Lesson 6.1 · 5 min
The self-declaration, due 30 September 2027
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- By 30 September 2027. Twelve months after the registration duty arises, essential and important entities file a self-declaration. For most, that means by 30 September 2027.
- Systems, supply chain, risk analysis. Information on the measures in place, in particular on the systems used, supply chain security and the results of the risk analysis.
- A form in the USP. According to the Federal Office, a form with short, specific questions. An indicator for the authority, not an audit.
- An open gap alone isn't fined. Measures not yet in place are not punishable insofar as the authority learns of them only from the self-declaration. False statements are.
- A basis for supervision. The authority uses the information to direct its supervision; for important entities it can be a reason for inspections.
In detail
What the self-declaration is
Within twelve months of the registration duty arising, essential and important entities send the authority information on the risk management measures they have implemented, in particular on the network and information systems they use, supply chain security and the results of their risk analysis, in a structured form set by the authority § 33(1) NISG 2026.
By when
The period is fixed: twelve months from the point at which the entity meets the conditions (notes on § 33). For entities covered since entry into force, the Federal Office names 30 September 2027 (Federal Office, FAQ on proof). An entity that comes into scope later has twelve months from then.
How
Through a form with short, specific questions in the USP. According to the Federal Office the self-declaration is only an indicator, not a full assessment, and doesn't replace an audit (FAQ on proof). It is meant to give the authority a first overview so that it can direct its supervision on a risk basis; the focus is on system components and the system landscape, dealings with direct service providers, and the results of the risk analysis (notes on § 33).
Honesty pays
- Anyone who doesn't file the self-declaration on time, or makes knowingly false statements in it about implementation, risks up to €50,000, and up to €100,000 if repeated § 45(4) nos. 7 and 8 NISG 2026.
- Measures not in place, on the other hand, are punishable only insofar as the authority has learned of this not only from the self-declaration § 45(1) no. 3 NISG 2026. So a gap declared honestly does not, on its own, lead to a fine for missing measures.
- It can trigger supervision, though: for important entities the authority can take supervisory measures if, for example, the self-declaration tells it of suspected breaches § 38(2) NISG 2026; for essential entities it can order an ad hoc audit to verify the self-declaration § 38(1) no. 5.
Getting ready
What is asked for is exactly what lessons 4.2 to 4.5 require: an inventory of systems, a register of suppliers and a documented risk analysis. If you have these together by summer 2027, the form won't take long.
Checklist
- 30 September 2027 is in the calendar, with a person responsible.
- Our inventory of network and information systems is current.
- Our register of suppliers and service providers is current.
- Our risk analysis is documented, with results and a treatment plan.
- Where measures are still missing, we have a dated plan we can state honestly.
Quiz
A business states truthfully in its self-declaration that MFA isn't in place everywhere yet. What follows under § 45(1) no. 3?
- A fine for that alone
- No fine for missing measures on that basis alone; but the authority can supervise
- Nothing, and the authority may not use the statement
- Loss of the registration
Show the answer
The answer is B: No fine for missing measures on that basis alone; but the authority can supervise. § 45(1) no. 3 NISG 2026 punishes measures not in place only insofar as the authority didn't learn of it only from the self-declaration; § 38(2), however, allows supervisory measures.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 33, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 38, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 45, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Federal Office for Cyber Security, FAQ: proof, in German (read on 6 October 2026)
- Explanatory notes to the government bill for the NISG 2026 (308 d.B. XXVIII. GP), PDF, in German
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.