Austria · NISG 2026
Does NISG 2026 apply to your company?
From 01.10.2026 the Austrian NISG 2026 places new cybersecurity obligations on essential and important entities — and, through the supply chain, on many of their suppliers. We will tell you where you stand and what is due when.
4,000
Austrian companies and institutions of medium size and above are expected to fall under NISG 2026.
01.10.2026
The day the obligations start. The statute sets no transition period for the measures themselves.
€10M
Maximum penalty for an essential entity, or 2% of worldwide annual turnover.
Sources: WKO, NIS-2 overview („rund 4.000 Unternehmen und Einrichtungen ab mittlerer Größe“); NISG 2026, BGBl. I Nr. 94/2025, § 45.
Four dates, and three of them hang off the first
There is no transition period for the measures themselves. Registration, the self-declaration and the possible audit are all counted from the day the law takes effect.
- 01.10.2026
NISG 2026 takes effect
From this day the risk-management obligations, the reporting obligations and the duties of the management body all apply.
- 31.12.2026
Registration with the Bundesamt für Cybersicherheit
Essential and important entities must register within three months of the law taking effect (§ 29). The form and the portal are to be set by a regulation that has not yet been issued.
- 30.09.2027
Self-declaration
You report to the authority which measures are in place. § 33 names the network and information systems in use, supply-chain security and the results of your risk analysis specifically.
- from 01.10.2028
Audit by an independent body
The authority may require evidence through an independent audit — on request, not automatically. An organization that has kept its registers up to date has nothing to catch up on.
Does this apply to you?
The free online check answers that in five minutes — anonymous, no registration, no sales call. The result appears straight away, with the paragraphs it rests on.
Five obligations, and one lands on the management body personally
§ 32 Abs. 4 names the substance in ten areas — from backup through supply chain to multi-factor sign-in. Proportionate to size and risk, but present in every area.
Register
Once with the Bundesamt für Cybersicherheit, with changes reported as they happen (§ 29).
Manage risk
Appropriate technical and organizational measures across the ten areas of § 32 Abs. 4.
Report incidents
Early warning within 24 hours, notification within 72 hours, final report after one month (§ 34). § 35 defines when an incident is significant.
Lead from the top
The management body has to ensure and supervise compliance with the risk-management measures, and must itself attend training designed for it (§ 31). A missed training falls in the highest penalty band of § 45.
Prove it
Self-declaration by 30.09.2027 (§ 33), and on the authority’s request an audit by an independent body as well.
The penalty range in § 45 reaches €10 million or 2% of worldwide annual turnover for essential entities, and €7 million or 1.4% for important ones. Formal breaches such as a missed registration or self-declaration carry up to €50,000, rising to €100,000 on repetition.
The national regulation has not been issued yet
For digital providers — DNS, cloud, data centres, CDN, managed services, trust services and others — Implementing Regulation (EU) 2024/2690 already applies directly. For every other sector the detail is to be set by a national regulation, and as this page stands it has not been issued. The WKO recommends working to the EU Implementing Regulation until it is. So do we — and every report we write says which part of it is binding and which part is orientation.
Not affected yourself? Your customers may well be.
Entities in scope have to account for the security of their supply chain. In practice that means security questionnaires, new contract clauses and evidence requirements — reaching suppliers and service providers the law itself does not cover. Being ready for them turns a two-week scramble into a two-day answer, and stops a tender being lost to an unanswered question.
Five steps, in this order
Each step can be commissioned on its own, at a fixed price quoted on request. The order is the method: without a defensible classification, any list of measures is guesswork.
- 01
Establish whether you are in scope
The free online check answers the ordinary case in five minutes — anonymously and without registration. For borderline cases we work through what you actually do and which group companies count towards your size.
- 02
Gap analysis
A structured review across the ten areas of § 32 Abs. 4, expert-led and reported: where you stand, what comes first, and what has to hold up by the time of the self-declaration.
- 03
Registration and management training
Registration in time for 31.12.2026, and the training of the management body that § 31 requires explicitly — general staff awareness training does not normally satisfy it.
- 04
Prepare the self-declaration
Documenting the measures in place, the supply chain and the risk analysis by 30.09.2027, in a form that survives a later audit.
- 05
Ongoing operation
Virtual CISO and ISMS operation: registers stay current, reporting paths stay rehearsed, and an audit on request is not an emergency when 2028 arrives.
Four reasons, and one of them is an address in Vienna
An office in Vienna
Spirity GmbH, Saturn Tower, Leonard-Bernstein-Straße 10, 1220 Vienna. An Austrian entity, with German-language support.
ISO/IEC 27001 certified
Through a UKAS-accredited body, for our own operation. That does not certify you — it means we work inside the framework we recommend, and can therefore say which NISG requirements an existing certification already covers and which it does not.
Platform-backed analysis
Structured review, traceable evidence, reporting the management body can act on. The registers stay current because a tool keeps them rather than an inbox.
The statute, not marketing
This page names the paragraphs it relies on, and says where a regulation is still missing. That is also the standard you are entitled to hold our advice to.
Each duty on its own page
Looking for one particular deadline or duty? Each is set out in full, with the paragraphs behind it.
Frequently asked questions
The questions we hear most often from security and IT leaders.
Something not covered here? Ask us directly
Two things decide it: what you do, and how big you are. The activity has to fall inside one of the 18 sectors in Anlage 1 and Anlage 2 of the NISG 2026, and the size threshold starts at 50 employees, or turnover and balance sheet total both above €10 million. Some providers are covered regardless of size — DNS service providers, TLD registries, qualified trust service providers and public electronic communications among them. What counts is what you actually do, not what the company name says.
No, and this is the part that surprises people. You have to assess it yourself and register yourself by 31.12.2026. The Bundesamt für Cybersicherheit can additionally classify an entity by formal notice in certain cases, but that is the exception — the rule is self-assessment, and a missed registration is a formal breach in its own right.
Not the obligations — those are the same. The difference is supervision and penalties. Essential entities can be examined without any particular trigger; important entities are supervised mainly when there is cause, such as a self-declaration that shows gaps. The penalty ceiling differs too: €10 million or 2% of worldwide turnover against €7 million or 1.4%.
In many cases yes, and this is the most common reason a company turns out to be affected when it expected not to be. Sizes are worked out on the EU SME definition: linked enterprises above 50% count in full, partner enterprises between 25% and 50% count proportionally. A 30-person subsidiary of a large group is frequently not a small enterprise in the eyes of the law.
Possibly. Anlage 1 Z 9 does carry an exemption, but a narrow one: managed services "operated and used exclusively by the entity concerned". It is written around the single entity, not the group — so a central group IT company that serves its sister companies is, on the wording, outside the exemption and can count as a managed service provider on its own account. Worth having examined rather than assumed; the assumption usually runs the wrong way.
§ 32 Abs. 4 names ten areas, from risk analysis and incident handling through supply chain, cryptography and access control to multi-factor authentication. The detail is left to a regulation. For digital providers, Implementing Regulation (EU) 2024/2690 already applies directly and is binding. For every other sector the national regulation has not been issued yet, and until it is the WKO recommends working to the EU regulation — which is what we do, saying in each report which part is binding and which is orientation.
Yes. § 31 requires the members of the management body to take part in cybersecurity training designed for them, and general staff awareness training does not normally satisfy it. The statute sets no separate deadline for it, which means it applies from 01.10.2026 like the rest of § 31 — together with the duty to ensure and supervise compliance that the same paragraph places on the same people. And a missed training is not a formal breach: § 45 Abs. 1 Z 1 puts it in the highest penalty band.
It is a strong foundation and covers a great deal of § 32 Abs. 4, but it does not cover everything the NISG 2026 asks for. Registration, the incident reporting deadlines, the self-declaration and the training of the management body are statutory duties that no certificate discharges. The useful exercise is mapping what your existing certification already evidences and naming what is left, rather than assuming either extreme.
No. What we produce is a reasoned assessment with the paragraphs it rests on, which is what you need in order to decide and to document the decision. It is not legal advice and it does not bind the authority. For genuine borderline cases we recommend a legal review, and we will say plainly when we think yours is one.
What this page cites
Every deadline, paragraph and figure on this page comes from one of these documents.
- NISG 2026, BGBl. I Nr. 94/2025
The text of the law in the federal legal information system.
- Federal Law Gazette, with Anlage 1 and Anlage 2
The 18 sectors, in the official PDF.
- Implementing Regulation (EU) 2024/2690
The directly applicable detail for digital providers.
- Bundesamt für Cybersicherheit
The competent authority.
- WKO — NIS-2 overview
Where the figure of roughly 4,000 affected entities comes from.
As at 24.09.2026.
This page is general information and is not legal advice. What governs is the NISG 2026 (BGBl. I Nr. 94/2025), the regulations issued under it, and any notice from the Bundesamt für Cybersicherheit.
Not sure which side of the line you are on?
The borderline cases almost always come down to two questions: what you actually do, and who counts towards your size. Both are worth half an hour with somebody who has read the statute.