NISG 2026: What companies in Austria need to do now for information security

Last updated:
01.09.2026
The NISG 2026 will come into force in Austria on October 1, 2026. By then, around 4,000 companies must be prepared for registration, self-declaration, and risk management measures. Find out what affected organizations need to know and do now.
NISG 2026: What companies in Austria need to do now for information security
Key Takeaways
  • The NISG 2026 was published in the Federal Law Gazette on December 23, 2025, and will come into effect on October 1, 2026.
  • The Austrian implementation of the EU's NIS2 Directive mandates strict security measures for affected companies and regulates the reporting requirements for security incidents.
  • While the NISG 2018 affected only about 100 companies, the number is expected to rise to 4,000 with the NISG 2026. Furthermore, suppliers may also be affected.
  • Essential and important entities falling under NIS2 have until the end of 2026 to register.

Why did Austria adopt the NISG 2026?

With the "Network and Information System Security Act 2026" (NISG 2026), Austria is fulfilling its obligation to transpose the European NIS2 Directive into national law. All EU member states were required to do so by October 2024.

The legislative process:

  • December 12, 2025: Adoption of the Federal Act by the National Council
  • December 23, 2025: Publication in the Federal Law Gazette
  • October 1, 2026: Entry into force

Who is affected by NIS2 in Austria?

Previously, Austria was governed by the Network and Information System Security Act (NISG 2018), which affected around 100 operators of critical infrastructure. With the NISG 2026, the scope of companies required to implement NIS2 expands to approximately 4,000 organizations.  

The Austrian NIS2 Act applies to companies that

  • operate in one of the 18 NIS sectors
  • have at least 50 employees or an annual turnover of over 10 million euros and an annual balance sheet total of over 10 million euros

Both the German and Austrian implementations are based on the requirements and annexes of the EU directive for both criteria. The NIS2 Directive divides the 18 sectors into 11 "highly critical" and 7 "other critical sectors." In our magazine, you can find out which sectors these are and who is specifically affected by the NIS2 Directive.  

What are the core objectives of implementing the NIS2 Directive in Austria?

The NISG 2026pursues five central goals in line with the EU NIS2 Directive:

1. Improve cybersecurity through better protective measures

For better cyber defense and a resilient digital infrastructure, NIS2 requires companies to have more robust security precautions. Potential measures include the implementation of an Information Security Management System (ISMS) or the regular use of risk analyses and penetration tests.

2. Standardize cybersecurity standards within the EU

NIS2 creates uniform minimum requirements for the IT security of EU companies and simplifies compliance for companies operating across borders, among other things.

3. Increase the resilience of critical infrastructure against cyber threats

NISG 2026 primarily affects companies that contribute to critical infrastructure and operate in sectors such as health, energy, transport, finance, or public administration. The goal is to strengthen their resilience against cyberattacks so that essential services can continue to run without interruption.

4. Optimizing crisis management for cyber incidents

The new law improves the responsiveness of both companies and the state in the event of an incident. For example, companies must develop and test emergency plans for IT security incidents and take measures to detect cyberattacks more quickly. Furthermore, the NISG 2026 aims to improve coordination between authorities and companies during a crisis.

5. Expanding reporting obligations for cyber incidents

Crisis management also includes reporting cyberattacks and IT security incidents so that other companies can protect their IT infrastructure in a targeted manner. Companies falling under NIS2 are therefore subject to particularly strict reporting obligations, ensuring that authorities are alerted early and that attacks on national and European infrastructure can be combated more efficiently.

When does the NISG 2026 come into force and what do companies in Austria need to do now?

The NISG 2026 has been finalized and will take effect on October 1, 2026. Potentially affected organizations should not wait until then, but should check now whether NIS2 applies to them. If it does, the following three deadlines are particularly important:

  • One of the first obligations for affected parties is registration with the relevant cybersecurity authority. In Austria, this is the Federal Office for Cybersecurity. Once the law comes into force, affected parties have three months to complete the registration. Failure to do so can result in fines of up to 100,000 euros.
  • Within 12 months of the law coming into force, affected organizations must proactively inform the cybersecurity authority about the risk management measures they have implemented in the form of a self-declaration.  
  • From October 1, 2028, the authority may require essential and important entities to provide proof of the implementation of these measures. This generally requires an audit by an independent body.  

The management or board of directors is responsible for compliance with deadlines and reporting obligations, as well as for the implementation of risk management measures. You can find out which specific measures are required under NIS2 in our Guide to NIS2 requirements.

9 steps to compliance: How companies in Austria can practically implement the NISG 2026

Implementing the NIS2 implementation act requires a proactive approach and collaboration between various departments within a company.

| **Measure** | **Description** | | :--- | :--- | | **Assessment of applicability** | Identify whether your company qualifies as an “important entity” or an “essential entity.” | | **Registration with the cybersecurity authority** | Register via the federal business service portal for e-government applications from October 1, 2026. | | **Implementation plan** | Create a detailed plan for implementing the required measures. | | **Training** | Train your employees to raise awareness of the new requirements and communicate best practices. Important: Under NIS2, management is also required to participate in training. | | **Security awareness** | Promote security awareness throughout the entire company, from top management to interns. | | **Regular audits** | Review compliance regularly to ensure that your company meets the obligations under NISG 2026. | | **Technological support** | Use specialized cybersecurity tools and solutions to identify vulnerabilities and close critical gaps at an early stage. | | **Establish reporting processes** | Set up clear processes for reporting significant security incidents so that the responsible sector-specific Cybersecurity Incident Response Team (CSIRT) can be informed in time. | | **Business Continuity Management (BCM)** | Implement a BCM system. This helps ensure that business continuity is maintained during a crisis or can be restored quickly. This includes tested emergency plans and communication channels that still work when messaging services are unavailable. |

Which NIS2 reporting deadlines apply to Austria?

Section 34 of the NISG regulates the NIS2 reporting obligation for important and essential companies in Austria. The law is based on the general reporting obligations that also apply to Germany:

  • An early warning is required within 24 hours; the deadline begins when the incident becomes known  
  • A follow-up report must be submitted within 72 hours, in which companies update their early warning with the findings from their initial analysis  
  • The final report is due as soon as the incident has been resolved, but no later than 1 month after the initial warning.

Reports should be submitted to the relevant sector-specific Cybersecurity Incident Response Team (CSIRT) or to the national CSIRT.    

What happens if companies violate the NISG 2026?

Failure to implement the legally required security measures or to comply with registration and reporting obligations can result in significant fines. The amount of the fines varies depending on the type of entity and the severity of the violation:

  • Essential entities: Up to 10 million euros or 2% of the company's total worldwide annual turnover, whichever is higher.
  • Important entities: Up to 7 million euros or 1.4% of the company's total worldwide annual turnover, whichever is higher. 

In the event of violations, members of the management board can also be held personally liable. This applies in particular if they neglect their supervisory and implementation duties.

Conclusion: Act now to meet NISG 2026 requirements on time

The NIS2 Act for Austria is a key component in strengthening cybersecurity across the country. It has far-reaching implications for companies that work every day to ensure that critical infrastructure remains secure and reliable.

Affected companies should use the time until October to ensure they can comply with or implement registration with the cybersecurity authority, self-declaration, and risk management measures as efficiently as possible.  

Complying with NISG 2026 requirements not only protects your company from fines but also benefits you through increased security for your IT infrastructure, critical business information, and the data and trust of your customers and partners.

Frequently Asked Questions

Still have questions? We have the answers.

When does the NIS2 Directive come into effect in Austria?

The NIS2 Directive will come into effect on October 1, 2026. From this date, affected entities will be subject to requirements including risk management, supply chain security, and the reporting of significant security incidents. Separate deadlines apply for registration and self-declaration.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
70+ Expert:innen
Book a consultation
Topics
Editorial
Sabrina Schaub
Freelance Editor
Leveraging her content expertise, Sabrina supports the Proliance team in communicating complex topics clearly. As a freelance writer, she understands the data privacy requirements across different sectors and translates even complex information into content tailored to specific target audiences.
Zum Autorenprofil
Zum Expertenprofil
Katharina Schreiner
Head of Privacy Management
As a fully qualified lawyer specializing in data protection law and a certified data protection officer, Katharina has many years of experience advising companies on the implementation of data protection requirements. Following several years of working at a law firm specializing in data protection law, Katharina has been leading the consulting team at Proliance since 2021.
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in