Austria adopted the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) in December 2025, promulgated in the Federal Law Gazette on 23 December 2025 as BGBl. I No. 94/2025. The Act enters into force on 1 October 2026, at which point the NIS2 framework becomes operational; the existing NISG 2018 regime continues to apply until then. Supervision passes to a new authority, the Bundesamt für Cybersicherheit (Federal Office for Cybersecurity) under the Federal Ministry of the Interior (BMI) — the ministry that took over the NIS Office and GovCERT Austria from the Federal Chancellery in April 2025. Around 4,000–5,000 Austrian entities are expected to fall within scope when NISG 2026 takes effect, with registration due by 1 January 2027.
- 23 Dec 2025NISG 2026 promulgated in the Federal Law Gazette (BGBl. I No. 94/2025) after the first transposition attempt failed in July 2024.
- 1 Oct 2026NISG 2026 enters into force — obligations apply in full from day one; the NISG 2018 regime ends.
- 1 Jan 2027Registration with the Bundesamt für Cybersicherheit due (three months from entry into force).
- 1 Oct 2027Self-declaration of implemented risk-management measures due (twelve months after the registration obligation arises — entry into force, for entities in scope on day one).
- Oct 2028Evidence requests begin running on statutory clocks — essential entities have two months to evidence operational and organisational measures.
Austria’s official NIS information point, run by the NIS authority within the BMI — today it covers the outgoing NISG 2018 regime and links the national incident-reporting platforms. The NISG 2026 registration procedure will be set by ordinance of the new Bundesamt für Cybersicherheit; registration is due within three months of entry into force, by 1 January 2027.