date.
- One person reports directly to the management on information security, at set intervals.
- The management has expressly accepted the residual risks from the risk assessment.
Quiz
A limited company has three managing directors. Is it enough if one of them attends the training for management bodies?
- Yes, if he informs the others
- It is enough if the head of IT attends
- Yes, one is enough
- No, every member of the management must take part
Show the answer
The answer is D: No, every member of the management must take part. § 31(2) NISG 2026; according to the Federal Office (FAQ on management) the duty applies to every natural person called to run the business.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 3, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 31, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 45, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 2, RIS, in German, version of 6 October 2026
- Implementing Regulation (EU) 2024/2690, Art. 2 and Annex, EUR-Lex (also in English)
- Federal Office for Cyber Security, FAQ: management, in German (read on 6 October 2026)
- Federal Office for Cyber Security, FAQ: measures, in German (read on 6 October 2026)
- Explanatory notes to the government bill for the NISG 2026 (308 d.B. XXVIII. GP), PDF, in German
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.