NISG 2026 course All courses

Lesson 6.4 · 5 min

The deadlines at a glance

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

The key dates

WhenWhatBasis
since 1 October 2026risk management, training and the reporting duty apply§ 51(2) NISG 2026
1 October to 31 December 2026register in the USP; legally by 4 January 2027 at the latest§ 29(3) NISG 2026; Federal Office
by 30 September 2027self-declaration§ 33(1) NISG 2026; Federal Office
from 1 October 2028a request for an audit by an independent body is possible§ 33(2) NISG 2026

Deadlines triggered by an event

WhenWhatBasis
within 24 hours of becoming awareearly warning to the CSIRT§ 34(2) no. 1
within 72 hours of becoming awarenotification§ 34(2) no. 2
without undue delayinform the recipients of services if the service is affected§ 34(3)
within one month of the notificationfinal report, otherwise progress report§ 34(2) nos. 4, 5
within two weeksreport changes to name, contacts, sector, countries, IP ranges§ 29(4) no. 1
within three monthsreport changes to establishments and size information§ 29(4) no. 2
within three monthsregister when the conditions are newly met§ 29(3)
within twelve monthsself-declaration when the registration duty newly arises§ 33(1)
two months or two years after a requestproof by an independent body§ 33(2)
one month before an auditaudit plan to the authority§ 33(5)

What comes round regularly

How oftenWhatBasis
every quartercheck whether incidents are recurringIR Annex point 3.4.2(b)
at least once a yearmanagement reviews the security policyIR Annex point 1.1.2
at least once a yearreview the risk assessment and treatment planIR Annex point 2.1.4
at least once a yearreview the effectiveness of compensating measures§ 4(3) NISV 2026
at least once a yearreview the assignment of staff to rolesIR Annex point 10.1.3
regularlytraining for staff; refresher for the management on a risk basis§ 31(2); Federal Office
regularlytest restoring from backupsIR Annex point 4.2.6
after every set of annual accountscheck size and classification; effective after two years in a row§ 25; Federal Office

IR is Implementing Regulation (EU) 2024/2690. After significant incidents and major changes, the policy, risk assessment and many other measures must also be reviewed (Implementing Regulation (EU) 2024/2690, Annex).

What this means day to day

Each of these deadlines is manageable on its own. It gets tedious because they are spread across the management, IT, purchasing and service providers, and because the proof has to come together in one place in the end: in the self-declaration, in a final report, in an audit.

We'd like to hear how you are tackling this and what is least clear to you: in eight short questions, or better still in a conversation of about 20 minutes. We're not selling anything.

Checklist

Quiz

By when must the self-declaration be filed if the registration duty arose on 1 October 2026?

  1. 31 December 2026
  2. 1 October 2028
  3. Only on request
  4. 30 September 2027
Show the answer

The answer is D: 30 September 2027. § 33(1) NISG 2026: twelve months after the registration duty arose; the Federal Office names 30 September 2027 (FAQ on proof).

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.