Lesson 6.3 · 6 min
Supervision, orders and fines
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- Inspections without a reason. For essential entities the authority may inspect on site and remotely, run security scans, request documents and order ad hoc audits.
- Inspections when there are indications. For important entities only once there is evidence or well-founded indications of breaches, from the self-declaration for instance.
- First a request, then a formal decision. The authority orders measures with a reasonable deadline. If they aren't followed, a formal decision follows.
- Monitoring officer, suspension, ban. For essential entities, up to suspending authorisations and temporarily banning management duties.
- Imposed by the district authority. The Federal Office reports, the district authority fines. Appeals go to the administrative court.
In detail
Supervision of essential entities
Besides the proof under § 33, for essential entities the authority may § 38(1) NISG 2026:
- inspect the implementation of the measures, on site and remotely or by accompanying audits, each time after giving notice;
- run security scans, on objective and transparent criteria;
- request information, including documented cyber security policies;
- require access to data, documents and other information;
- order ad hoc audits, for instance after a significant incident, a breach, or to verify the self-declaration.
Supervision of important entities
If the authority learns through evidence such as the self-declaration, or other well-founded indications, that an important entity is suspected of not meeting its duties, in particular under §§ 32 and 34, it can take measures nos. 1 to 4 there too § 38(2) NISG 2026. All measures must be limited to what is strictly necessary and spare rights and operations as far as possible § 38(3).
Enforcement
- Request: the authority can order measures with a reasonable deadline, for instance to fix shortcomings or an incident § 39(1) NISG 2026.
- Formal decision: if the request isn't followed, demonstrable implementation is ordered by formal decision § 39(2).
- Further decisions: to inform those affected about a significant cyber threat; to make public aspects of duties not met; for essential entities, a monitoring officer for a limited time § 39(3).
- Last resort, essential entities only: asking for certifications or authorisations to be suspended, and temporarily banning management duties § 39(4), to be lifted as soon as the measures have demonstrably been taken § 39(5).
What is punishable
| Administrative offence | Fine range |
|---|---|
| no training for management or staff; § 32 measures not in place (not known only from the self-declaration); incidents not reported; recipients of services not informed; measures ordered under § 39(2) not implemented on time § 45(1) | essential: up to €10m or 2%; important: up to €7m or 1.4% (2), (3) |
| not or wrongly registered, changes not reported; self-declaration late or knowingly false; audit report or audit plan late; inspections, scans or ad hoc audits obstructed; information or access refused; orders under § 39(3) not followed; monitoring officer obstructed; certified ICT products under § 40 not used § 45(4) | up to €50,000, up to €100,000 if repeated |
The authority reports suspected offences to the district administrative authority, which imposes the fine § 44(1) NISG 2026; where an offence is suspected it also takes enforcement measures § 39(8). The authority can also require the use of ICT products certified under European schemes § 40.
Appeals
Appeals against the Federal Office's decisions go to the Federal Administrative Court, against the district authorities' decisions to the state administrative court § 41 NISG 2026.
Checklist
- We know which supervisory measures are possible for our classification.
- We could produce documented security policies at short notice.
- Who accompanies an inspection or a security scan is settled.
- We know that obstructing inspections is itself punishable.
- If an order comes, we know who is responsible for implementing and proving it.
Quiz
When may the Federal Office inspect or request information from an important entity under § 38?
- When evidence or well-founded indications show it is suspected of not meeting its duties
- At any time, without a reason
- Never, only essential entities
- Only once a year
Show the answer
The answer is A: When evidence or well-founded indications show it is suspected of not meeting its duties. § 38(2) NISG 2026: for important entities only with evidence, from the self-declaration for instance, or other well-founded indications.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 38, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 39, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 40, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 41, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 44, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 45, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Federal Office for Cyber Security: measures for breaches, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.