NIS2 Austria: NISG 2026, Deadlines & Registration
Austria transposed NIS2 as the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), published on 23 December 2025 and in force from 1 October 2026. A new federal authority takes over supervision, registration closes on 31 December 2026, and a self-declaration follows twelve months later.
Introduction
Austria implemented the original NIS Directive through the Netz- und Informationssystemsicherheitsgesetz (NISG 2018). Its NIS2 successor, the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), was published in the Federal Law Gazette as BGBl. I Nr. 94/2025 on 23 December 2025 and takes effect on 1 October 2026. Austria was among the last member states to transpose, arriving almost two years after the EU deadline.
Until 1 October 2026 the old NISG 2018 still governs, and incidents are still reported through the existing CSIRT channels. On that date the 2018 act, the NIS-Verordnung and the QuaSteV are all repealed at once, and a newly created federal authority takes over.
What you must do in Austria
Austria front-loads the calendar: three hard dates in the first two years, each one separately punishable if missed.
- Work out whether you are in scope, before October. Classification is a self-assessment against Annexes 1 and 2 and the medium-enterprise thresholds. No authority writes to tell you first.
- Register by 31 December 2026. Three months from entry into force, under § 29(3). See Registration.
- Keep your registration current. Changes to core details must be reported within two weeks — one of the tightest update duties in the EU.
- Get your management trained. Under § 31(2) the management body must personally attend cybersecurity training, and you must offer training to staff. Both are fineable at the highest tier.
- File the self-declaration by 1 October 2027. Twelve months after the registration duty arises, a structured report to the authority on the risk-management measures you have actually implemented.
- Be ready to prove it from October 2028. The authority can require verification by an independent body, and its first request cannot come earlier than two years after entry into force.
NIS2 implementation in Austria
NISG 2026 is the federal act that transposes NIS2 into Austrian law. It was enacted and published as BGBl. I Nr. 94/2025 on 23 December 2025. Under § 51 it enters into force nine months after publication, on the first day of the following month — 1 October 2026. Almost the entire act commences on that single date, so there is no phased switch-on to plan around: supervision, registration, reporting duties and penalties all begin together.
Status
Enacted and published as BGBl. I Nr. 94/2025 on 23 December 2025. In force 1 October 2026.
Official law
The enacted text, in German, in the Federal Law Gazette: NISG 2026, BGBl. I Nr. 94/2025.
Registration
Opens with the law and closes 31 December 2026 (§ 29(3)). Until then, incidents under the old regime still go through nis.cert.at.
| Sector | Austria note |
|---|---|
| What replaces what | On 1 October 2026 the NISG 2018, the Netz- und Informationssystemsicherheitsverordnung (NISV) and the Verordnung über qualifizierte Stellen (QuaSteV) are all repealed together. |
| Public sector | Public administration bodies are in scope, with a separate non-compliance regime under § 46 rather than the ordinary fines. |
| Digital infrastructure | Cloud, data centre, CDN, managed service and managed security service providers, DNS providers and TLD registries follow the EU Annex scoping. Their registration data is forwarded by the single point of contact to ENISA. |
| Finance | Where DORA applies it takes precedence as lex specialis, so financial entities meet the sector rules rather than duplicating them. |
Compliance & certification
NISG 2026 uses the NIS2 split between wesentliche Einrichtungen (essential entities) and wichtige Einrichtungen (important entities). The distinction decides your penalty ceiling and how closely you are supervised, not whether the duties apply.
Scope
- Sectors listed in Annexes 1 and 2 to the act, across 18 sectors
- Medium-enterprise thresholds: 50+ staff, or turnover and balance sheet total above €10 million
- Certain entities are covered regardless of size, including DNS providers, TLD registries and parts of the public administration
- Classification is self-assessed — you are not designated by the authority first
Obligations (core)
- Risk management policies and governance
- Incident detection & reporting (CSIRT coordination)
- Business continuity & crisis management
- Supply-chain security & contractual controls
- Access control, segmentation, encryption
Standards & evidence
No certification is mandated. But § 33(2) lets you evidence the operational and organisational side through valid certificates where you hold them, so ISO/IEC 27001 does real work here: it is accepted proof, not just good practice.
Registration: who, where, by when
Every essential and important entity must register with the cybersecurity authority within three months of the law taking effect — by 31 December 2026 (§ 29(3)). Entities that qualify later have three months from the date they meet the criteria.
Who
You decide. Classification is a self-assessment against Annexes 1 and 2 and the size thresholds. Nobody designates you first, and missing the deadline is an offence in its own right, independent of how good your security is.
Where
The act requires electronic, structured submission over a secure channel. The Austrian Chamber of Commerce (WKO) indicates this will run through the USP — Unternehmensserviceportal, the federal business services portal.
What you submit
Entity name, address and current contact details, any designated representative, the sector and sub-sector you fall under, the member states where you provide services, and for digital providers your IP ranges. The authority keeps the register and reviews it at least every two years.
Registration is not a one-off filing you can then forget. Under § 29(4) you must report changes to your core registration details within two weeks of the change, and changes to the remaining details within three months. Failing to do so carries the same penalty tier as failing to register at all.
Incident reporting in Austria
Significant incidents go to a CSIRT, not to the cybersecurity authority — a split worth knowing before you need it. Section 34 sets four stages.
Until 1 October 2026 incidents are still handled under the old regime through nis.cert.at. Failing to report, or to inform the recipients of your services where that is required, sits in the top penalty tier alongside the risk-management duties.
Timeline & key dates
Sector-specific notes
- Public sector: federal bodies are in scope, and each ministry must give the authority a list of the entities in its remit within three months of entry into force, then at least every three years. Non-compliance by public administration bodies runs under § 46, a separate regime from the ordinary fines.
- Finance: where DORA applies it governs as lex specialis. The overlap is resolved in DORA's favour rather than doubled up.
- Digital infrastructure: cloud, data centre, CDN, managed service and managed security service providers, DNS providers and TLD registries are covered regardless of size, and their registration data is passed to ENISA by the single point of contact.
- Domain registration services: a distinct set of duties under § 30 — maintain an accurate domain registration database, publish your policies, and answer lawful access requests within 72 hours.
How Austria differs from the NIS2 Directive
Austria transposed late and then wrote one of the more demanding supervisory regimes in the EU. Four things go meaningfully beyond the Directive's baseline.
- You file a self-declaration nobody asked for. The Selbstdeklaration under § 33(1): twelve months after registering, every essential and important entity must send the authority a structured account of the risk-management measures it has implemented, including supply-chain security and the results of its risk analysis. Most member states wait until they have a reason to ask. Austria requires the filing up front, and getting it wrong knowingly is separately punishable.
- Management training is a top-tier offence. Section 31(2) requires the management body to personally attend cybersecurity training, and the entity to offer training to staff. Failing either is the first item listed in the penalty provision and carries the full €10 million or €7 million ceiling. Very few member states price training failures at that level.
- The regulator can scan you. Under § 38 the authority may run Sicherheitsscans against your systems on objective, non-discriminatory and transparent risk criteria, alongside on-site and remote inspections. Obstructing a scan is itself an offence.
- Two clearly separated penalty tiers. Procedural failures — late registration, stale details, a missing self-declaration, blocking an inspection — sit at €50,000, doubling to €100,000 on repeat. Substantive failures on risk management, reporting and training sit at €10 million or €7 million. The split is cleaner than most national regimes, and it means the cheap mistakes are genuinely cheaper.
Two smaller points worth knowing:
- Two-week change notifications. Core registration details must be updated within a fortnight of any change — among the tightest such duties in the EU.
- No double punishment with the GDPR. If the data protection authority has already fined the same conduct under Art. 58(2)(i) GDPR, no NISG fine may be imposed for it.
Operating in more than one EU country?
If you are a DNS service provider, TLD name registry, cloud computing provider, data centre provider, content delivery network provider, managed service provider or managed security service provider, you answer to the regulator of the country where your main establishment sits — under Article 26 of the Directive, generally where cybersecurity risk-management decisions are taken. Not in every country you serve. With no EU establishment, you must designate a representative.
For those same entity types Implementing Regulation (EU) 2024/2690 applies directly and is not transposed, so the technical requirements read identically in Austria and everywhere else. Austria also forwards their registration data to ENISA through its single point of contact, which means the cross-border picture is assembled centrally rather than country by country.
Penalties
Section 45 sets two distinct tiers, and which one applies depends on what you got wrong rather than on how serious the consequences were.
Substantive failures — no risk-management measures, missed incident reports, no management or staff training, ignoring an enforcement order:
- Essential entities: up to €10,000,000 or 2% of total worldwide turnover in the preceding financial year, whichever is higher.
- Important entities: up to €7,000,000 or 1.4% of total worldwide turnover, whichever is higher.
Procedural failures — registering late or with knowingly false details, missing the two-week change notification, no self-declaration or a knowingly false one, no audit report, obstructing an inspection or a security scan, breaching the domain-data duties:
- Up to €50,000, and up to €100,000 for a repeat breach.
Fines are imposed by the district administrative authority. The authority can also order corrective measures and enforcement steps, and ignoring those orders moves you back into the higher tier.
How to prepare
- Sort out USP access now. The dullest item on this list and the most likely to bite. If registration runs through the business portal, you need an account and the right authorisations before 31 December 2026.
- Book the board training. Management attendance is a legal duty, not a recommendation, and it is fineable at the €10 million tier. Keep the attendance record.
- Write the self-declaration backwards. You will have to describe your implemented measures in structured form by October 2027, so decide now what you will be able to say, and close the gaps while there is time.
- Rehearse the 24-hour clock: who decides an incident is significant, who files the early warning to the CSIRT, and who covers nights and weekends.
- Map the supply chain: supply-chain security is named explicitly in the self-declaration, so it needs to be documented rather than assumed.
- Keep certificates current: valid certificates are accepted as proof of operational and organisational implementation, which makes ISO 27001 more than a nice-to-have here.
Official links & resources
FAQ: NIS2 in Austria
Is NIS2 already in force in Austria?
Where do I register, and by when?
Who is the competent authority?
What is the self-declaration?
How quickly must we report an incident?
Do we need ISO 27001?
Sources & verification
Every date, figure and section reference on this page was taken from the enacted text of NISG 2026 and checked on 2 August 2026. Public NIS2 trackers contradict each other and are not used.
- NISG 2026, BGBl. I Nr. 94/2025 (RIS, Federal Law Gazette) — the primary source for entry into force (§ 51), the authority (§§ 3a–5), registration (§ 29), governance and training (§ 31), the self-declaration (§ 33), incident reporting (§ 34), supervision and security scans (§ 38) and penalties (§ 45).
- WKO — NISG 2026 Q&A — the source for registration running through the USP.
- nis.gv.at — the official information point, which as of August 2026 still describes the pre-2026 regime.
