Austria has passed the NISG 2026.
From 1 October 2026, essential and important entities covered by the law must have governance, cybersecurity risk-management measures and incident reporting in place. Later registration and self-declaration dates do not delay these duties.
Read section 51 of the NISG 2026 and the WKO and Austrian NIS authority FAQ.
Key dates and duties
Core duties start
Management oversight, training, security measures and incident reporting must be working.
Registration deadline
Entities covered on 1 October must complete their electronic registration by this date.
First self-declaration is due
The declaration covers security measures, relevant systems, suppliers and risk findings.
Common implementation problems
Public posts describe old systems, missing records and too much confidence in an ISO 27001 certificate.
Es gibt Rechner wo selbstprogrammierte alte Programme laufen, die wichtig sind für den Betrieb und älter sind als 20 Jahre…Wie dokumentiert ihr die Teilnahme? Wie führt ihr den Nachweis gegenüber Auditoren oder Behörden?We hold ISO 27001 and I always assumed that would carry most of the weight … and boy was I wrong.Check whether each legal entity is covered
The main NISG 2026 test uses sector and size. Each legal entity must check its own position. Do not wait for an authority letter before checking whether registration is required.
Check the sector
Annex 1 covers highly critical sectors. Annex 2 covers other critical sectors. In some categories, a secondary activity can bring the legal entity into scope.
Check the size and special rules
Medium generally means at least 50 employees, or more than €10 million in annual turnover and more than €10 million on the balance sheet. Large means at least 250 employees, or more than €50 million turnover and more than €43 million on the balance sheet. Company-group figures and special rules can change the answer.
Annex 1: high criticality
- Energy
- Transport
- Banking
- Financial market infrastructure
- Health
- Drinking water
- Wastewater
- Digital infrastructure
- B2B ICT service management
- Public administration
- Space
Annex 2: other critical sectors
- Postal and courier services
- Waste management
- Chemicals
- Food production, processing and distribution
- Manufacturing
- Digital providers
- Research
Essential and important entities
Under the main rule, a large Annex 1 entity is essential. Medium Annex 1 entities and medium or large Annex 2 entities are important unless another rule makes them essential. Some providers, public bodies and designated entities have extra rules.
Company groups
Partner and linked companies usually count in the size test. Section 25 has a narrow exception based on how the relevant systems are organised, operated and secured.
DORA
Current WKO guidance treats DORA as the main regime for certain security and reporting duties. Covered financial entities still register and file a self-declaration under the NISG.
For the full test, read NISG section 24 and section 25. The WKO self-assessment can help, but it is not a binding scope decision.
Put these duties in place by 1 October 2026
The measures must suit the organisation's risks and size. They must also reflect how likely an incident is and how much harm it could cause.
The management body must oversee the work
The management body must ensure and supervise the security measures. Every member must take cybersecurity training for the role. The organisation must also offer suitable training to employees on a regular basis.
The ten risk-management areas
- 01
Risk analysis and information-system security policies
- 02
Incident handling
- 03
Business continuity, backup, disaster recovery and crisis management
- 04
Security of immediate suppliers and service providers
- 05
Secure acquisition, development and maintenance, including vulnerability handling
- 06
Evaluation of whether cybersecurity measures are effective
- 07
Basic cyber hygiene and cybersecurity training
- 08
Cryptography and, where appropriate, encryption
- 09
Personnel security, access control and asset management
- 10
Multi-factor or continuous authentication and secure communications
Your incident-reporting process must work at all times
Early warning
Send it as soon as possible and within 24 hours of becoming aware.
Incident notification
Send more detail about the severity, impact and available indicators.
Final report
Send it within one month after the 72-hour notice. Use a progress report if the incident is still active.
An incident is significant if it caused, or could cause, severe disruption, severe financial loss or serious harm to another person. Other factors include service dependencies, health, the environment, market importance, location and technical severity. Send reports to the relevant sector CSIRT, or to the national CSIRT if no sector CSIRT applies.
The reporting rules are in sections 31, 32, 34 and 35 of the NISG 2026.
Prepare registration while putting controls in place
An entity covered when the law starts must register between 1 October and 31 December 2026. An entity covered later must register as soon as possible and within three months of meeting the conditions.
Each legal entity registers separately. The current plan uses an online form in the Austrian Business Service Portal (USP) or the public-sector portal network. Prepare the company, address, contact, sector, location, size and technical data now. The authority has not yet confirmed that the form is available.
The first self-declaration is due by 30 September 2027. It helps the authority assess the entity. It does not replace an audit.
Read NISG section 29, section 33 and the WKO timetable for the filing rules.
How ISO 27001 can help
ISO 27001 can organise much of the security work and its records. It does not decide legal scope, make Austrian filings or prove that an untested control works.
ISO 27001 can organise
- A governed risk method, risk register and treatment decisions
- Defined responsibilities, competence records and management review
- Supplier inventory, assessment, contracts and service review
- Incident handling, continuity, backup and recovery procedures
- Access, asset, vulnerability, logging and cryptography controls
- Internal audit, effectiveness checks and corrective action
NISG work to handle separately
- The legal entity, sector, size and essential-or-important classification
- Registration with the Austrian cybersecurity authority
- The NISG self-declaration and any authority-requested proof
- A statutory 24-hour, 72-hour and final-report route to the correct CSIRT
- Role-specific management-body training and evidence of oversight
- Austrian and applicable EU sector rules beyond the ISO standard
ISO 27001 certification alone does not meet every NISG duty. A valid certificate can help prove operational and organisational measures within its scope. It does not prove technical implementation. Parts of the entity outside the certificate scope need other proof.
Map the shared controls and keep the records in one managed system. Track Austrian scope, reporting, deadlines, filings and owners separately.
The Austrian FAQ explains how ISO 27001 evidence may be used. ENISA has technical guidance for digital sectors covered by EU Implementing Regulation 2024/2690.
Five steps to prepare
These steps help management review scope, security measures, records and open risks. They do not guarantee compliance.
- 01
Record the scope decision
Check each legal entity against the sectors, size rules, company-group rules and special inclusions. Record the answer, the evidence, the reviewer and the next review date.
The executive sponsor should work with legal or compliance and security.
Store a scope record and classification decision for each entity.
- 02
Give management clear responsibility
Give the management body a clear list of gaps, owners, priorities and open decisions. Arrange role-specific cybersecurity training and keep the materials, attendance and actions.
The management body and implementation lead should approve the work.
Keep the approved mandate, training records and decision log.
- 03
Assign each security area to an owner
Compare current controls and records with each NISG risk area. For every gap, record the owner, action, due date, temporary control and proof that the measure works.
Security, IT, operations, HR, procurement and service owners share the work.
Use a risk-based gap register and an approved treatment plan.
- 04
Test incident reporting
Run an exercise for a realistic incident. Check the decision, early warning and full notification. Confirm the right CSIRT, weekend cover, approval route and the information available after 24 and 72 hours.
The incident lead should work with legal, communications and the management duty officer.
Keep the tested escalation route, report templates and exercise findings.
- 05
Prepare supplier records and registration data
Start with suppliers that support relevant systems. Record dependencies, weaknesses, contract terms, security evidence and fallback options. Gather the company, sector, location, contact and technical data needed for registration.
Procurement and service owners should work with legal and the registration owner.
Prepare a prioritised supplier record and registration data pack.
Maximum penalties under NISG 2026
These are maximum amounts, not automatic fines. The result depends on the entity and the breach.
Essential entities
€10m or 2%Up to the higher of €10 million or 2% of the undertaking's prior-year worldwide turnover.
Important entities
€7m or 1.4%Up to the higher of €7 million or 1.4% of the undertaking's prior-year worldwide turnover.
Late or knowingly false registration, missed updates, self-declaration failures and some obstruction offences can lead to a fine of up to €50,000. For repeat offences, the maximum is €100,000.
Read the penalty rules in NISG section 45.
Your questions, answered.
When does NIS2 take effect in Austria?
Austria's NIS2 law, the NISG 2026, takes effect on 1 October 2026. From that date, covered essential and important entities must meet the governance, training, cybersecurity risk-management and significant-incident reporting duties that apply to them.
Which organisations fall under Austria's NISG 2026?
The main test combines work in one of 18 sectors with medium or large company size. Some entities are covered whatever their size. Figures from linked or partner companies can affect the calculation. Each legal entity must check its own position.
When and how must an Austrian NIS2 entity register?
An essential or important entity covered on 1 October 2026 must register online by 31 December 2026. Current guidance says the form will use Austria's Business Service Portal or the public-sector portal network. Prepare the required data now, but check that the form is available before trying to submit it.
Does ISO 27001 certification satisfy NIS2 in Austria?
No. ISO 27001 certification alone is not enough. A valid certificate can help prove operational and organisational measures within its scope. It does not prove technical implementation or replace registration, incident reporting and other NISG duties.
What are the Austrian NIS2 incident-reporting deadlines?
For a significant incident, the entity must send an early warning within 24 hours of becoming aware. It must send an incident notification within 72 hours. A final report is normally due within one month after that notification.
Can a small Austrian supplier still be affected by NIS2?
Yes. A small supplier may be covered by a special category or official designation. Even when it is not directly covered, a customer may ask for security terms, evidence and help with incident reporting because the customer must manage supplier risk.
Use the rules and deadlines for each country
NIS2 is implemented through national law. If your organisation also operates in the Netherlands, use the Dutch guide for the Dutch authority, scope and filing process.
