Lesson 4.1 · 7 min
The yardstick: § 32, the NISV 2026 and the EU catalogue
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- Appropriate and proportionate. Technical, operational and organisational measures, in line with the risk, the state of the art and with regard to the cost.
- Ten elements, from a to j. From risk analysis through incidents, backups, supply chain, maintenance, effectiveness, training and cryptography to access and multi-factor authentication.
- The EU catalogue applies to all. Since October 2026 the NISV 2026 has made the Annex to Implementing Regulation (EU) 2024/2690 binding for all essential and important entities.
- Explain instead of implement, where it says: where appropriate. Where the catalogue requires something only where appropriate, a clearly documented reason why it doesn't fit you is enough.
- Compensating measures. If a requirement can't be met because of size or for the time being, another measure must be taken, justified and reviewed every year.
In detail
The principle
Essential and important entities must put in place appropriate and proportionate technical, operational and organisational risk management measures to reduce the risks to their network and information systems and to prevent or minimise the impact of incidents on the users of their services and on other services § 32(1) NISG 2026. They must take account of the state of the art, relevant standards, good practice and the cost of implementation § 32(2); for proportionality, of their exposure to risk, their size and the likelihood and severity of incidents, including their social and economic impact § 32(3).
The ten elements
The measures follow an all-hazards approach that also protects the physical components, and cover at least § 32(4) NISG 2026:
| Element | EU catalogue, Annex point | Lesson | |
|---|---|---|---|
| a | policies on risk analysis and information system security | 1, 2 | 4.2 |
| b | incident handling | 3 | 4.3 |
| c | business continuity: backups, disaster recovery, crisis management | 4, 13.1 | 4.3 |
| d | supply chain security | 5 | 4.4 |
| e | security in acquisition, development and maintenance, handling vulnerabilities | 6 | 4.4 |
| f | assessing the effectiveness of the measures | 7 | 4.2 |
| g | cyber hygiene and training | 8 | 4.6 |
| h | cryptography and, where appropriate, encryption | 9 | 4.5 |
| i | human resources security, access control, asset management | 10, 11, 12, 13 | 4.5 |
| j | multi-factor or continuous authentication, secured communications | 11.7 | 4.5 |
The NISV 2026 and the EU catalogue
On the basis of § 32(5) the Federal Office has issued the Network and Information System Security Regulation 2026 (Federal Law Gazette II No. 290/2026, published on 1 October 2026). It declares the requirements of Art. 2 and the Annex of Implementing Regulation (EU) 2024/2690 applicable to all types of essential and important entities in Annexes 1 and 2 that the Implementing Regulation doesn't already cover § 2 NISV 2026. So everyone works to the same catalogue in 13 chapters, mapped in the column above. According to the explanatory notes it is a framework, not a ready-made implementation; how to implement it is the entity's risk-based decision (notes on the NISV 2026). As guidance the notes name ENISA's "Technical Implementation Guidance" with its mapping table.
Four risk categories
The risk analysis must cover at least technological risks, human risks, risks in the ICT supply chain and site-related risks § 3 NISV 2026.
What "proportionate" means for a medium-sized business
- Explain where the catalogue allows it: where the Annex requires something only "where appropriate", "where applicable" or "where feasible", and the entity considers it not appropriate, it documents its reasons clearly (Implementing Regulation, Art. 2(2)). No compensating measure is then needed § 4(4) NISV 2026.
- Compensate where it can't be done: if an entity can't meet particular requirements for the time being or because of its size, it puts in place compensating measures that serve the requirement's purpose, documents them with reasons and reviews their effectiveness at least once a year § 4(1) to (3) NISV 2026. An example from the recitals: a business too small to separate conflicting duties can instead provide for targeted oversight by the management or more logging.
- Not a blank cheque: according to the explanatory notes, size may not be used as a blanket argument to avoid the requirements (notes on § 4 NISV 2026).
ISO 27001 and outsourcing
According to the Federal Office an ISO 27001 certification is a very good basis, but must be checked against the catalogue and supplemented where needed; its scope matters (Federal Office, FAQ on measures). The measures apply to the whole legal person, and outsourced IT remains your responsibility (FAQ).
Checklist
- We have the Annex to Implementing Regulation (EU) 2024/2690 as a checklist.
- For each requirement we know: implemented, explained as not appropriate, compensated, or open.
- Reasons and compensating measures are in writing.
- We review compensating measures for effectiveness at least once a year.
- Our risk analysis covers the four categories of the NISV 2026.
Quiz
A business with 60 staff can't meet a requirement of the EU catalogue because of its size. What does the NISV 2026 require?
- A compensating measure, documented with reasons and reviewed at least once a year
- An exemption from the Federal Office
- To implement the requirement fully anyway
- Nothing, the requirement falls away
Show the answer
The answer is A: A compensating measure, documented with reasons and reviewed at least once a year. § 4(1) to (3) NISV 2026: compensating measures that serve the requirement's purpose, documented with reasons and reviewed for effectiveness at least once a year.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 32, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 2, RIS, in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 3, RIS, in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 4, RIS, in German, version of 6 October 2026
- Implementing Regulation (EU) 2024/2690, Art. 2 and Annex, EUR-Lex (also in English)
- Explanatory notes to the NISV 2026, PDF, in German
- Federal Office for Cyber Security: risk management measures, in German (read on 6 October 2026)
- Federal Office for Cyber Security, FAQ: measures, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.