Skip to content

Austria · NISG 2026

Does NISG 2026 apply to your company?

From 01.10.2026 the Austrian NISG 2026 places new cybersecurity obligations on essential and important entities — and, through the supply chain, on many of their suppliers. We will tell you where you stand and what is due when.

  • 4,000

    Austrian companies and institutions of medium size and above are expected to fall under NISG 2026.

  • 01.10.2026

    The day the obligations start. The statute sets no transition period for the measures themselves.

  • €10M

    Maximum penalty for an essential entity, or 2% of worldwide annual turnover.

Sources: WKO, NIS-2 overview („rund 4.000 Unternehmen und Einrichtungen ab mittlerer Größe“); NISG 2026, BGBl. I Nr. 94/2025, § 45.

The deadlines

Four dates, and three of them hang off the first

There is no transition period for the measures themselves. Registration, the self-declaration and the possible audit are all counted from the day the law takes effect.

  1. 01.10.2026

    NISG 2026 takes effect

    From this day the risk-management obligations, the reporting obligations and the duties of the management body all apply.

  2. 31.12.2026

    Registration with the Bundesamt für Cybersicherheit

    Essential and important entities must register within three months of the law taking effect (§ 29). The form and the portal are to be set by a regulation that has not yet been issued.

  3. 30.09.2027

    Self-declaration

    You report to the authority which measures are in place. § 33 names the network and information systems in use, supply-chain security and the results of your risk analysis specifically.

  4. from 01.10.2028

    Audit by an independent body

    The authority may require evidence through an independent audit — on request, not automatically. An organization that has kept its registers up to date has nothing to catch up on.

Does this apply to you?

The free online check answers that in five minutes — anonymous, no registration, no sales call. The result appears straight away, with the paragraphs it rests on.

What the law requires

Five obligations, and one lands on the management body personally

§ 32 Abs. 4 names the substance in ten areas — from backup through supply chain to multi-factor sign-in. Proportionate to size and risk, but present in every area.

  1. Register

    Once with the Bundesamt für Cybersicherheit, with changes reported as they happen (§ 29).

  2. Manage risk

    Appropriate technical and organizational measures across the ten areas of § 32 Abs. 4.

  3. Report incidents

    Early warning within 24 hours, notification within 72 hours, final report after one month (§ 34). § 35 defines when an incident is significant.

  4. Lead from the top

    The management body has to ensure and supervise compliance with the risk-management measures, and must itself attend training designed for it (§ 31). A missed training falls in the highest penalty band of § 45.

  5. Prove it

    Self-declaration by 30.09.2027 (§ 33), and on the authority’s request an audit by an independent body as well.

The penalty range in § 45 reaches €10 million or 2% of worldwide annual turnover for essential entities, and €7 million or 1.4% for important ones. Formal breaches such as a missed registration or self-declaration carry up to €50,000, rising to €100,000 on repetition.

The national regulation has not been issued yet

For digital providers — DNS, cloud, data centres, CDN, managed services, trust services and others — Implementing Regulation (EU) 2024/2690 already applies directly. For every other sector the detail is to be set by a national regulation, and as this page stands it has not been issued. The WKO recommends working to the EU Implementing Regulation until it is. So do we — and every report we write says which part of it is binding and which part is orientation.

Suppliers too

Not affected yourself? Your customers may well be.

Entities in scope have to account for the security of their supply chain. In practice that means security questionnaires, new contract clauses and evidence requirements — reaching suppliers and service providers the law itself does not cover. Being ready for them turns a two-week scramble into a two-day answer, and stops a tender being lost to an unanswered question.

How we work

Five steps, in this order

Each step can be commissioned on its own, at a fixed price quoted on request. The order is the method: without a defensible classification, any list of measures is guesswork.

  1. 01

    Establish whether you are in scope

    Start the check

    The free online check answers the ordinary case in five minutes — anonymously and without registration. For borderline cases we work through what you actually do and which group companies count towards your size.

  2. 02

    Gap analysis

    A structured review across the ten areas of § 32 Abs. 4, expert-led and reported: where you stand, what comes first, and what has to hold up by the time of the self-declaration.

  3. 03

    Registration and management training

    Registration in time for 31.12.2026, and the training of the management body that § 31 requires explicitly — general staff awareness training does not normally satisfy it.

  4. 04

    Prepare the self-declaration

    Documenting the measures in place, the supply chain and the risk analysis by 30.09.2027, in a form that survives a later audit.

  5. 05

    Ongoing operation

    Virtual CISO and ISMS operation: registers stay current, reporting paths stay rehearsed, and an audit on request is not an emergency when 2028 arrives.

Why Spirity

Four reasons, and one of them is an address in Vienna

  • An office in Vienna

    Spirity GmbH, Saturn Tower, Leonard-Bernstein-Straße 10, 1220 Vienna. An Austrian entity, with German-language support.

  • ISO/IEC 27001 certified

    Through a UKAS-accredited body, for our own operation. That does not certify you — it means we work inside the framework we recommend, and can therefore say which NISG requirements an existing certification already covers and which it does not.

  • Platform-backed analysis

    Structured review, traceable evidence, reporting the management body can act on. The registers stay current because a tool keeps them rather than an inbox.

  • The statute, not marketing

    This page names the paragraphs it relies on, and says where a regulation is still missing. That is also the standard you are entitled to hold our advice to.

In detail

Each duty on its own page

Looking for one particular deadline or duty? Each is set out in full, with the paragraphs behind it.

FAQ

Frequently asked questions

The questions we hear most often from security and IT leaders.

Something not covered here? Ask us directly

Two things decide it: what you do, and how big you are. The activity has to fall inside one of the 18 sectors in Anlage 1 and Anlage 2 of the NISG 2026, and the size threshold starts at 50 employees, or turnover and balance sheet total both above €10 million. Some providers are covered regardless of size — DNS service providers, TLD registries, qualified trust service providers and public electronic communications among them. What counts is what you actually do, not what the company name says.

No, and this is the part that surprises people. You have to assess it yourself and register yourself by 31.12.2026. The Bundesamt für Cybersicherheit can additionally classify an entity by formal notice in certain cases, but that is the exception — the rule is self-assessment, and a missed registration is a formal breach in its own right.

Not the obligations — those are the same. The difference is supervision and penalties. Essential entities can be examined without any particular trigger; important entities are supervised mainly when there is cause, such as a self-declaration that shows gaps. The penalty ceiling differs too: €10 million or 2% of worldwide turnover against €7 million or 1.4%.

In many cases yes, and this is the most common reason a company turns out to be affected when it expected not to be. Sizes are worked out on the EU SME definition: linked enterprises above 50% count in full, partner enterprises between 25% and 50% count proportionally. A 30-person subsidiary of a large group is frequently not a small enterprise in the eyes of the law.

Possibly. Anlage 1 Z 9 does carry an exemption, but a narrow one: managed services "operated and used exclusively by the entity concerned". It is written around the single entity, not the group — so a central group IT company that serves its sister companies is, on the wording, outside the exemption and can count as a managed service provider on its own account. Worth having examined rather than assumed; the assumption usually runs the wrong way.

§ 32 Abs. 4 names ten areas, from risk analysis and incident handling through supply chain, cryptography and access control to multi-factor authentication. The detail is left to a regulation. For digital providers, Implementing Regulation (EU) 2024/2690 already applies directly and is binding. For every other sector the national regulation has not been issued yet, and until it is the WKO recommends working to the EU regulation — which is what we do, saying in each report which part is binding and which is orientation.

Yes. § 31 requires the members of the management body to take part in cybersecurity training designed for them, and general staff awareness training does not normally satisfy it. The statute sets no separate deadline for it, which means it applies from 01.10.2026 like the rest of § 31 — together with the duty to ensure and supervise compliance that the same paragraph places on the same people. And a missed training is not a formal breach: § 45 Abs. 1 Z 1 puts it in the highest penalty band.

It is a strong foundation and covers a great deal of § 32 Abs. 4, but it does not cover everything the NISG 2026 asks for. Registration, the incident reporting deadlines, the self-declaration and the training of the management body are statutory duties that no certificate discharges. The useful exercise is mapping what your existing certification already evidences and naming what is left, rather than assuming either extreme.

No. What we produce is a reasoned assessment with the paragraphs it rests on, which is what you need in order to decide and to document the decision. It is not legal advice and it does not bind the authority. For genuine borderline cases we recommend a legal review, and we will say plainly when we think yours is one.

Sources

What this page cites

Every deadline, paragraph and figure on this page comes from one of these documents.

As at 24.09.2026.

This page is general information and is not legal advice. What governs is the NISG 2026 (BGBl. I Nr. 94/2025), the regulations issued under it, and any notice from the Bundesamt für Cybersicherheit.

Not sure which side of the line you are on?

The borderline cases almost always come down to two questions: what you actually do, and who counts towards your size. Both are worth half an hour with somebody who has read the statute.