NISG 2026: What companies in Austria need to do now for information security

- The NISG 2026 was published in the Federal Law Gazette on December 23, 2025, and will come into effect on October 1, 2026.
- The Austrian implementation of the EU's NIS2 Directive mandates strict security measures for affected companies and regulates the reporting requirements for security incidents.
- While the NISG 2018 affected only about 100 companies, the number is expected to rise to 4,000 with the NISG 2026. Furthermore, suppliers may also be affected.
- Essential and important entities falling under NIS2 have until the end of 2026 to register.
Why did Austria adopt the NISG 2026?
With the "Network and Information System Security Act 2026" (NISG 2026), Austria is fulfilling its obligation to transpose the European NIS2 Directive into national law. All EU member states were required to do so by October 2024.
The legislative process:
- December 12, 2025: Adoption of the Federal Act by the National Council
- December 23, 2025: Publication in the Federal Law Gazette
- October 1, 2026: Entry into force
Who is affected by NIS2 in Austria?
Previously, Austria was governed by the Network and Information System Security Act (NISG 2018), which affected around 100 operators of critical infrastructure. With the NISG 2026, the scope of companies required to implement NIS2 expands to approximately 4,000 organizations.
The Austrian NIS2 Act applies to companies that
- operate in one of the 18 NIS sectors
- have at least 50 employees or an annual turnover of over 10 million euros and an annual balance sheet total of over 10 million euros
Both the German and Austrian implementations are based on the requirements and annexes of the EU directive for both criteria. The NIS2 Directive divides the 18 sectors into 11 "highly critical" and 7 "other critical sectors." In our magazine, you can find out which sectors these are and who is specifically affected by the NIS2 Directive.
What are the core objectives of implementing the NIS2 Directive in Austria?
The NISG 2026 pursues five central goals in line with the EU NIS2 Directive:
1. Improve cybersecurity through better protective measures
For better cyber defense and a resilient digital infrastructure, NIS2 requires companies to have more robust security precautions. Potential measures include the implementation of an Information Security Management System (ISMS) or the regular use of risk analyses and penetration tests.
2. Standardize cybersecurity standards within the EU
NIS2 creates uniform minimum requirements for the IT security of EU companies and simplifies compliance for companies operating across borders, among other things.
3. Increase the resilience of critical infrastructure against cyber threats
NISG 2026 primarily affects companies that contribute to critical infrastructure and operate in sectors such as health, energy, transport, finance, or public administration. The goal is to strengthen their resilience against cyberattacks so that essential services can continue to run without interruption.
4. Optimizing crisis management for cyber incidents
The new law improves the responsiveness of both companies and the state in the event of an incident. For example, companies must develop and test emergency plans for IT security incidents and take measures to detect cyberattacks more quickly. Furthermore, the NISG 2026 aims to improve coordination between authorities and companies during a crisis.
5. Expanding reporting obligations for cyber incidents
Crisis management also includes reporting cyberattacks and IT security incidents so that other companies can protect their IT infrastructure in a targeted manner. Companies falling under NIS2 are therefore subject to particularly strict reporting obligations, ensuring that authorities are alerted early and that attacks on national and European infrastructure can be combated more efficiently.
When does the NISG 2026 come into force and what do companies in Austria need to do now?
The NISG 2026 has been finalized and will take effect on October 1, 2026. Potentially affected organizations should not wait until then, but should check now whether NIS2 applies to them. If it does, the following three deadlines are particularly important:
- One of the first obligations for affected parties is registration with the relevant cybersecurity authority. In Austria, this is the Federal Office for Cybersecurity. Once the law comes into force, affected parties have three months to complete the registration. Failure to do so can result in fines of up to 100,000 euros.
- Within 12 months of the law coming into force, affected organizations must proactively inform the cybersecurity authority about the risk management measures they have implemented in the form of a self-declaration.
- From October 1, 2028, the authority may require essential and important entities to provide proof of the implementation of these measures. This generally requires an audit by an independent body.
The management or board of directors is responsible for compliance with deadlines and reporting obligations, as well as for the implementation of risk management measures. You can find out which specific measures are required under NIS2 in our Guide to NIS2 requirements.
9 steps to compliance: How companies in Austria can practically implement the NISG 2026
Implementing the NIS2 implementation act requires a proactive approach and collaboration between various departments within a company.
Which NIS2 reporting deadlines apply to Austria?
Section 34 of the NISG regulates the NIS2 reporting obligation for important and essential companies in Austria. The law is based on the general reporting obligations that also apply to Germany:
- An early warning is required within 24 hours; the deadline begins when the incident becomes known
- A follow-up report must be submitted within 72 hours, in which companies update their early warning with the findings from their initial analysis
- The final report is due as soon as the incident has been resolved, but no later than 1 month after the initial warning.
Reports should be submitted to the relevant sector-specific Cybersecurity Incident Response Team (CSIRT) or to the national CSIRT.
What happens if companies violate the NISG 2026?
Failure to implement the legally required security measures or to comply with registration and reporting obligations can result in significant fines. The amount of the fines varies depending on the type of entity and the severity of the violation:
- Essential entities: Up to 10 million euros or 2% of the company's total worldwide annual turnover, whichever is higher.
- Important entities: Up to 7 million euros or 1.4% of the company's total worldwide annual turnover, whichever is higher.
In the event of violations, members of the management board can also be held personally liable. This applies in particular if they neglect their supervisory and implementation duties.
Conclusion: Act now to meet NISG 2026 requirements on time
The NIS2 Act for Austria is a key component in strengthening cybersecurity across the country. It has far-reaching implications for companies that work every day to ensure that critical infrastructure remains secure and reliable.
Affected companies should use the time until October to ensure they can comply with or implement registration with the cybersecurity authority, self-declaration, and risk management measures as efficiently as possible.
Complying with NISG 2026 requirements not only protects your company from fines but also benefits you through increased security for your IT infrastructure, critical business information, and the data and trust of your customers and partners.
Still have questions? We have the answers.
The NIS2 Directive will come into effect on October 1, 2026. From this date, affected entities will be subject to requirements including risk management, supply chain security, and the reporting of significant security incidents. Separate deadlines apply for registration and self-declaration.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.














