Skip to content

NISG 2026 · § 29

Registration by 31.12.2026

Essential and important entities must register with the Bundesamt für Cybersicherheit within three months of the law taking effect. This is not signing up to a programme; it is a statutory duty with a penalty range of its own.

Deadline

31.12.2026

What the law says

  1. You register yourself

    The authority does not classify you and does not invite you. You assess whether you are in scope, and you register.

  2. Within three months

    The period runs from the law taking effect on 01.10.2026, which puts the deadline at 31.12.2026.

  3. And later, if it applies later

    A company that meets the conditions later — through growth, a new activity or a changed group structure — must register within three months of that point.

  4. Keep the details current

    Registered details have to stay up to date, and changes have to be reported.

  5. Registrars additionally

    Providers of domain name registration services carry their own registration and data duties (§§ 29, 30) even where they are not an essential or important entity.

What is not settled yet

The form and the portal are to be set by a regulation that has not been issued as this page stands. Waiting for the portal is waiting for the wrong thing: what you need now — your classification, who owns it, and contact details for incident reports — does not depend on the form registration eventually takes.

What you can do now

  • Settle the classification defensibly: essential, important, or not in scope.
  • Name who owns it — who registers, and who keeps the details current.
  • Fix the contact details for incident reports, including cover outside business hours.
  • Assemble what a registration predictably asks for: company details, sector, activity, named contacts.

If the deadline passes

A missed registration is a breach in its own right, however good your security measures are. The penalty range for formal breaches reaches €50,000, and €100,000 on repetition (§ 45).

FAQ

Frequently asked questions

The questions we hear most often from security and IT leaders.

Something not covered here? Ask us directly

Every essential and every important entity — the obligation follows from being in scope, not from any notice. If you are unsure which you are, that is the question the free check answers.

Registering is not an admission that turns a company into a covered entity. Scope follows from activity and size, not from the register. If a check later shows you are out of scope, the sensible thing is to document the reasoning rather than quietly disappear.

Not for the work that matters. The form and portal are set by a regulation that has not been issued, but the classification, the named owner and the incident contact details are all independent of it — and they are the parts with lead time.

Then the three months run from that point rather than from 01.10.2026. Growth, a new activity or a changed group structure can all trigger it, which is why the size question is worth revisiting annually.

Not sure which of these applies to you?

The free check answers the ordinary case in five minutes. For anything else a conversation is the quicker route.