NISG 2026 course All courses

Lesson 6.3 · 6 min

Supervision, orders and fines

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

Supervision of essential entities

Besides the proof under § 33, for essential entities the authority may § 38(1) NISG 2026:

  1. inspect the implementation of the measures, on site and remotely or by accompanying audits, each time after giving notice;
  2. run security scans, on objective and transparent criteria;
  3. request information, including documented cyber security policies;
  4. require access to data, documents and other information;
  5. order ad hoc audits, for instance after a significant incident, a breach, or to verify the self-declaration.

Supervision of important entities

If the authority learns through evidence such as the self-declaration, or other well-founded indications, that an important entity is suspected of not meeting its duties, in particular under §§ 32 and 34, it can take measures nos. 1 to 4 there too § 38(2) NISG 2026. All measures must be limited to what is strictly necessary and spare rights and operations as far as possible § 38(3).

Enforcement

What is punishable

Administrative offenceFine range
no training for management or staff; § 32 measures not in place (not known only from the self-declaration); incidents not reported; recipients of services not informed; measures ordered under § 39(2) not implemented on time § 45(1)essential: up to €10m or 2%; important: up to €7m or 1.4% (2), (3)
not or wrongly registered, changes not reported; self-declaration late or knowingly false; audit report or audit plan late; inspections, scans or ad hoc audits obstructed; information or access refused; orders under § 39(3) not followed; monitoring officer obstructed; certified ICT products under § 40 not used § 45(4)up to €50,000, up to €100,000 if repeated

The authority reports suspected offences to the district administrative authority, which imposes the fine § 44(1) NISG 2026; where an offence is suspected it also takes enforcement measures § 39(8). The authority can also require the use of ICT products certified under European schemes § 40.

Appeals

Appeals against the Federal Office's decisions go to the Federal Administrative Court, against the district authorities' decisions to the state administrative court § 41 NISG 2026.

Checklist

Quiz

When may the Federal Office inspect or request information from an important entity under § 38?

  1. When evidence or well-founded indications show it is suspected of not meeting its duties
  2. At any time, without a reason
  3. Never, only essential entities
  4. Only once a year
Show the answer

The answer is A: When evidence or well-founded indications show it is suspected of not meeting its duties. § 38(2) NISG 2026: for important entities only with evidence, from the self-declaration for instance, or other well-founded indications.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.