Lesson 6.4 · 5 min
The deadlines at a glance
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- Since 1 October: all duties. Measures, reporting and training have applied since 1 October 2026. Register by 31 December 2026.
- By 30 September: self-declaration. Twelve months after the registration duty arose. By then the inventory, supplier register and risk analysis should be in place.
- From 1 October: audits possible. From then on the authority can require proof by an independent body: two months or two years to provide it.
- 24 hours, 72 hours, one month. With every significant incident. Changes to the registration within two weeks or three months.
- Policy, risks, compensating measures. Review the security policy, risk assessment and compensating measures at least once a year; recurring incidents every quarter.
In detail
The key dates
| When | What | Basis |
|---|---|---|
| since 1 October 2026 | risk management, training and the reporting duty apply | § 51(2) NISG 2026 |
| 1 October to 31 December 2026 | register in the USP; legally by 4 January 2027 at the latest | § 29(3) NISG 2026; Federal Office |
| by 30 September 2027 | self-declaration | § 33(1) NISG 2026; Federal Office |
| from 1 October 2028 | a request for an audit by an independent body is possible | § 33(2) NISG 2026 |
Deadlines triggered by an event
| When | What | Basis |
|---|---|---|
| within 24 hours of becoming aware | early warning to the CSIRT | § 34(2) no. 1 |
| within 72 hours of becoming aware | notification | § 34(2) no. 2 |
| without undue delay | inform the recipients of services if the service is affected | § 34(3) |
| within one month of the notification | final report, otherwise progress report | § 34(2) nos. 4, 5 |
| within two weeks | report changes to name, contacts, sector, countries, IP ranges | § 29(4) no. 1 |
| within three months | report changes to establishments and size information | § 29(4) no. 2 |
| within three months | register when the conditions are newly met | § 29(3) |
| within twelve months | self-declaration when the registration duty newly arises | § 33(1) |
| two months or two years after a request | proof by an independent body | § 33(2) |
| one month before an audit | audit plan to the authority | § 33(5) |
What comes round regularly
| How often | What | Basis |
|---|---|---|
| every quarter | check whether incidents are recurring | IR Annex point 3.4.2(b) |
| at least once a year | management reviews the security policy | IR Annex point 1.1.2 |
| at least once a year | review the risk assessment and treatment plan | IR Annex point 2.1.4 |
| at least once a year | review the effectiveness of compensating measures | § 4(3) NISV 2026 |
| at least once a year | review the assignment of staff to roles | IR Annex point 10.1.3 |
| regularly | training for staff; refresher for the management on a risk basis | § 31(2); Federal Office |
| regularly | test restoring from backups | IR Annex point 4.2.6 |
| after every set of annual accounts | check size and classification; effective after two years in a row | § 25; Federal Office |
IR is Implementing Regulation (EU) 2024/2690. After significant incidents and major changes, the policy, risk assessment and many other measures must also be reviewed (Implementing Regulation (EU) 2024/2690, Annex).
What this means day to day
Each of these deadlines is manageable on its own. It gets tedious because they are spread across the management, IT, purchasing and service providers, and because the proof has to come together in one place in the end: in the self-declaration, in a final report, in an audit.
We'd like to hear how you are tackling this and what is least clear to you: in eight short questions, or better still in a conversation of about 20 minutes. We're not selling anything.
Checklist
- All the dates in this lesson are in our calendar.
- For every deadline it is clear who keeps track of it, with a deputy.
- The management's yearly review has a fixed date.
- The reporting deadlines are in our incident playbook.
- We know where our proof is kept, for the self-declaration and an audit.
Quiz
By when must the self-declaration be filed if the registration duty arose on 1 October 2026?
- 31 December 2026
- 1 October 2028
- Only on request
- 30 September 2027
Show the answer
The answer is D: 30 September 2027. § 33(1) NISG 2026: twelve months after the registration duty arose; the Federal Office names 30 September 2027 (FAQ on proof).
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 25, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 29, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 31, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 33, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 34, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 51, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 4, RIS, in German, version of 6 October 2026
- Implementing Regulation (EU) 2024/2690, Art. 2 and Annex, EUR-Lex (also in English)
- Federal Office for Cyber Security: registration, in German (read on 6 October 2026)
- Federal Office for Cyber Security, FAQ: proof, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.