NIS2 Country Guide

NIS2 Austria: NISG 2026, Deadlines & Registration

Austria transposed NIS2 as the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), published on 23 December 2025 and in force from 1 October 2026. A new federal authority takes over supervision, registration closes on 31 December 2026, and a self-declaration follows twelve months later.

In force: 1 Oct 2026 Register by: 31 Dec 2026 Law: NISG 2026 (BGBl. I Nr. 94/2025) Authority: Bundesamt für Cybersicherheit Last updated: 2 Aug 2026

Introduction

Austria implemented the original NIS Directive through the Netz- und Informationssystemsicherheitsgesetz (NISG 2018). Its NIS2 successor, the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), was published in the Federal Law Gazette as BGBl. I Nr. 94/2025 on 23 December 2025 and takes effect on 1 October 2026. Austria was among the last member states to transpose, arriving almost two years after the EU deadline.

Until 1 October 2026 the old NISG 2018 still governs, and incidents are still reported through the existing CSIRT channels. On that date the 2018 act, the NIS-Verordnung and the QuaSteV are all repealed at once, and a newly created federal authority takes over.

Quick link: Read our overview “What is NIS2?” and “NIS vs NIS2”.

What you must do in Austria

Austria front-loads the calendar: three hard dates in the first two years, each one separately punishable if missed.

  1. Work out whether you are in scope, before October. Classification is a self-assessment against Annexes 1 and 2 and the medium-enterprise thresholds. No authority writes to tell you first.
  2. Register by 31 December 2026. Three months from entry into force, under § 29(3). See Registration.
  3. Keep your registration current. Changes to core details must be reported within two weeks — one of the tightest update duties in the EU.
  4. Get your management trained. Under § 31(2) the management body must personally attend cybersecurity training, and you must offer training to staff. Both are fineable at the highest tier.
  5. File the self-declaration by 1 October 2027. Twelve months after the registration duty arises, a structured report to the authority on the risk-management measures you have actually implemented.
  6. Be ready to prove it from October 2028. The authority can require verification by an independent body, and its first request cannot come earlier than two years after entry into force.
The nearest deadline is 31 December 2026, and the one before it is practical rather than legal: if registration runs through the USP business portal as expected, you need a working USP account first, and that is not something to start in late December.

NIS2 implementation in Austria

NISG 2026 is the federal act that transposes NIS2 into Austrian law. It was enacted and published as BGBl. I Nr. 94/2025 on 23 December 2025. Under § 51 it enters into force nine months after publication, on the first day of the following month — 1 October 2026. Almost the entire act commences on that single date, so there is no phased switch-on to plan around: supervision, registration, reporting duties and penalties all begin together.

Status

Enacted and published as BGBl. I Nr. 94/2025 on 23 December 2025. In force 1 October 2026.

Official law

The enacted text, in German, in the Federal Law Gazette: NISG 2026, BGBl. I Nr. 94/2025.

Registration

Opens with the law and closes 31 December 2026 (§ 29(3)). Until then, incidents under the old regime still go through nis.cert.at.

SectorAustria note
What replaces whatOn 1 October 2026 the NISG 2018, the Netz- und Informationssystemsicherheitsverordnung (NISV) and the Verordnung über qualifizierte Stellen (QuaSteV) are all repealed together.
Public sectorPublic administration bodies are in scope, with a separate non-compliance regime under § 46 rather than the ordinary fines.
Digital infrastructureCloud, data centre, CDN, managed service and managed security service providers, DNS providers and TLD registries follow the EU Annex scoping. Their registration data is forwarded by the single point of contact to ENISA.
FinanceWhere DORA applies it takes precedence as lex specialis, so financial entities meet the sector rules rather than duplicating them.

Compliance & certification

NISG 2026 uses the NIS2 split between wesentliche Einrichtungen (essential entities) and wichtige Einrichtungen (important entities). The distinction decides your penalty ceiling and how closely you are supervised, not whether the duties apply.

Scope

  • Sectors listed in Annexes 1 and 2 to the act, across 18 sectors
  • Medium-enterprise thresholds: 50+ staff, or turnover and balance sheet total above €10 million
  • Certain entities are covered regardless of size, including DNS providers, TLD registries and parts of the public administration
  • Classification is self-assessed — you are not designated by the authority first

Obligations (core)

  • Risk management policies and governance
  • Incident detection & reporting (CSIRT coordination)
  • Business continuity & crisis management
  • Supply-chain security & contractual controls
  • Access control, segmentation, encryption

Standards & evidence

No certification is mandated. But § 33(2) lets you evidence the operational and organisational side through valid certificates where you hold them, so ISO/IEC 27001 does real work here: it is accepted proof, not just good practice.

The law is enacted — the work is no longer preparatory. Scoping, asset inventory and incident playbooks now have a fixed date to be ready by, and the self-declaration a year later means you will have to describe, in writing and in a structured form, what you actually implemented.

Competent authorities & CSIRT

NISG 2026 moves NIS supervision out of the Federal Chancellery. It creates a new federal authority under the Ministry of the Interior, and separates supervision from incident response: you report incidents to a CSIRT, but you answer to the authority.

RoleAuthorityNotes
Cybersecurity authority (supervision) Bundesamt für Cybersicherheit (BfC), under the Ministry of the Interior (BMI) Created by § 3a as a new federal office. Acts as the Cybersicherheitsbehörde: keeps the register, supervises, inspects, runs security scans and imposes penalties.
Single point of contact Zentrale Anlaufstelle, within the authority (§ 5) The EU-facing liaison for cross-border cooperation with the NIS Cooperation Group, EU-CyCLONe and the CSIRTs network, and the channel that forwards digital-provider data to ENISA.
Incident reporting CERT.at and GovCERT Austria Incident notifications go to a CSIRT, not to the authority. The existing platform is nis.cert.at; GovCERT covers the public sector.
National coordination Cyber Sicherheit Steuerungsgruppe (CSS), IKDOK, OpKoord Strategic and operational coordination bodies (§§ 12–14), plus a National Coordination Centre for Cybersecurity under § 6.
Independent verification Unabhängige Stellen und unabhängige Prüfer (§ 7) Accredited bodies and auditors who can be required to verify that your risk-management measures are actually implemented.

Registration: who, where, by when

Every essential and important entity must register with the cybersecurity authority within three months of the law taking effect — by 31 December 2026 (§ 29(3)). Entities that qualify later have three months from the date they meet the criteria.

Who

You decide. Classification is a self-assessment against Annexes 1 and 2 and the size thresholds. Nobody designates you first, and missing the deadline is an offence in its own right, independent of how good your security is.

Where

The act requires electronic, structured submission over a secure channel. The Austrian Chamber of Commerce (WKO) indicates this will run through the USP — Unternehmensserviceportal, the federal business services portal.

What you submit

Entity name, address and current contact details, any designated representative, the sector and sub-sector you fall under, the member states where you provide services, and for digital providers your IP ranges. The authority keeps the register and reviews it at least every two years.

As of August 2026 the registration channel is not live yet, and the official portal nis.gv.at still describes the old NISG regime. That is expected — the duty starts with the law on 1 October. The useful thing to do now is make sure someone in your organisation can actually access the USP, because obtaining that access has its own lead time and is not something to discover in the last week of December.

Registration is not a one-off filing you can then forget. Under § 29(4) you must report changes to your core registration details within two weeks of the change, and changes to the remaining details within three months. Failing to do so carries the same penalty tier as failing to register at all.

Incident reporting in Austria

Significant incidents go to a CSIRT, not to the cybersecurity authority — a split worth knowing before you need it. Section 34 sets four stages.

Within 24 hoursFrühwarnung, an early warning. It must flag whether the incident is suspected to result from unlawful or malicious acts, or could have cross-border effects.
Within 72 hoursMeldung, the notification proper. Updates the early warning and adds a first assessment of severity and impact, plus indicators of compromise where you have them.
On requestZwischenbericht, an interim report with status updates, where a CSIRT or the authority asks for one.
Within one month of the 72-hour notificationAbschlussbericht, the final report: a detailed description with severity and impact, the threat type and likely root cause, remediation applied and still running, and cross-border effects.
If the incident is still running when the final report falls due, you file a progress report at that point instead, and the final report within one month of closing out the incident. The clock runs from the 72-hour notification, not from the incident.

Until 1 October 2026 incidents are still handled under the old regime through nis.cert.at. Failing to report, or to inform the recipients of your services where that is required, sits in the top penalty tier alongside the risk-management duties.

Timeline & key dates

27 Dec 2022 — NIS2 published in the EU Official Journal.
17 Oct 2024 — EU transposition deadline. Austria misses it.
23 Dec 2025NISG 2026 is published in the Federal Law Gazette as BGBl. I Nr. 94/2025, roughly 14 months late.
1 Oct 2026The act enters into force. The NISG 2018, the NISV and the QuaSteV are repealed the same day, and the Bundesamt für Cybersicherheit takes over supervision.
31 Dec 2026Registration deadline. Three months from entry into force (§ 29(3)).
1 Oct 2027Self-declaration due. Twelve months after the registration duty arises: a structured report on the risk-management measures actually implemented (§ 33(1)).
From 1 Oct 2028 — The authority may start requiring verification by an independent body. Its first such request cannot come earlier than two years after entry into force (§ 33(2)).

Sector-specific notes

  • Public sector: federal bodies are in scope, and each ministry must give the authority a list of the entities in its remit within three months of entry into force, then at least every three years. Non-compliance by public administration bodies runs under § 46, a separate regime from the ordinary fines.
  • Finance: where DORA applies it governs as lex specialis. The overlap is resolved in DORA's favour rather than doubled up.
  • Digital infrastructure: cloud, data centre, CDN, managed service and managed security service providers, DNS providers and TLD registries are covered regardless of size, and their registration data is passed to ENISA by the single point of contact.
  • Domain registration services: a distinct set of duties under § 30 — maintain an accurate domain registration database, publish your policies, and answer lawful access requests within 72 hours.

How Austria differs from the NIS2 Directive

Austria transposed late and then wrote one of the more demanding supervisory regimes in the EU. Four things go meaningfully beyond the Directive's baseline.

  • You file a self-declaration nobody asked for. The Selbstdeklaration under § 33(1): twelve months after registering, every essential and important entity must send the authority a structured account of the risk-management measures it has implemented, including supply-chain security and the results of its risk analysis. Most member states wait until they have a reason to ask. Austria requires the filing up front, and getting it wrong knowingly is separately punishable.
  • Management training is a top-tier offence. Section 31(2) requires the management body to personally attend cybersecurity training, and the entity to offer training to staff. Failing either is the first item listed in the penalty provision and carries the full €10 million or €7 million ceiling. Very few member states price training failures at that level.
  • The regulator can scan you. Under § 38 the authority may run Sicherheitsscans against your systems on objective, non-discriminatory and transparent risk criteria, alongside on-site and remote inspections. Obstructing a scan is itself an offence.
  • Two clearly separated penalty tiers. Procedural failures — late registration, stale details, a missing self-declaration, blocking an inspection — sit at €50,000, doubling to €100,000 on repeat. Substantive failures on risk management, reporting and training sit at €10 million or €7 million. The split is cleaner than most national regimes, and it means the cheap mistakes are genuinely cheaper.

Two smaller points worth knowing:

  • Two-week change notifications. Core registration details must be updated within a fortnight of any change — among the tightest such duties in the EU.
  • No double punishment with the GDPR. If the data protection authority has already fined the same conduct under Art. 58(2)(i) GDPR, no NISG fine may be imposed for it.
The practical consequence: Austria is a documentation regime as much as a security one. The two duties most likely to catch a well-secured organisation out are the self-declaration and the training record, and neither is about your firewall.

Operating in more than one EU country?

If you are a DNS service provider, TLD name registry, cloud computing provider, data centre provider, content delivery network provider, managed service provider or managed security service provider, you answer to the regulator of the country where your main establishment sits — under Article 26 of the Directive, generally where cybersecurity risk-management decisions are taken. Not in every country you serve. With no EU establishment, you must designate a representative.

For those same entity types Implementing Regulation (EU) 2024/2690 applies directly and is not transposed, so the technical requirements read identically in Austria and everywhere else. Austria also forwards their registration data to ENISA through its single point of contact, which means the cross-border picture is assembled centrally rather than country by country.

Everyone else registers in each member state where they are established. Also in scope elsewhere? See our guides for Germany, Italy and Czechia, or the full country index.

Penalties

Section 45 sets two distinct tiers, and which one applies depends on what you got wrong rather than on how serious the consequences were.

Substantive failures — no risk-management measures, missed incident reports, no management or staff training, ignoring an enforcement order:

  • Essential entities: up to €10,000,000 or 2% of total worldwide turnover in the preceding financial year, whichever is higher.
  • Important entities: up to €7,000,000 or 1.4% of total worldwide turnover, whichever is higher.

Procedural failures — registering late or with knowingly false details, missing the two-week change notification, no self-declaration or a knowingly false one, no audit report, obstructing an inspection or a security scan, breaching the domain-data duties:

  • Up to €50,000, and up to €100,000 for a repeat breach.

Fines are imposed by the district administrative authority. The authority can also order corrective measures and enforcement steps, and ignoring those orders moves you back into the higher tier.

One protection worth knowing. Where the data protection authority has already imposed a GDPR fine under Art. 58(2)(i) for the same underlying conduct, no NISG fine may be imposed for it. The same incident can still trigger both regimes; it just cannot be fined twice for the same behaviour.

How to prepare

  1. Sort out USP access now. The dullest item on this list and the most likely to bite. If registration runs through the business portal, you need an account and the right authorisations before 31 December 2026.
  2. Book the board training. Management attendance is a legal duty, not a recommendation, and it is fineable at the €10 million tier. Keep the attendance record.
  3. Write the self-declaration backwards. You will have to describe your implemented measures in structured form by October 2027, so decide now what you will be able to say, and close the gaps while there is time.
  4. Rehearse the 24-hour clock: who decides an incident is significant, who files the early warning to the CSIRT, and who covers nights and weekends.
  5. Map the supply chain: supply-chain security is named explicitly in the self-declaration, so it needs to be documented rather than assumed.
  6. Keep certificates current: valid certificates are accepted as proof of operational and organisational implementation, which makes ISO 27001 more than a nice-to-have here.

Official links & resources

Looking for NISG 2026 in English? There is no official English translation. The authoritative text is the German original in the Federal Law Gazette. English summaries, including this page, are guidance only — where an obligation matters, work from the German text or a certified translation.

FAQ: NIS2 in Austria

Is NIS2 already in force in Austria?
The law exists but its obligations have not started yet. NISG 2026 was enacted on 23 December 2025 as BGBl. I Nr. 94/2025 and takes effect on 1 October 2026. Until that date the older NISG 2018 still governs.
Where do I register, and by when?
With the cybersecurity authority, by 31 December 2026 — three months from the law taking effect. The Chamber of Commerce indicates registration will run through the USP business portal. As of August 2026 the channel is not open yet, so the useful preparation is making sure someone can access the USP when it is.
Who is the competent authority?
The Bundesamt für Cybersicherheit, a new federal office under the Ministry of the Interior, created by § 3a. This is a change: cybersecurity coordination previously sat with the Federal Chancellery. Incident reports still go to a CSIRT rather than to the authority.
What is the self-declaration?
A structured report to the authority, due twelve months after your registration duty arises — 1 October 2027 for most entities — describing the risk-management measures you have actually implemented, the systems in use, your supply-chain security and the results of your risk analysis. Filing it late, or knowingly misstating what you implemented, is separately punishable.
How quickly must we report an incident?
An early warning to the CSIRT within 24 hours, the full notification within 72 hours, and a final report within one month of that notification. If the incident is still open, you file a progress report instead and the final report a month after closing it out.
Do we need ISO 27001?
It is not mandatory. But § 33(2) accepts valid certificates as evidence of operational and organisational implementation when the authority asks you to prove your measures, so a current certificate does real work in Austria rather than merely looking good.

Sources & verification

Every date, figure and section reference on this page was taken from the enacted text of NISG 2026 and checked on 2 August 2026. Public NIS2 trackers contradict each other and are not used.

  • NISG 2026, BGBl. I Nr. 94/2025 (RIS, Federal Law Gazette) — the primary source for entry into force (§ 51), the authority (§§ 3a–5), registration (§ 29), governance and training (§ 31), the self-declaration (§ 33), incident reporting (§ 34), supervision and security scans (§ 38) and penalties (§ 45).
  • WKO — NISG 2026 Q&A — the source for registration running through the USP.
  • nis.gv.at — the official information point, which as of August 2026 still describes the pre-2026 regime.
Three things we deliberately do not state. We give no official count of affected entities: industry estimates range from about 4,000 to 5,000, but no government figure exists because registration has not happened yet. We attribute the USP as the registration channel to the WKO rather than presenting it as confirmed, since the official portal has not been updated. And we do not claim the new authority is operational today — the act creates it, and its powers run from 1 October 2026.
General guidance, not legal advice. NISG 2026 takes effect on 1 October 2026 and further ordinances may follow — check the primary sources listed above before acting on a deadline.