Checked on September 27, 2026

NIS2 in Austria

How Austria applies the NIS2 cybersecurity directive: the national law, who supervises, and how to register and report incidents.

Transposition status
Adopted, not yet in force
National law
Network and Information System Security Act 2026 · Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) · from October 1, 2026
National CSIRT
CERT.at (national CSIRT)
Registration
Required · deadline December 31, 2026

Register with the cyber security authority within 3 months of entry into force; format to be set by regulation. Self-declaration on risk measures due within 12 months after registration obligation.

Incident reporting
Significant incidents to the competent CSIRT (CERT.at, via https://nis2.cert.at/): early warning 24h, notification 72h, final report 1 month.
National specifics
  • Passed by the Nationalrat on 2025-12-12 and published 2025-12-23 (BGBl I 94/2025).
  • Fines: essential entities up to EUR 10m or 2% of turnover; important up to EUR 7m or 1.4%; public bodies subject to naming instead of fines.

Where does your company stand?

The free assessment applies these national rules to your answers and scores every area of the law.

Sources

National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.

NIS2 in other countries

NIS2 in Austria: national law, authority and registration | Parendum