Austria · NISG 2026

Does NIS2 apply to your Austrian entity?

This check answers for Austria only. The NISG 2026 is the Austrian transposition of NIS2; every other member state transposed it differently, so if your entity is not established in Austria this will not give you a useful answer. No authority determines coverage of its own motion — each entity works it out itself and registers itself by 31 December 2026. This check takes you through that assessment and produces a dated document recording it.

  • Anonymous – your answers stay in your browser; the check stores and sends none of them
  • Every question cites the provision it comes from
  • Austrian citation style: § section · Abs. subsection · Z numbered point · lit. lettered sub-point. Annex 1/2 are the NISG’s own annexes (Anlage 1/2), not the EU Directive’s. ÖNACE is the Austrian version of the EU NACE industry classification; a Land (plural Länder) is one of Austria’s nine provinces.

What remains without JavaScript

The interactive check needs JavaScript. The classification itself is deliberately not summarised again here: it depends on several interlocking provisions of §§ 24 to 26, and an abbreviated second version would be wrong after the first amendment without anyone noticing. The Act itself governs in any case.

The key facts

  • Jurisdiction: Austria only. The NISG 2026 transposes NIS2 for Austria; other member states have their own laws.
  • Legal basis: Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), BGBl. I Nr. 94/2025, published 23 December 2025.
  • 1 October 2026: the Act applies. Risk management (§ 32), management-body duties including cybersecurity training (§ 31) and the reporting obligations (§ 34) apply without a transition period.
  • 31 December 2026: registration with the Federal Office for Cybersecurity (§ 29 Abs. 3). Entities that meet the conditions later have three months from that point.
  • Reporting deadlines for a significant incident: early warning within 24 hours, notification within 72 hours, final report within one month (§ 34 Abs. 2) — to the competent CSIRT.
  • Penalties: up to €10 million or 2 % of worldwide group turnover for essential entities, up to €7 million or 1.4 % for important entities (§ 45 Abs. 2 and 3); for breaches of the registration duties up to €50,000, and up to €100,000 for a repeat breach (§ 45 Abs. 4). These fines do not apply to public administration bodies — there a declaratory decision and publication take their place (§ 46 Abs. 2).
  • Channel for submitting the registration: not yet published. § 29 Abs. 2 requires only a secure electronic channel; ask the Federal Office for Cybersecurity before the deadline.

Note

These statements are guidance, not legal advice, and are not binding. Classification irrespective of size under § 26 is made solely by formal decision of the cybersecurity authority. TG Advisory is neither an „independent body“ nor an „independent auditor“ within the meaning of § 7 NISG 2026 and issues no proofs of implementation under § 33 Abs. 2 and 3. The full text of the Act is in the Austrian legal information system at ris.bka.gv.at (German only).

Who does NIS2 apply to in Austria?

The NISG 2026 covers entities that are established in Austria or provide services here, operate in one of the sectors of Annex 1 or Annex 2, and reach at least the size of a medium-sized enterprise (§ 24 read together with § 25). A few services are covered irrespective of size, among them providers of public electronic communications networks and services, DNS service providers, TLD name registries, trust service providers and public administration bodies. The lists below give the sectors in the order of the annexes. Classification itself also depends on main activity, size class and special cases, which is what the check works through question by question.

Annex 1 · Sectors of high criticality

Annex 1 Z 1 Energy

Electricity, district heating and cooling, oil, gas, hydrogen — including operators of public recharging points.

Annex 1 Z 2 Transport

Covered: commercial air carriers and airports · railway undertakings and infrastructure managers, including private sidings and service facilities · inland, sea and coastal shipping and ports · road authorities and operators of intelligent transport systems. Not covered: freight forwarders, hauliers, bus, taxi and delivery companies in road transport.

Annex 1 Z 3 Banking

Credit institutions as defined in Art. 4(1) of Regulation (EU) 575/2013.

Annex 1 Z 4 Financial market infrastructures

Operators of trading venues, central counterparties.

Annex 1 Z 5 Healthcare, laboratories, medicinal products

Healthcare providers as defined in Article 3(g) of Directive 2011/24/EU — hospitals, outpatient clinics, laboratories · EU reference laboratories · research and development of medicinal products and manufacture of basic pharmaceutical products (ÖNACE C21) · manufacturers of medical devices considered critical during a public health emergency.

Annex 1 Z 6 Drinking water

Suppliers and distributors of water intended for human consumption.

Annex 1 Z 7 Waste water

Collecting, disposing of or treating urban, domestic or industrial waste water.

Annex 1 Z 8 Internet, cloud and data centre services for others

Data centre or cloud computing services for customers · providers of public electronic communications networks and publicly available services · hosting and DNS · trust services such as electronic signatures and time stamps · internet exchange points (IXP) and content delivery networks (CDN).

Annex 1 Z 9 IT services for other businesses (IT systems house, managed services)

Managed service providers (MSP) and managed security service providers (MSSP): ongoing management of someone else’s IT — servers, networks, workplaces, backup, firewall, SOC. This covers IT systems houses and managed-security providers.

Annex 1 Z 10 Public administration

Bodies at federal and Land level. Municipalities and associations of municipalities are excluded.

Annex 1 Z 11 Ground stations for satellite services

Operators of ground-based infrastructure that supports the provision of space-based services — satellite ground stations and associated facilities.

Annex 2 · Other critical sectors

Annex 2 Z 1 Postal and courier services

Carrying and delivering letters, parcels or consignments for others — postal service providers (§ 3 Z 3 PMG) and courier, express and parcel services (§ 3 Z 4a PMG).

Annex 2 Z 2 Waste management

Undertakings within the meaning of § 2 Abs. 6 Z 3 and 4 AWG 2002 (Austrian Waste Management Act).

Annex 2 Z 3 Manufacture and wholesale distribution of chemicals

Covered: undertakings that manufacture substances and distribute those substances or mixtures at wholesale level, and the production of articles from them within ÖNACE division 20.

Annex 2 Z 4 Food: wholesale distribution and industrial processing

Food businesses engaged in wholesale distribution and in industrial production and processing. If only one of the two applies to you, select this field anyway — the Austrian wording says “and”, and whether that is meant cumulatively is unsettled.

Annex 2 Z 5 Manufacture of medical devices, electronics, machinery or vehicles

These only: medical devices and in vitro diagnostic medical devices · manufacture of computer, electronic and optical products (ÖNACE C26) · electrical equipment (C27) · machinery and equipment n.e.c. (C28) · motor vehicles, trailers and semi-trailers (C29) · other transport equipment (C30).

Annex 2 Z 6 Online marketplace, search engine or social network

Platforms on which third parties conclude business with one another · online search engines · social networking services.

Annex 2 Z 7 Research and development for commercial purposes

Entities whose primary objective is applied research or experimental development intended to be sold or commercially exploited — including research carried out for your own account and your own exploitation.

Frequently asked questions about the NISG 2026

What does the NIS2 scope check work out?

It walks through exactly the assessment the NISG 2026 leaves to each entity itself: establishment or provision of services in Austria, sector under Annex 1 or Annex 2, main activity, size class under § 25 and the special cases in §§ 24 to 26. What comes out is a dated document recording the answers, the result and the provisions relied on, ready to be filed.

Which entities does NIS2 cover in Austria?

As a rule, entities in the sectors of Annexes 1 and 2 that are at least a medium-sized enterprise within the meaning of § 25 Abs. 3. Irrespective of size, the Act also covers providers of public electronic communications networks and services, DNS service providers, TLD name registries, trust service providers and public administration bodies, among others. Unlike under the previous regime, no authority determines coverage of its own motion: each entity works it out itself. Only the size-independent classification under § 26 is made by formal decision of the cybersecurity authority.

Which size thresholds apply?

Medium-sized enterprise: 50 employees or more, or annual turnover above €10 million and an annual balance sheet total above €10 million (§ 25 Abs. 3). Large enterprise: 250 employees or more, or annual turnover above €50 million and an annual balance sheet total above €43 million (§ 25 Abs. 2). The two routes carry equal weight: the headcount alone can cross the threshold. Where network and information systems are shared with a group, the figures of partner and linked enterprises have to be added (§ 25 Abs. 4).

What is the difference between an essential and an important entity?

In substance there is none: the same risk-management and reporting requirements apply. The difference lies in supervision and in the level of fines. Essential entities are under full supervision and may be inspected without any particular cause; important entities are supervised on an ex-post basis and have longer deadlines for producing evidence. Fines run up to €10 million or 2 % of worldwide turnover, against €7 million or 1.4 % (§ 45 Abs. 2 and 3).

When does the NISG 2026 apply, and by when must an entity register?

The Act applies from 1 October 2026. Risk management (§ 32), the duties of the management body (§ 31) and the reporting obligations (§ 34) apply without a transition period. Registration with the Federal Office for Cybersecurity is due by 31 December 2026 (§ 29 Abs. 3); entities that meet the conditions later have three months from that point. The channel for submitting the registration has not been published yet — § 29 Abs. 2 requires only a secure electronic channel.

What duties fall on the management body?

The management body has to ensure the risk-management measures and oversee their implementation (§ 31 Abs. 1). Its members must complete cybersecurity training themselves and offer comparable training to staff (§ 31 Abs. 2). Failure to train the management body is the first offence listed in § 45 Abs. 1 Z 1 and sits in the highest band of fines. The Act therefore addresses the leadership level expressly, not the IT department.

What are the reporting deadlines for a significant incident?

Early warning within 24 hours, full notification including an initial assessment within 72 hours, final report within one month (§ 34 Abs. 2). The recipient is the competent CSIRT — the Act names it sector by sector, and for most sectors that is CERT.at.

What penalties does the NISG 2026 provide for?

Up to €10 million or 2 % of total worldwide turnover in the preceding financial year for essential entities, up to €7 million or 1.4 % for important entities (§ 45 Abs. 2 and 3). The higher amount governs, and the turnover that counts is that of the undertaking the entity belongs to, not only the entity itself. Late or incorrect registration: up to €50,000, and up to €100,000 for a repeat breach (§ 45 Abs. 4). These fines do not apply to public administration bodies; there a declaratory decision and publication take their place (§ 46 Abs. 2).

We are not directly covered. Does NIS2 still affect us?

Possibly as a supplier. Covered entities have to bring supply-chain security into their risk management (§ 32 Abs. 4) and pass the requirements on contractually. Not being covered therefore does not mean never having to produce evidence. The result also holds for today only: an entity that meets the conditions later, through growth, a new activity or a changed group structure, has to register within three months from that point (§ 29 Abs. 3 second sentence).

Is anything I enter stored?

No. The check runs entirely in your browser. There is no account and no sign-in, the answers are not transmitted to any server, and the result document is produced locally as well. The check is free of charge.

Does the check replace a legal assessment?

No. It is guidance, not legal advice, and it is not binding. Classification irrespective of size under § 26 is made solely by formal decision of the cybersecurity authority. TG Advisory is neither an "independent body" nor an "independent auditor" within the meaning of § 7 NISG 2026 and issues no proofs of implementation under § 33 Abs. 2 and 3. The text of the Act in the Austrian legal information system is what governs.

TG Advisory supports the implementation in an advisory and organisational capacity: gap analysis against NIS2 and the Austrian NISG 2026, risk management, policies, evidence readiness and training for the management body. The services page gives an overview.

Contact Us

Message received

Together for your cybersecurity

Thank you!

Your message has been successfully sent.
We will get back to you shortly.
An error occurred.
Please check your input and try again.