Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
Back to the NIS2 overview
NIS2 · Austria

NIS2 in Austria — transposition status and what’s changed

Austria adopted the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) in December 2025, promulgated in the Federal Law Gazette on 23 December 2025 as BGBl. I No. 94/2025. The Act enters into force on 1 October 2026, at which point the NIS2 framework becomes operational; the existing NISG 2018 regime continues to apply until then. Supervision passes to a new authority, the Bundesamt für Cybersicherheit (Federal Office for Cybersecurity) under the Federal Ministry of the Interior (BMI) — the ministry that took over the NIS Office and GovCERT Austria from the Federal Chancellery in April 2025. Around 4,000–5,000 Austrian entities are expected to fall within scope when NISG 2026 takes effect, with registration due by 1 January 2027.

Key dates
  • 23 Dec 2025NISG 2026 promulgated in the Federal Law Gazette (BGBl. I No. 94/2025) after the first transposition attempt failed in July 2024.
  • 1 Oct 2026NISG 2026 enters into force — obligations apply in full from day one; the NISG 2018 regime ends.
  • 1 Jan 2027Registration with the Bundesamt für Cybersicherheit due (three months from entry into force).
  • 1 Oct 2027Self-declaration of implemented risk-management measures due (twelve months after the registration obligation arises — entry into force, for entities in scope on day one).
  • Oct 2028Evidence requests begin running on statutory clocks — essential entities have two months to evidence operational and organisational measures.
National competent authority
Austrian NIS Office

Austria’s official NIS information point, run by the NIS authority within the BMI — today it covers the outgoing NISG 2018 regime and links the national incident-reporting platforms. The NISG 2026 registration procedure will be set by ordinance of the new Bundesamt für Cybersicherheit; registration is due within three months of entry into force, by 1 January 2027.

1.0 / What Austrian entities face under NIS2

Austria enters NIS2 with the sharpest scope jump in the region relative to its starting point: NISG 2018 covered roughly 100 designated operators of essential services, and NISG 2026 brings around 4,000–5,000 entities into scope on 1 October 2026 — with obligations applying in full from day one. The delta is the Austrian mid-market: machinery and component manufacturers, food and chemical producers, logistics operators, regional utilities and healthcare providers, plus the Vienna-headquartered groups whose operations span central and eastern Europe. Most of the newly scoped population has never dealt with a cybersecurity supervisor.

Entities sort into essential and important, with genuinely different supervisory postures: essential entities face proactive, ex ante supervision, while important entities are supervised reactively, on occasion. The calendar is compressed either way — registration with the new Cybersecurity Authority within three months of entry into force, and a proactive self-declaration of implemented risk-management measures within twelve months of the registration obligation arising. Austria transposed late; the schedule it adopted makes up the time.

2.0 / NISG 2026 and what the new Cybersecurity Authority will ask for

The NISG 2026 was promulgated in the Federal Law Gazette (BGBl. I No. 94/2025) on 23 December 2025 — after a first transposition attempt, the NISG 2024, failed to reach the required two-thirds parliamentary majority in July 2024. It enters into force on 1 October 2026; until then the NISG 2018 continues to apply to its small population of designated operators. The act establishes a new supervisory authority, the Bundesamt für Cybersicherheit (Federal Office for Cybersecurity), under the Federal Ministry of the Interior; CERT.at and GovCERT Austria continue as the operational CSIRTs. Incident notification follows the directive ladder — early warning within 24 hours of becoming aware, full notification within 72 hours, a final report within a month, interim reports on request.

What distinguishes the Austrian regime is its explicit proof-of-compliance staircase: register within three months, self-declare implemented risk-management measures within twelve months of the registration obligation arising, and from October 2028 answer evidence requests on statutory clocks — essential entities have two months to evidence their operational and organisational measures, and a current ISO/IEC 27001 certification can carry part of that demonstration. Management accountability is personal: executive bodies bear responsibility for risk management, must complete cybersecurity training themselves, and in severe cases can be temporarily barred from exercising managerial functions.

3.0 / Supplier-risk patterns particular to Austria

Austria’s timing creates a two-way asymmetry. Slovakia’s transposition took effect in January 2025, Czechia’s in November 2025, Germany’s in December 2025 — so Austrian suppliers selling into those markets have been receiving NIS2-shaped evidence requests from regulated buyers well before their own law bites. Meanwhile, Austrian buyers starting structured supplier programmes in October 2026 will find much of the domestic supplier base untouched by supervision: when the regulated population jumps from about 100 entities to around 4,000–5,000, the supplier tier beneath is greener still.

Vienna’s role as a regional headquarters hub adds a structural pattern of its own: Austrian groups in banking, insurance, energy, and retail run subsidiaries across central and eastern Europe, so supplier inventories and intra-group service relationships cross borders in both directions. And the statutory weight NISG 2026 gives ISO/IEC 27001 will make certificates do more of the talking in Austrian evidence collection — useful, but a supplier’s certificate is evidence about the supplier; it is not your documented assessment of the relationship, and that assessment duty stays with the buyer.

4.0 / How Vittnor fits the Austrian market

Vittnor — Supply Chain Assurance for the mid-market — produces the proof shape the Austrian regime is built around: structured, dated, reviewer-attributed records with a decision trace, exportable when the Cybersecurity Authority asks. In a regime where implemented measures must be self-declared within twelve months and evidence requests run on statutory clocks — two months for essential entities’ operational and organisational measures — the working difference is between answering from records you already hold and attempting a reconstruction under deadline. Hosting is Microsoft Azure, EU regions only, with customer evidence never leaving the EU.

For the cross-border chains Austrian buyers actually run, the aim is one supplier file that supports the Austrian buyer’s questions and the supplier’s own German, Czech, or Slovak obligations — cross-buyer routing is planned for later versions. For mid-market entities without a dedicated CISO, the one-off NIS2 Supplier Exposure Assessment maps the supplier-risk landscape before the 1 October 2026 clock starts, and the platform then carries the ongoing programme the NISG 2026 expects — the pilot is open today, ahead of the in-force date.

5.0 / Next step

Where are you with NIS2 supplier work in Austria?

Two ways to find out fast — a five-minute readiness check, or a practitioner-walked exposure picture in two to three weeks.