NISG 2026 course All courses

Lesson 6.1 · 5 min

The self-declaration, due 30 September 2027

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

What the self-declaration is

Within twelve months of the registration duty arising, essential and important entities send the authority information on the risk management measures they have implemented, in particular on the network and information systems they use, supply chain security and the results of their risk analysis, in a structured form set by the authority § 33(1) NISG 2026.

By when

The period is fixed: twelve months from the point at which the entity meets the conditions (notes on § 33). For entities covered since entry into force, the Federal Office names 30 September 2027 (Federal Office, FAQ on proof). An entity that comes into scope later has twelve months from then.

How

Through a form with short, specific questions in the USP. According to the Federal Office the self-declaration is only an indicator, not a full assessment, and doesn't replace an audit (FAQ on proof). It is meant to give the authority a first overview so that it can direct its supervision on a risk basis; the focus is on system components and the system landscape, dealings with direct service providers, and the results of the risk analysis (notes on § 33).

Honesty pays

Getting ready

What is asked for is exactly what lessons 4.2 to 4.5 require: an inventory of systems, a register of suppliers and a documented risk analysis. If you have these together by summer 2027, the form won't take long.

Checklist

Quiz

A business states truthfully in its self-declaration that MFA isn't in place everywhere yet. What follows under § 45(1) no. 3?

  1. A fine for that alone
  2. No fine for missing measures on that basis alone; but the authority can supervise
  3. Nothing, and the authority may not use the statement
  4. Loss of the registration
Show the answer

The answer is B: No fine for missing measures on that basis alone; but the authority can supervise. § 45(1) no. 3 NISG 2026 punishes measures not in place only insofar as the authority didn't learn of it only from the self-declaration; § 38(2), however, allows supervisory measures.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.