NISG 2026 · § 31
What lands on the management body
Under the NISG 2026 cybersecurity is not a duty that can be delegated away. § 31 addresses the management body directly — and sets no deadline of its own, which means it applies from 01.10.2026.
Applies from
01.10.2026
§ 31 is three sentences long
Ensure
The management body has to ensure compliance with the § 32 risk-management measures. The statute does not say "approve" — it requires seeing to it that the measures are actually complied with.
Supervise
Same sentence: compliance has to be supervised. A one-off resolution does not satisfy that; a standing reporting line does.
Be trained personally
Members "must attend cybersecurity training specifically designed for them". On the wording, a general awareness course is not "specifically designed".
Train the staff
The third sentence addresses the entity: staff must regularly be offered corresponding training. That duty can be delegated — the management body's duty to attend cannot.
The point most often missed
§ 31 has no transition period of its own. Unlike registration (31.12.2026) and the self-declaration (30.09.2027), it simply applies from the day the law does. Scheduling management training for "after the registration" means the duty has already been missed.
What you can do now
- Pass a resolution that carries the measures — and minute it. The statute asks you to ensure and supervise; neither is evidenced without a record.
- Fix a reporting rhythm: what the management body hears, and when.
- Book training designed for the management body, not the general awareness course.
- Record attendance. What is not documented did not happen, as far as an examination is concerned.
The penalty band few people expect here
Both training duties sit in § 45 Abs. 1 — as Z 1 and Z 2, alongside unimplemented risk-management measures and an unreported incident. They are punished under Abs. 2 and 3: up to €10m or 2 % of worldwide group turnover for essential entities, up to €7m or 1.4 % for important ones, whichever is higher. It is not the €50,000 band that covers formal breaches such as a late registration. The fine is imposed by the district administrative authority, and under § 44 Abs. 3 against the legal person where the offence was committed by people in a leading position. Only for public administration bodies does § 46 apply instead: there the authority establishes the non-compliance by formal decision and sets a remediation deadline rather than imposing a fine.
Read on
The other duties, each on its own page.
Frequently asked questions
The questions we hear most often from security and IT leaders.
Something not covered here? Ask us directly
The work, yes. The duties, no. § 31 addresses the management body directly: it has to ensure compliance with the § 32 measures, supervise that compliance, and attend training designed for it. Note the statute says "ensure and supervise", not "approve" — a policy decided inside IT and never followed up on satisfies neither.
Something designed for that audience — obligations, liability, what a significant incident is and what has to happen in the first 24 hours. The general phishing-awareness course staff take does not normally satisfy it.
There is no separate deadline, which is exactly the trap: it applies from 01.10.2026, the day the law does. Scheduling it after the registration deadline means missing it.
A minuted resolution carrying the measures, a reporting rhythm somebody can point at, and attendance records for the training. All three have to exist before anybody asks.
Not sure which of these applies to you?
The free check answers the ordinary case in five minutes. For anything else a conversation is the quicker route.