Lesson 6.2 · 5 min
An audit by an independent body
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- An audit by an independent body. The authority can require the implementation of the measures to be audited and proven by an independent body. From 1 October 2028 at the earliest.
- Two months or two years. Essential entities prove the organisational and operational implementation within two months; otherwise two years apply.
- Only when there are indications. Important entities are asked only if there are indications of breaches.
- ISO 27001 for the organisational side. Organisational and operational implementation can also be proven with valid certificates, if their scope covers the whole entity. The technical side can't.
- Audit plan, report, action plan. Announce planned audits a month ahead; the management and the auditors sign the audit report with shortcomings and an action plan. The entity pays.
In detail
Proof on request
When the authority asks, essential and important entities prove the technical, operational and organisational implementation of their measures through an audit by an independent body, to the authority's specifications and based on their risk analysis or another audit no older than two years § 33(2) NISG 2026.
| organisational and operational | technical | |
|---|---|---|
| essential entity | two months from the request | two years from the request |
| important entity | two years from the request | two years from the request |
For important entities a request is only possible if there are indications of suspected breaches § 33(2) with § 38(2) NISG 2026. The first request can be made at the earliest two years after entry into force, that is from 1 October 2028 § 33(2) (Federal Office, audits by independent bodies).
What a certificate does
Operational and organisational implementation can also be proven with relevant valid certificates § 33(2) NISG 2026. According to the Federal Office they must be based on established European or international standards, such as the ISO 27001 series, and issued under the right conditions; the scope must cover the whole entity, otherwise the rest must be proven another way. Matrix certifications are allowed if the scope fits; scope, deviations and audit reports must be sent with the certificate. The technical implementation can't be proven with a certificate (audits by independent bodies; FAQ on proof).
The process
- Planned audits must be announced at least one month in advance with an audit plan § 33(5) NISG 2026.
- The audit report, with the shortcomings found and an action plan to fix them, is signed by the management and the auditors and sent in structured form § 33(3).
- The audited entity bears the cost, unless the authority decides otherwise in justified cases § 33(4).
- Failing to send the audit report on time or to announce audits in time risks up to €50,000 § 45(4) nos. 9 and 10.
Who may audit
Independent bodies and auditors are approved by the authority; they need qualifications, at least three years' experience in network and information system security and an aptitude test; a regulation sets out the details (Federal Office, independent bodies and auditors). Until twelve months after that regulation, the qualified bodies under the old NISG count as independent bodies § 51(7) NISG 2026.
Checklist
- We know which deadline would apply to us if asked.
- If we are certified: we have checked whether the scope covers the whole entity.
- Our records of the measures are organised so that an audit can find them.
- We know audits must be announced a month ahead with an audit plan.
- We have an idea of what an audit costs and plan for it.
Quiz
From when, at the earliest, can the Federal Office require an audit by an independent body?
- From 30 September 2027
- From 1 October 2028
- From 1 January 2027
- From 1 October 2026
Show the answer
The answer is B: From 1 October 2028. § 33(2) NISG 2026: the first request at the earliest two years after entry into force, so from 1 October 2028.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 33, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 38, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 45, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 51, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Federal Office for Cyber Security: audits by independent bodies, in German (read on 6 October 2026)
- Federal Office for Cyber Security, FAQ: proof, in German (read on 6 October 2026)
- Federal Office for Cyber Security: independent bodies and auditors, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.