NISG 2026 course All courses

Lesson 6.2 · 5 min

An audit by an independent body

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

Proof on request

When the authority asks, essential and important entities prove the technical, operational and organisational implementation of their measures through an audit by an independent body, to the authority's specifications and based on their risk analysis or another audit no older than two years § 33(2) NISG 2026.

organisational and operationaltechnical
essential entitytwo months from the requesttwo years from the request
important entitytwo years from the requesttwo years from the request

For important entities a request is only possible if there are indications of suspected breaches § 33(2) with § 38(2) NISG 2026. The first request can be made at the earliest two years after entry into force, that is from 1 October 2028 § 33(2) (Federal Office, audits by independent bodies).

What a certificate does

Operational and organisational implementation can also be proven with relevant valid certificates § 33(2) NISG 2026. According to the Federal Office they must be based on established European or international standards, such as the ISO 27001 series, and issued under the right conditions; the scope must cover the whole entity, otherwise the rest must be proven another way. Matrix certifications are allowed if the scope fits; scope, deviations and audit reports must be sent with the certificate. The technical implementation can't be proven with a certificate (audits by independent bodies; FAQ on proof).

The process

Who may audit

Independent bodies and auditors are approved by the authority; they need qualifications, at least three years' experience in network and information system security and an aptitude test; a regulation sets out the details (Federal Office, independent bodies and auditors). Until twelve months after that regulation, the qualified bodies under the old NISG count as independent bodies § 51(7) NISG 2026.

Checklist

Quiz

From when, at the earliest, can the Federal Office require an audit by an independent body?

  1. From 30 September 2027
  2. From 1 October 2028
  3. From 1 January 2027
  4. From 1 October 2026
Show the answer

The answer is B: From 1 October 2028. § 33(2) NISG 2026: the first request at the earliest two years after entry into force, so from 1 October 2028.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.