Checked on September 27, 2026
NIS2 in Austria
How Austria applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.
- Transposition status
- Adopted, not yet in force
- National law
- Network and Information System Security Act 2026 · Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) · from October 1, 2026
- Competent authority
- Federal Office for Cyber Security (under the Federal Ministry of the Interior) (Bundesamt für Cybersicherheit)
- National CSIRT
- CERT.at (national CSIRT)
- Registration
- Required · deadline December 31, 2026
Register with the cyber security authority within 3 months of entry into force; format to be set by regulation. Self-declaration on risk measures due within 12 months after registration obligation.
- Incident reporting
- Significant incidents to the competent CSIRT (CERT.at, via https://nis2.cert.at/): early warning 24h, notification 72h, final report 1 month.
- National specifics
- Passed by the Nationalrat on 2025-12-12 and published 2025-12-23 (BGBl I 94/2025).
- Fines: essential entities up to EUR 10m or 2% of turnover; important up to EUR 7m or 1.4%; public bodies subject to naming instead of fines.
Where does your company stand?
The free assessment applies these national rules to your answers and scores every area of the law.
Sources
- riscontrol.at/2025/12/15/news/nisg-2026-beschlossen/
- www.schoenherr.eu/content/oesterreich-nisg-2026-alles-was-sie-wissen-mussen
- www.wko.at/it-sicherheit/nis2-uebersicht
- www.parlament.gv.at/gegenstand/XXVIII/I/308
- www.heise.de/en/news/From-Oct-1-IT-incident-reporting-obligation-in-Austria-11462461.html
- www.nis.gv.at/
National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.