Photo of Mag. Eduard Frankford M.Sc.
WRITTEN BY Mag. Eduard Frankford M.Sc.

NIS2 Directive 2026: what companies in Austria need to know and do now

Illustrative image for the NIS2 directive

Originally published on 29 June 2024 and fully revised on 27 July 2026. The article reflects the Austrian NISG 2026 passed in December 2025 as well as current studies on the threat landscape.

With the NIS2 Directive (EU) 2022/2555 the EU has significantly tightened its cybersecurity requirements. Since late 2025 it is also clear how Austria implements it: the Network and Information System Security Act 2026 (NISG 2026) was passed by the National Council on 12 December 2025 and applies from 1 October 2026. For many companies the hot phase starts now, because the registration deadline already ends on 31 December 2026.

This article sums up the current status: who is affected, which duties and fines the law brings and which steps companies should take now. All sources are linked at the end of the article.

The current status: the NISG 2026 has been passed

Austria implemented the NIS2 directive with considerable delay. The EU deadline expired on 17 October 2024, which is why the European Commission opened infringement proceedings against Austria and 22 other member states in November 2024. A first attempt, the NISG 2024, failed to reach the required two-thirds majority in the National Council. On 12 December 2025 the NISG 2026 was finally passed and promulgated in the Federal Law Gazette on 23 December 2025 (BGBl. I No. 94/2025). The law also creates a new supervisory authority, the Federal Office for Cybersecurity within the Ministry of the Interior. According to estimates from the parliamentary debate, around 4,000 companies and organisations are affected.

The key dates at a glance:

  • 1 October 2026: The NISG 2026 enters into force. From this day the risk management and reporting duties apply, and the previous NISG 2018 is repealed.
  • 31 December 2026: End of the registration period. Affected companies must register with the cybersecurity authority within three months of entry into force, according to the WKO via the Austrian business service portal (USP).
  • 30 September 2027: Deadline for the self-declaration. Within twelve months of the registration duty taking effect, companies must report to the authority in a structured form which risk management measures they have implemented.
  • After that: Upon request by the authority, an audit by an independent body must be provided within two years. The audit report has to be signed personally by the management.

Who is affected?

The NISG 2026 covers 18 sectors, from energy, transport and health via digital infrastructure and IT services to manufacturing. Within these sectors, company size is generally decisive:

  • Medium-sized companies: from 50 employees or more than 10 million euros in both turnover and balance sheet total. They usually count as important entities.
  • Large companies: from 250 employees or more than 50 million euros in turnover and 43 million euros in balance sheet total. In the sectors of high criticality they count as essential entities and are therefore subject to stricter supervision, including proactive audits.
  • Special cases regardless of size: for example DNS service providers, trust service providers, parts of the public administration or entities classified by the authority by official decision.

Important to know: the classification is a self-assessment, and as a rule there is no official decision by the authority. The free online guide of the Austrian Economic Chamber (WKO) is a good starting point. KPMG surveys show that many companies misjudge their own affectedness, and quite a few wrongly believe they are not affected. And even companies below the thresholds often feel NIS2 through the supply chain, more on that below.

The most important duties at a glance

  • Governance: Cybersecurity is a management responsibility. Management must ensure the implementation of the measures, supervise compliance and attend dedicated cybersecurity trainings. Omitted trainings are a separate punishable offence (secs. 31 and 45 NISG 2026).
  • Risk management: Sec. 32 NISG 2026 prescribes ten minimum measures, from incident management to supply chain security. Details in the next section.
  • Reporting duties: Significant security incidents must be reported to the competent CSIRT: early warning within 24 hours, detailed notification with an initial assessment within 72 hours, final report within one month.
  • Registration: by 31 December 2026 with master data, sector and classification at the cybersecurity authority. Changes must be reported within two weeks.
  • Evidence: Self-declaration by 30 September 2027, afterwards audits by independent bodies upon request of the authority.

The ten risk management measures

The catalogue of measures in sec. 32 para. 4 NISG 2026 adopts the ten minimum measures from Art. 21 of the NIS2 directive. Required are:

  1. Policies on risk analysis and information system security
  2. Incident handling (incident management)
  3. Business continuity, meaning backup management, disaster recovery and crisis management
  4. Supply chain security including the relationships with direct suppliers and service providers
  5. Security in the acquisition, development and maintenance of IT systems including vulnerability handling and disclosure
  6. Procedures to assess the effectiveness of the measures
  7. Cyber hygiene and regular cybersecurity trainings
  8. Policies on cryptography and encryption
  9. Human resources security, access control and asset management
  10. Multi-factor authentication and secured voice, video and text communication

The benchmark is the state of the art, but the measures may be proportionate to risk and company size. Standards such as ISO/IEC 27001 serve as orientation. Caution: an ISO 27001 certification does not automatically count as NIS2-compliant. The German BSI explicitly recommends a complementary gap analysis even to certified companies, because NIS2 goes beyond the standard in scope, reporting deadlines and governance duties, among other things.

Fines: up to 10 million euros

The NISG 2026 provides for substantial fines:

  • Essential entities: up to 10 million euros or 2 percent of the total worldwide turnover of the preceding financial year, whichever amount is higher.
  • Important entities: up to 7 million euros or 1.4 percent of the total worldwide turnover of the preceding financial year.
  • Formal violations: such as a missed registration or self-declaration cost up to 50,000 euros, and up to 100,000 euros in case of repetition.

There is also an often overlooked point: for essential entities the authority can, as an enforcement measure, temporarily prohibit individual executives from exercising managerial functions. This prohibition is entered in the commercial register.

The threat landscape in numbers

There is a real background to the legislator's pressure. A look at current, documented figures:

  • In 2025, 63,459 internet crime offences were reported in Austria. Cybercrime in the narrow sense, meaning hacking, data damage, DDoS and the like, rose by 8.6 percent (Austrian Criminal Intelligence Service, Crime Report 2025).
  • One in eight cyberattacks on Austrian companies was recently successful, and one in four companies hit by ransomware paid the ransom. In 40 percent of the attack cases ineffective patch management was the entry point (KPMG study Cybersecurity in Austria 2026, 1,396 companies surveyed).
  • 22 percent of Austrian companies experienced attacks via compromised service providers, and for 39 percent a service provider or supplier itself became the victim of an attack within one year (KPMG 2026).
  • Worldwide, the share of data breaches involving third parties doubled to 30 percent within one year. For small and medium-sized businesses, ransomware was present in 88 percent of the breaches analysed (Verizon Data Breach Investigations Report 2025).
  • Phishing remains by far the most common initial access vector in Europe at around 60 percent (ENISA Threat Landscape 2025).

NIS2 and the supply chain: why small service providers are affected too

One point is central when awarding software and web development contracts: supply chain security is one of the ten mandatory measures. Affected companies must assess the cybersecurity practice of their direct suppliers, explicitly including the security of their development processes. The WKO puts it in a nutshell: service providers and suppliers of affected entities will be contractually obliged to implement risk management measures.

As a client you should therefore:

  • Put security requirements and reporting duties into the contract, including the question of who reports which incident to whom within which deadline.
  • Request evidence. According to the WKO, recognised proofs include ISO/IEC 27001, IEC 62443 or the Austrian CyberRisk rating based on the KSÖ scheme, handled via KSV1870.
  • Re-assess service providers regularly instead of only once at onboarding, and keep an eye on their subcontractors as well.

The reverse also applies: software developers, IT service providers and suppliers working for NIS2-regulated customers receive the requirements via security questionnaires and contract clauses, entirely without a legal duty of their own. Those who proactively prepare evidence such as a certification or a rating turn the obligation into a competitive advantage. For providers such as managed service providers, cloud providers or data centres, EU-wide uniform technical requirements additionally apply directly from Implementing Regulation (EU) 2024/2690.

Our tips: how to prepare your company now

  1. Check affectedness: Check sector and size thresholds, for example with the free WKO online guide. Do not rely on gut feeling, many companies misjudge this.
  2. Clarify responsibility: Involve the management, define budget and responsibilities and schedule the mandatory training for the management level right away.
  3. Run a gap analysis: Compare the current state with the ten measure areas in a structured way and prioritise the gaps by risk. In June 2025 ENISA published practical implementation guidance for this, with a mapping to ISO 27001 and NIST CSF.
  4. Set up and rehearse the reporting process: If you only work out during an emergency who reports what to the CSIRT within 24 hours, you lose valuable time. Emergency contacts, report templates and a dry run are part of it.
  5. Map the supply chain: List critical service providers, request security evidence and add security and reporting clauses to contracts.
  6. Implement basic measures immediately: Multi-factor authentication, tested backups and consistent patch management take effect immediately and cover a large share of real-world attacks.
  7. Prepare registration and documentation: Have master data, classification and documentation of measures ready well before 31 December 2026. A look at funding programmes is also worthwhile, as their status changes constantly. KMU.DIGITAL was exhausted as of July 2026, while Tyrol's provincial digitalisation funding is still running.

Conclusion

With the NISG 2026 the years of limbo around Austria's NIS2 implementation are over. The deadlines are now fixed: entry into force on 1 October 2026, registration by 31 December 2026, self-declaration by 30 September 2027. Those who start early work through the requirements without rush and turn the obligation into a trust advantage with customers and partners. The current threat figures show that far more than compliance is at stake.

Want to know where your company stands? We check your affectedness free of charge and create a prioritised roadmap up to the registration deadline.

Get your free NIS2 gap analysis

Sources and further links

The growing importance of web development in the Innsbruck region

The article describes the growing importance of web development in the Innsbruck region. It provides an overview of the current scene and future trends.

Read
10 reasons why you should have your web design done by Frankford's IT-Solutions in Innsbruck

The article presents 10 compelling reasons why you should have your web design done by Frankford's IT-Solutions in Innsbruck. It discusses advantages such as local expertise, personal contact, quick response times, customized services, and long-term partnerships.

Read
Web development in Innsbruck

Here you can find the offers from Frankford's IT-Solutions. From consultation to the finished online project, you can completely rely on us. As a full-service web agency, we offer you a wide range of services - from web design, SEO to hosting.

Read