NISG 2026: Cybersecurity becomes mandatory

From 1 October 2026, new rules on cyber security will come into force in Austria. The NISG 2026 implements the European NIS2 Directive – and this means the issue will move straight onto the agenda for significantly more businesses.

It is not just traditional areas of critical infrastructure that are affected. Companies from other relevant sectors, as well as their suppliers and service providers, may also face greater accountability in future. For many organisations, this means assessing their situation, categorising their risks and implementing the appropriate technical and organisational measures in good time.

Mehr Unternehmen betroffen

NIS2 no longer applies solely to traditional critical infrastructure. Its scope is being extended to cover numerous other sectors.

Size and sector are key factors

In many cases, companies with 50 or more employees, or those meeting certain turnover and balance sheet thresholds, are affected.

Cyber security is becoming a requirement

From risk analyses and backups to multi-factor authentication, the law requires specific security measures.

Incidents must be reported promptly

In the future, binding reporting deadlines will apply to significant security incidents – the initial report may need to be submitted within 24 hours.

Management taking responsibility

Cyber security is becoming a management responsibility. Senior management must oversee the measures and undergo appropriate training.

Am I affected by NIS2?

Whether a company falls within the scope of the NISG 2026 depends primarily on its sector and size. Among others, companies in the energy, transport, healthcare, digital infrastructure, ICT services, postal services, waste management, food, chemical, manufacturing, digital services and research sectors are affected. In many cases, the regulation applies to organisations with 50 or more employees, or those exceeding certain turnover and balance sheet thresholds. Special provisions apply, for example, to certain digital and electronic services, which may be affected regardless of their size. Even companies not directly covered by NIS2 should look into this issue: as a supplier or service provider to an affected company, new security requirements may also apply to them.

What must affected organisations do now?

From 1 October 2026, specific requirements for cybersecurity risk management will apply. These include, amongst other things:

  • Risk analyses and security strategies
  • Incident management and reporting processes
  • Backups and recovery
  • Access controls and multi-factor authentication
  • Supply chain security
  • Training for staff and management

In the event of significant security incidents, an initial report must generally be submitted within 24 hours, followed by a further report within 72 hours. Affected organisations must also register by 31 December 2026. A self-declaration regarding the risk management measures implemented must be submitted by 30 September 2027.

Source: Austrian Chamber of Commerce NISG

Das NISG 2026 tritt am 1. Oktober 2026 vollständig in Kraft. Ab diesem Zeitpunkt müssen betroffene Unternehmen die gesetzlichen Anforderungen erfüllen.

Nein. Die geforderten Maßnahmen müssen ab Inkrafttreten umgesetzt sein. Dazu gehören unter anderem Risikomanagementmaßnahmen sowie entsprechende Schulungen für Leitungsorgane und Mitarbeitende.

Ja. Unternehmen müssen ihre Betroffenheit selbst beurteilen und gegebenenfalls die erforderliche Registrierung als wesentliche oder wichtige Einrichtung vornehmen. Eine automatische Einstufung durch die Cybersicherheitsbehörde ist nicht vorgesehen.

Erfasst werden wesentliche und wichtige Einrichtungen aus den gesetzlich definierten Sektoren. Dazu kommen besondere Regelungen für bestimmte digitale Dienste, Kommunikationsanbieter und weitere Einrichtungen mit entsprechendem Bezug zu Österreich.

Der erste Schritt ist eine strukturierte Prüfung der eigenen Betroffenheit. Danach sollten bestehende Sicherheitsmaßnahmen, Verantwortlichkeiten, Prozesse und Schulungen mit den Anforderungen des NISG 2026 abgeglichen und notwendige Maßnahmen rechtzeitig umgesetzt werden.

Für eine erste Einschätzung bietet die WKO einen Online-Ratgeber zu NIS2 an. Dieser unterstützt unter anderem bei der Einordnung des Sektors und der Unternehmensgröße.

New cybersecurity obligations: NISG 2026

From 1 October 2026, NIS2 will become mandatory in Austria, bringing cyber security into sharp focus for a significantly larger number of businesses. This concise and practical overview sets out which organisations are actually affected, what obligations now apply, and why suppliers and service providers should not underestimate the importance of this issue.