Skip to content

NISG 2026 · § 33

Self-declaration by 30.09.2027

Twelve months after the registration duty begins, you report to the authority which measures you have put in place. This is the point at which intentions have to become evidence.

Deadline

30.09.2027

What § 33 names specifically

  1. Your network and information systems

    An overview of the systems your measures apply to. Without a current inventory this is the longest piece of work in the list.

  2. The security of your supply chain

    Which suppliers and outsourced ICT services are critical, and how you account for their security.

  3. The results of your risk analysis

    Not the method — what it found, and what you did about it.

  4. And the measures in place

    The comparison against the ten areas of § 32 Abs. 4 — and, where something is missing, why.

What is not settled yet

The format is set by the authority, and no official form exists as this page stands. The contents are already named in the statute, though — which is the reason to set a gap analysis up so that it produces exactly those three blocks.

What you can do now

  • Build or refresh the system inventory — it has the longest lead time of anything here.
  • Name and assess the critical suppliers and outsourced ICT services.
  • Document the risk analysis so its results can be quoted, not just its method.
  • Compare your measures against § 32 Abs. 4 and give every gap an owner and a date.

And afterwards

From 01.10.2028 the authority may require evidence through an independent body — no earlier than that, and on request, not automatically (§ 33 Abs. 2). Short deadlines follow: two years for the full evidence, but essential entities have to evidence operational and organisational implementation within two months of being asked. The audit report has to be signed by the management body and the auditors and must set out the deficiencies found together with a remediation plan; the entity audited bears the cost. Two months is not a project timeline — what you built for the self-declaration is precisely what such an examination asks to see.

Declaring honestly is not what gets punished

A point buried in § 45 Abs. 1 Z 3 that explains a lot of hesitancy: unimplemented risk-management measures are punishable only "in so far as that circumstance did not become known to the cybersecurity authority solely on the basis of a self-declaration under § 33 Abs. 1". So where a gap becomes known exclusively through your own self-declaration, it carries no fine in itself. The statute rewards a complete declaration — and an incomplete one forfeits the protection, because the authority then learns of the gap from somewhere else.

FAQ

Frequently asked questions

The questions we hear most often from security and IT leaders.

Something not covered here? Ask us directly

No. You declare what is in place; nobody examines it at that moment. The examination is separate and comes later — from 01.10.2028 the authority may require evidence through an independent body, and only on request.

The declaration is a statement of what is in place, not a pass mark. Gaps with an owner and a date read very differently from gaps nobody has noticed — and the supervision of important entities is largely triggered by a declaration that shows the second kind.

The three contents § 33 names: the systems in use, the security of the supply chain, and the results of the risk analysis. Those do not change with the format, and the system inventory in particular has the longest lead time.

It covers a great deal of the underlying measures and none of the declaration itself. The duty to report what is in place is a statutory one; no certificate discharges it.

Not sure which of these applies to you?

The free check answers the ordinary case in five minutes. For anything else a conversation is the quicker route.