NISG 2026 course All courses

Lesson 4.1 · 7 min

The yardstick: § 32, the NISV 2026 and the EU catalogue

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

The principle

Essential and important entities must put in place appropriate and proportionate technical, operational and organisational risk management measures to reduce the risks to their network and information systems and to prevent or minimise the impact of incidents on the users of their services and on other services § 32(1) NISG 2026. They must take account of the state of the art, relevant standards, good practice and the cost of implementation § 32(2); for proportionality, of their exposure to risk, their size and the likelihood and severity of incidents, including their social and economic impact § 32(3).

The ten elements

The measures follow an all-hazards approach that also protects the physical components, and cover at least § 32(4) NISG 2026:

ElementEU catalogue, Annex pointLesson
apolicies on risk analysis and information system security1, 24.2
bincident handling34.3
cbusiness continuity: backups, disaster recovery, crisis management4, 13.14.3
dsupply chain security54.4
esecurity in acquisition, development and maintenance, handling vulnerabilities64.4
fassessing the effectiveness of the measures74.2
gcyber hygiene and training84.6
hcryptography and, where appropriate, encryption94.5
ihuman resources security, access control, asset management10, 11, 12, 134.5
jmulti-factor or continuous authentication, secured communications11.74.5

The NISV 2026 and the EU catalogue

On the basis of § 32(5) the Federal Office has issued the Network and Information System Security Regulation 2026 (Federal Law Gazette II No. 290/2026, published on 1 October 2026). It declares the requirements of Art. 2 and the Annex of Implementing Regulation (EU) 2024/2690 applicable to all types of essential and important entities in Annexes 1 and 2 that the Implementing Regulation doesn't already cover § 2 NISV 2026. So everyone works to the same catalogue in 13 chapters, mapped in the column above. According to the explanatory notes it is a framework, not a ready-made implementation; how to implement it is the entity's risk-based decision (notes on the NISV 2026). As guidance the notes name ENISA's "Technical Implementation Guidance" with its mapping table.

Four risk categories

The risk analysis must cover at least technological risks, human risks, risks in the ICT supply chain and site-related risks § 3 NISV 2026.

What "proportionate" means for a medium-sized business

ISO 27001 and outsourcing

According to the Federal Office an ISO 27001 certification is a very good basis, but must be checked against the catalogue and supplemented where needed; its scope matters (Federal Office, FAQ on measures). The measures apply to the whole legal person, and outsourced IT remains your responsibility (FAQ).

Checklist

Quiz

A business with 60 staff can't meet a requirement of the EU catalogue because of its size. What does the NISV 2026 require?

  1. A compensating measure, documented with reasons and reviewed at least once a year
  2. An exemption from the Federal Office
  3. To implement the requirement fully anyway
  4. Nothing, the requirement falls away
Show the answer

The answer is A: A compensating measure, documented with reasons and reviewed at least once a year. § 4(1) to (3) NISV 2026: compensating measures that serve the requirement's purpose, documented with reasons and reviewed for effectiveness at least once a year.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.