Cybersecurity29. August 202616 min

NISG 2026: What Austrian Companies Must Actually Do From 1 October 2026

On 1 October 2026 Austria’s Network and Information System Security Act 2026 enters into force. It transposes the same EU directive as Germany’s NIS2UmsuCG — with a different authority, a different registration route, different deadlines and an evidence mechanism Germany does not have. This article sets out what the NISG 2026 demands, where it diverges from German law, and why a German NIS2 checklist does not carry over.

R&D

R&D Team

Alev-B Research & Development

In short

Austria’s NISG 2026 enters into force on 1 October 2026. Affected entities must register with the Cybersicherheitsbehörde within three months, file a self-declaration within twelve months, and report significant incidents within 24 hours, 72 hours and one month. Fines reach EUR 10 million or 2 percent of worldwide turnover.

Why a German NIS2 Checklist Does Not Carry Over to Austria

The Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) was promulgated as Article 1 of Federal Law Gazette BGBl. I No. 94/2025 on 23 December 2025. Under § 51(1) and (2) NISG 2026 its provisions enter into force nine months after promulgation, on the first day of the following month — that is 1 October 2026 (see https://ris.bka.gv.at/Dokumente/BgblAuth/BGBLA_2025_I_94/BGBLA_2025_I_94.pdf). At the same moment the old NISG 2018, the Netz- und Informationssystemsicherheitsverordnung and the Verordnung über qualifizierte Stellen cease to apply.

Both statutes — Austria’s NISG 2026 and Germany’s NIS2 implementation act — transpose the same Directive (EU) 2022/2555, which Member States had to adopt by 17 October 2024 and apply from 18 October 2024 (Article 41 of the directive, see https://eur-lex.europa.eu/eli/dir/2022/2555/oj). Both countries were substantially late. The substance — risk management, supply chain security, tiered reporting deadlines — is accordingly similar. What differs is everything that actually steers an implementation project: which authority you register with, through which channel, by when, who audits, who fines, and what the evidence looks like.

That is precisely why a NIS2 checklist imported from Germany saves no time in Austria; it introduces errors. It names the BSI as the counterparty, carries an expired registration deadline, uses the category "besonders wichtige Einrichtung" instead of "wesentliche Einrichtung", and omits the central Austrian mechanism — the self-declaration under § 33 NISG 2026 — altogether. The comparison below sets out the differences exactly where they hurt in a project plan.

The fine ceilings are almost identical in both countries. The difference is the route: in Austria the Cybersicherheitsbehörde files the referral, the Bezirksverwaltungsbehörde imposes the penalty in administrative penal proceedings — and a prohibition against management members ends up in the publicly searchable commercial register.

AspectGermany (NIS2UmsuCG / BSIG 2025)Austria (NISG 2026)
Legal source and promulgationNIS2 implementation act, promulgated 05.12.2025, BSIG 2025BGBl. I No. 94/2025, issued 23.12.2025
Entry into forcein force since 06.12.2025, no general transition periodin force from 01.10.2026 (§ 51(1) and (2) NISG 2026)
Competent authorityFederal Office for Information Security (BSI)Cybersicherheitsbehörde, seated in Vienna, within the portfolio of the Federal Ministry of the Interior (§ 3, § 50 no. 5)
Entity categoriesbesonders wichtige and wichtige Einrichtungen (§ 28 BSIG)wesentliche and wichtige Einrichtungen (§ 24), 18 sectors under § 2
Registration routeELSTER organisation certificate via "Mein Unternehmenskonto", then registration in the BSI portalelectronic submission to the Cybersicherheitsbehörde over a secure communication channel (§ 29(2))
Registration deadlinewithin three months of first qualifying (§ 33(1) BSIG); already expired for entities covered from the outsetwithin three months of entry into force, i.e. by 31.12.2026 (§ 29(3))
Recurring evidence dutyproof every three years, but only for operators of critical installations (§ 39 BSIG)self-declaration by all essential and important entities within twelve months, then audit by an independent body upon request (§ 33)
Incident reporting addressreport to the BSI as central reporting and contact pointreport to the sector-specific CSIRT, otherwise the national CSIRT, which forwards to the authority (§ 34(1))
Fine ceilingsup to EUR 10m or 2 percent of total turnover (besonders wichtige), up to EUR 7m or 1.4 percent (wichtige)up to EUR 10m or 2 percent of worldwide turnover (essential), up to EUR 7m or 1.4 percent (important); plus up to EUR 50,000, EUR 100,000 on repetition (§ 45)
Enforcing bodyadministrative fine proceedings by the BSIadministrative penal proceedings by the Bezirksverwaltungsbehörde after referral by the Cybersicherheitsbehörde (§ 44(1))
Sanction against managementtemporary prohibition on unreliable management members acting, as a measure of last resorttemporary prohibition by formal decision, additionally transmitted to the commercial register court for entry in the Firmenbuch (§ 39(4) no. 2)

Scope: 18 Sectors and Two Size Thresholds

§ 2 NISG 2026 lists 18 sectors: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration, space, postal and courier services, waste management, manufacture and trade in chemicals, food, manufacturing and production of goods, digital service providers, and research. The sub-sectors are set out in Annexes 1 and 2 of the act.

Size classification follows § 25 NISG 2026 via the EU SME Recommendation 2003/361/EC. An entity counts as a large enterprise if it employs at least 250 people, or if it has annual turnover above EUR 50 million and a balance sheet total above EUR 43 million. It counts as a medium-sized enterprise if it employs at least 50 people, or has annual turnover above EUR 10 million together with a balance sheet total above EUR 10 million. Notable for group structures: under § 25(4) the figures of partner or linked enterprises are not aggregated where the entity is organisationally, technically and operationally independent in respect of the network and information systems it uses. That independence is a question of fact you must be able to evidence — shared Active Directory domains or a group SOC argue against it.

In addition, under § 26 NISG 2026 the Cybersicherheitsbehörde may classify an entity that does not meet the size threshold as an essential or important entity by formal decision — and may upgrade an important entity to an essential one. The size threshold is therefore a rebuttable rule, not a ceiling.

On the number of affected companies, candour is called for. The Austrian Federal Economic Chamber states around 4,000 companies and institutions of medium size and above across 18 sectors (see https://www.wko.at/it-sicherheit/nis2-uebersicht). That figure does not appear in the legislative materials: the regulatory impact assessment for government bill 308 der Beilagen XXVIII. GP expressly states that the actual number of affected entities will only become visible in the authority’s register (see https://www.parlament.gv.at/gegenstand/XXVIII/I/308). The 4,000 is therefore a chamber estimate, not a legislative determination. For comparison, the BSI puts Germany at around 29,500 covered entities (see https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/nis-2-regulierte-unternehmen_node.html).

The most dangerous answer to the scope question is "we are too small". § 26 NISG 2026 lets the Cybersicherheitsbehörde classify an entity by formal decision regardless of size — and an undocumented negative assessment will not relieve management later.

The Deadline Chain From 1 October 2026

Unlike Germany, where obligations went live immediately on entry into force and the registration deadline has already passed, Austria provides a staggered run-up. That staggering is not a reprieve; it is a schedule with four hard points.

The registration deadline expires on 31 December 2026 — in the middle of the holidays. Planning for the year-end date effectively schedules the work into a week when neither legal nor IT is fully staffed. A realistic target is November 2026.

  1. 11 October 2026 — entry into force: §§ 2 to 45 NISG 2026 and the annexes enter into force (§ 51(2)). From that day the risk management duties of § 32 and the reporting duties of § 34 apply directly. There is no grace period for an incident occurring on 2 October.
  2. 231 December 2026 — registration: registration under § 29(2) must occur within three months of entry into force (§ 29(3)). Required details include name, address and contact data, sector and sub-sector, the EU Member States in which services are provided, IP address ranges, the address of the main establishment, and the data on thresholds and classification as an essential or important entity.
  3. 330 September 2027 — self-declaration: under § 33(1), within twelve months of the registration duty arising, information on the risk management measures implemented must be submitted to the Cybersicherheitsbehörde, in particular on the network and information systems used, on supply chain security, and on the results of the risk analysis.
  4. 4From 1 October 2028 — audits by independent bodies: the first request for proof under § 33(2) may be issued at the earliest two years after entry into force. Thereafter the rule is two years from the request — but only two months for essential entities as regards operational and organisational implementation.
  5. 5Ongoing — change notifications: changes to name, address, contact data, sector or IP ranges must be notified within two weeks; changes to establishment and threshold classification within three months (§ 29(4)). That two-week deadline is the one most often missed in practice, because it attaches to entirely ordinary business events.

The Self-Declaration: Austria’s Distinct Route

The largest structural difference from German law is § 33 NISG 2026. In Germany a recurring duty to prove implementation through audits, inspections or certifications every three years applies only to operators of critical installations (§ 39 BSIG 2025, see https://www.gesetze-im-internet.de/bsig_2025/BJNR12D0B0025.html). The bulk of German essential and important entities initially submits nothing proactively — it must be able to deliver when the BSI asks.

Austria inverts that. Every essential and every important entity must set out, on its own initiative and without being asked, in structured form and within twelve months, which risk management measures it has implemented. The format is prescribed by the Cybersicherheitsbehörde. That creates an obligation to deliver which Germany does not impose at this breadth — and a document the authority can later hold against the actual state of affairs.

The second stage is the audit by an independent body under § 33(2). It follows a request, builds on the entity’s own risk analysis, and proof of operational and organisational implementation may also be provided through relevant valid certificates — a practically important opening for organisations holding ISO/IEC 27001. Under § 33(3) an audit report must be submitted to the Cybersicherheitsbehörde, signed by the management bodies and by the independent auditors engaged, listing the deficiencies identified together with a remediation plan. Under § 33(4) the cost of these audits is generally borne by the audited entity. Planned audits must be notified to the authority at least one month in advance with an audit plan (§ 33(5)).

Two consequences follow immediately. First, a signature by the management bodies on a report that names their own deficiencies is a governance act, not an IT act — it belongs on the management meeting agenda in good time, not in the last week before the deadline. Second, anyone presenting themselves in the self-declaration as better than they are risks separate liability under § 45(4) no. 8 for knowingly false statements about the implementation of risk management measures. The converse is striking: under § 45(1) no. 3 the failure to implement risk management measures is punishable only where the authority learned of it other than solely through the self-declaration. The act privileges honest self-reporting and penalises the embellished version.

For substantive preparation, a structured maturity picture is the most effective lever. Our Cybersecurity Assessment maps the measure areas required by § 32 NISG 2026 and delivers exactly the structure in which the self-declaration must be argued. A first, non-binding position fix comes from our free NIS2 readiness check — with one honest caveat: this quick check assesses structural maturity along the NIS2 measure logic, but its legal references are aligned to German law. For the Austrian legal position it does not replace an assessment against the NISG 2026; it prioritises one.

Reporting Duties: Same Clock, Different Address

The reporting deadlines in § 34(2) NISG 2026 follow the directive and are therefore identical to the German ones: an early warning without undue delay and in any event within 24 hours of becoming aware of the significant incident, an incident notification with a first assessment of severity, impact and indicators of compromise within 72 hours, an interim report on request, and a final report no later than one month after the 72-hour notification. Where incident handling is still ongoing, a progress report takes the place of the final report, which then follows within one month of the handling being concluded.

The difference lies in the addressee. In Germany you report to the BSI. In Austria, under § 34(1), you report to the sector-specific CSIRT competent for your entity, or, where none exists, to the national CSIRT, which forwards the report to the Cybersicherheitsbehörde without delay. The official reporting platforms are reachable via the Interior Ministry’s NIS contact point (see https://www.nis.gv.at/). For a company established in both countries this means two separate reporting channels, two access procedures and two contact lists — against an identical clock.

The quid pro quo is more generous than in Germany. Under § 34(4) the CSIRT must respond to the reporting entity no later than 24 hours after receipt of the early warning, including an initial assessment of the incident and, on request, operational advice on possible remediation. Where a criminal background is suspected, the CSIRT additionally provides guidance on reporting to law enforcement. This obligatory feedback channel makes the first report operationally valuable rather than a mere formality.

§ 34(3) adds a duty regularly absent from crisis exercises: where the incident impairs service delivery, the recipients of those services must be informed without delay, together with any countermeasures available to them. That is customer communication under time pressure — it needs prepared text modules and a settled approval chain, or it collides with the live incident response. How to embed such a reporting chain in a team is covered in our article on NIS2 compliance for IT teams.

The 24-hour deadline almost never fails through ignorance; it fails through a lack of response capability at the weekend. A rehearsed reporting chain with names, deputies and working credentials for the correct CSIRT platform is the cheapest measure in the entire NISG programme.

Management Bodies, Fine Ceilings and the Route Into the Commercial Register

§ 31(1) NISG 2026 obliges the management bodies of essential and important entities to ensure and supervise compliance with the risk management measures. § 31(2) requires management bodies to attend cybersecurity training designed specifically for them; employees must be offered corresponding training on a regular basis. Both are separately punishable: § 45(1) nos. 1 and 2 expressly penalise failing to provide the training for management bodies and for employees.

The German counterpart is constructed differently. § 38 BSIG 2025 likewise obliges management to implement and supervise the measures and mandates regular training — but liability in subsection 2 leads into company law: management bodies are liable to their own entity for culpably caused damage under the rules applicable to its legal form, and under the BSIG itself only where company law contains no liability rule. The NISG 2026 contains no such internal liability provision, but it carries a sharper supervisory instrument.

Under § 39(4) no. 2 NISG 2026 the management bodies of an essential entity, including its legal representatives, may be temporarily prohibited by formal decision from performing management duties in that entity — and the Cybersicherheitsbehörde must transmit that decision to the commercial register court for entry in the Firmenbuch. The prohibition must be lifted without delay once the ordered measures have demonstrably been taken, and under § 39(6) it does not apply to public administration bodies. The reputational difference from the German regime remains considerable: an entry in the Firmenbuch is publicly searchable.

On monetary penalties the ceilings are near identical. § 45(2) NISG 2026 provides for up to EUR 10,000,000 or up to 2 percent of total worldwide turnover in the preceding financial year for essential entities, whichever is higher; § 45(3) provides up to EUR 7,000,000 or 1.4 percent for important entities. The BSIG 2025 likewise provides up to ten million euros or 2 percent of total turnover for besonders wichtige Einrichtungen and up to seven million euros or 1.4 percent for wichtige Einrichtungen.

What is specific to Austria is the second fine tier. § 45(4) NISG 2026 attaches a long list of formal breaches — late or false registration, missed change notification, omitted or untrue self-declaration, audit report not submitted in time, obstruction of inspections and security scans — to a fine of up to EUR 50,000 and, on repetition, up to EUR 100,000. Those amounts are low enough to be underestimated, and the triggering conduct is purely administrative. They will hit precisely those organisations that are technically sound but administratively careless.

Procedurally the competences are cleanly separated. Under § 44(1) the imposition of administrative penalties rests with the Bezirksverwaltungsbehörden; the Cybersicherheitsbehörde merely refers the suspicion. Under § 44(3) and (4) fines may also be imposed on the legal person, among other cases where a lack of supervision or control by a person in a leading position made the breach possible. § 44(7) contains a practically important double jeopardy bar: where the data protection authority has already imposed a fine under Article 58(2)(i) GDPR for the same conduct, the Bezirksverwaltungsbehörde may not impose a penalty under the NISG 2026.

The documentary side of these duties — dated approval, traceable oversight, evidenced training attendance — can be produced systematically with our Governance Doc Generator. Which service tier you need for that is set out in our pricing overview.

Groups Operating in Both Countries: What Runs Twice, What Runs Once

For groups with companies in Germany and Austria the decisive question is not whether you must be compliant twice — you must, because both statutes attach to the individual entity and not to the group. The question is which artefacts you build once and merely file differently.

Everything substantive can be built once: the risk analysis, the security concept, the incident response plan, the supplier register with risk classes, backup and restore evidence, cryptography and access control concepts, training content. Both statutes transpose the same catalogue of measures from the directive; the substance overlaps enough to carry a single shared control set.

What must run twice is everything formal and authority-facing. That means two registrations with different access routes, two reporting chains with different recipients and credentials, deadline calendars with different key dates, evidence formats — Germany’s proof duty for critical installations versus Austria’s self-declaration for all entities — and the respective training records per management body and per company.

One special case deserves attention: classification under § 25(4) NISG 2026. Where an Austrian subsidiary is organisationally, technically and operationally independent of the group, group figures are not aggregated for the size threshold. Centralised IT effectively removes that independence and may therefore be what brings the entity into scope in the first place. Anyone who does not decide this question in documented form still decides it — just unconsciously.

How to overlay several regulatory regimes without duplicating work is covered in depth in The 2026 regulatory collision. The underlying logic applies here one to one: build controls once, vary the evidence format per regime and per jurisdiction. An overview of the instruments for that is in our template library.

Rule of thumb for DACH groups: the control framework is a shared resource, the authority relationship never is. Draw that line cleanly and you save roughly half the effort — blur it and you file your incident report with the wrong body.

Roadmap to 1 October 2026

Only a few months remain before entry into force. The roadmap below prioritises by liability exposure and deadline risk rather than technical elegance: what protects the management bodies in proceedings comes first.

  1. 1Immediately — decide scope in documented form: check sector membership under § 2 and Annexes 1 and 2, calculate the size classification under § 25, and, where the entity belongs to a group, reason through the independence question under § 25(4). Record the result as a dated resolution of the management bodies — including, and especially, a negative one.
  2. 2By end of September 2026 — prepare registration data: assemble all details required by § 29(2), in particular the IP address ranges and the list of EU Member States in which services are provided. In our experience those two items take longest, because they cut across network operations and sales at the same time.
  3. 3By end of October 2026 — arm the reporting chain: identify the competent sector-specific CSIRT, set up access to the reporting platform, name roles with deputies, prepare text templates for the early warning, the 72-hour notification and the customer information required by § 34(3), and test them in a tabletop exercise. The reporting duty applies from 1 October 2026, not from registration onwards.
  4. 4By November 2026 — file the registration: do not wait until 31 December. A six-week buffer absorbs authority queries and access problems without putting the deadline at risk.
  5. 5Q1 to Q3 2027 — build the substance behind the self-declaration: update the risk analysis, set up the supplier register with risk classes, record restore tests with date and result, complete management body training and evidence attendance. The self-declaration is not a writing project; it is the summary of what was actually done beforehand.
  6. 6By September 2027 — file the self-declaration and become audit-ready: submit the declaration in the format prescribed by the authority and, in parallel, check whether existing certificates support the proof required under § 33(2). Anyone who must expect a request from October 2028 onwards should already know the audit path by then.

Key Takeaways

  • The NISG 2026 (BGBl. I No. 94/2025) enters into force on 1 October 2026 — nine months after promulgation on 23 December 2025, on the first day of the following month (§ 51(1) and (2)).
  • The competent body is the Cybersicherheitsbehörde, seated in Vienna within the Federal Ministry of the Interior, not the BSI. Incidents are reported to the sector-specific CSIRT, not directly to the authority.
  • The deadline chain is unambiguous: registration within three months of entry into force (by 31.12.2026), self-declaration within twelve months (by 30.09.2027), audit requests no earlier than 1 October 2028.
  • The self-declaration under § 33 NISG 2026 applies to all essential and important entities. Germany imposes a recurring proof duty only on operators of critical installations — that is the single largest structural difference.
  • The fine ceilings are nearly identical (EUR 10m or 2 percent, EUR 7m or 1.4 percent), the route to them is not: in Austria the Bezirksverwaltungsbehörde imposes penalties, and a prohibition against management bodies is entered in the commercial register.
  • For DACH groups: build the control framework and its artefacts once, but keep registration, reporting route, deadline calendar and evidence format separate per country.
  • The figure of around 4,000 affected companies comes from the Austrian Federal Economic Chamber. The legislative materials deliberately give no number and point to the future register kept by the authority.

Frequently Asked Questions

On 1 October 2026. Federal law BGBl. I No. 94/2025 was issued on 23 December 2025; under § 51(1) and (2) NISG 2026 the provisions enter into force nine months after promulgation, on the first day of the following month. At the same time the NISG 2018, the Netz- und Informationssystemsicherheitsverordnung and the Verordnung über qualifizierte Stellen cease to apply. The statutory text is available in the federal legal information system (see https://ris.bka.gv.at/Dokumente/BgblAuth/BGBLA_2025_I_94/BGBLA_2025_I_94.pdf).

Registration is with the Cybersicherheitsbehörde, which is seated in Vienna and sits within the portfolio of the Federal Ministry of the Interior. Under § 29(3) NISG 2026 it must take place within three months of entry into force, that is by 31 December 2026. The submission covers name, address, sector and sub-sector, the EU Member States in which services are provided, IP address ranges, and the data on thresholds and classification. Changes to most of these details must be notified within two weeks.

In four respects that drive the project plan. First the authority: the Cybersicherheitsbehörde rather than the BSI, with incident reports going to the sector-specific CSIRT rather than directly to the authority. Second the timing: Germany has been in force since 6 December 2025 with an expired registration deadline, while Austria only starts on 1 October 2026. Third the evidence: Austria requires a self-declaration from every entity, Germany a recurring proof duty only from operators of critical installations. Fourth the sanction architecture: in Austria the Bezirksverwaltungsbehörde imposes penalties in administrative penal proceedings, and a prohibition against management bodies is entered in the commercial register.

The Austrian Federal Economic Chamber states around 4,000 companies and institutions of medium size and above across 18 sectors. That figure comes from the chamber, not from the act: the regulatory impact assessment for government bill 308 der Beilagen XXVIII. GP expressly records that the actual number of affected entities will only become visible in the authority’s register. By comparison, the BSI puts Germany at around 29,500 covered entities.

A structured submission by every essential and important entity to the Cybersicherheitsbehörde covering the risk management measures implemented, in particular the network and information systems used, supply chain security, and the results of the risk analysis. It is due within twelve months of the registration duty arising, that is by 30 September 2027. Knowingly false statements about implementation are separately punishable under § 45(4) no. 8; conversely § 45(1) no. 3 privileges honest self-reporting, because missing measures are not punishable where the authority learned of them solely through the self-declaration.

Under § 45(2) NISG 2026 up to EUR 10,000,000 or up to 2 percent of total worldwide turnover in the preceding financial year for essential entities, whichever is higher; under § 45(3) up to EUR 7,000,000 or 1.4 percent for important entities. Alongside sits a second tier: § 45(4) provides up to EUR 50,000, and up to EUR 100,000 on repetition, for formal breaches such as late registration, missed change notification, omitted self-declaration or obstruction of inspections. Penalties are imposed by the Bezirksverwaltungsbehörde after the Cybersicherheitsbehörde files a referral.

The NISG 2026 obliges management bodies in § 31(1) to ensure and supervise compliance with the risk management measures, and in § 31(2) to attend cybersecurity training designed for them; both training duties are penalised under § 45(1) nos. 1 and 2. It contains no express internal liability provision comparable to § 38(2) BSIG 2025 in Germany. Instead, under § 39(4) no. 2 the Cybersicherheitsbehörde may temporarily prohibit the management bodies of an essential entity from performing management duties by formal decision — and that decision goes to the commercial register court for entry. Company law duties of care remain untouched; assessing them in a specific case belongs with an Austrian law firm.

Not necessarily. § 25(4) NISG 2026 provides that the data of partner or linked enterprises are not aggregated where the entity is organisationally, technically and operationally independent in respect of the network and information systems used to provide its services. Centralised IT, shared identity management or a group SOC argue against that independence. In addition, under § 26 the Cybersicherheitsbehörde may classify an entity by formal decision regardless of size. The decision should be documented with reasons, because the entire scope question rests on it.

Substantively for the most part, formally not at all. Both statutes transpose the same Directive (EU) 2022/2555, so the risk analysis, security concepts, incident response plan, supplier register and restore evidence work as a shared control set. What must be kept separate are registration, reporting route and credentials, deadline calendars, evidence formats, and training records per management body and company. Both statutes attach to the individual entity, not to the group — a German registration never substitutes for the Austrian one.

NISG 2026NIS2ÖsterreichComplianceCybersecurityDACH

Ready for Your Assessment?

Use our interactive templates to measure your IT organization's maturity — with automatic scores, AI-powered recommendations, and professional PDF reports.