10 February 2026 · Legal position as of: August 2026

NIS-2 in Austria: the NISG 2026 has arrived

After long delay, Austria has implemented the European NIS-2 directive: the Network and Information System Security Act 2026 (NISG 2026, Federal Law Gazette I 94/2025) entered into force at the start of the year; the central obligations take effect in stages over the course of 2026.

Who is covered now

The scope grows dramatically: from around a hundred operators of essential services to several thousand companies across 18 sectors – including energy, transport, health and digital infrastructure, but also food production, waste management and manufacturing. Depending on the sector, companies from 50 employees or 10 million euros in turnover are covered; those affected must register themselves – waiting for an official request is not a strategy.

Management is personally on the hook

The sharpest point in practice: the act makes governing bodies expressly responsible for implementing the cybersecurity measures. Managing directors and board members must approve the risk management measures, supervise their implementation and undergo training themselves. Delegating downwards does not relieve them.

What to do

  • Clarify applicability: sector, size class, role in the supply chain – suppliers of covered companies also receive the requirements contractually passed down.
  • Register with the competent authority in time.
  • Risk management in line with the state of the art: access control, encryption, backup concepts, supply chain security, contingency plans.
  • Set up reporting channels: significant incidents require an initial report within 24 hours, with follow-up reports.

The overlap with the GDPR is intentional: anyone who has done their homework there – records of processing, technical measures, reporting processes – already has a foundation for the NISG. We assess applicability and build on it.

This information is general in nature and does not replace legal advice on an individual case.

More on this practice area: Data Protection Law (GDPR)