NIS-2 in Austria: the NISG 2026 has arrived
After long delay, Austria has implemented the European NIS-2 directive: the Network and Information System Security Act 2026 (NISG 2026, Federal Law Gazette I 94/2025) entered into force at the start of the year; the central obligations take effect in stages over the course of 2026.
Who is covered now
The scope grows dramatically: from around a hundred operators of essential services to several thousand companies across 18 sectors – including energy, transport, health and digital infrastructure, but also food production, waste management and manufacturing. Depending on the sector, companies from 50 employees or 10 million euros in turnover are covered; those affected must register themselves – waiting for an official request is not a strategy.
Management is personally on the hook
The sharpest point in practice: the act makes governing bodies expressly responsible for implementing the cybersecurity measures. Managing directors and board members must approve the risk management measures, supervise their implementation and undergo training themselves. Delegating downwards does not relieve them.
What to do
- Clarify applicability: sector, size class, role in the supply chain – suppliers of covered companies also receive the requirements contractually passed down.
- Register with the competent authority in time.
- Risk management in line with the state of the art: access control, encryption, backup concepts, supply chain security, contingency plans.
- Set up reporting channels: significant incidents require an initial report within 24 hours, with follow-up reports.
The overlap with the GDPR is intentional: anyone who has done their homework there – records of processing, technical measures, reporting processes – already has a foundation for the NISG. We assess applicability and build on it.
This information is general in nature and does not replace legal advice on an individual case.