


NISG 2026: Cybersecurity becomes mandatory
From 1 October 2026, new rules on cyber security will come into force in Austria. The NISG 2026 implements the European NIS2 Directive – and this means the issue will move straight onto the agenda for significantly more businesses.
It is not just traditional areas of critical infrastructure that are affected. Companies from other relevant sectors, as well as their suppliers and service providers, may also face greater accountability in future. For many organisations, this means assessing their situation, categorising their risks and implementing the appropriate technical and organisational measures in good time.
Am I affected by NIS2?
Whether a company falls within the scope of the NISG 2026 depends primarily on its sector and size. Among others, companies in the energy, transport, healthcare, digital infrastructure, ICT services, postal services, waste management, food, chemical, manufacturing, digital services and research sectors are affected. In many cases, the regulation applies to organisations with 50 or more employees, or those exceeding certain turnover and balance sheet thresholds. Special provisions apply, for example, to certain digital and electronic services, which may be affected regardless of their size. Even companies not directly covered by NIS2 should look into this issue: as a supplier or service provider to an affected company, new security requirements may also apply to them.
What must affected organisations do now?
From 1 October 2026, specific requirements for cybersecurity risk management will apply. These include, amongst other things:
- Risk analyses and security strategies
- Incident management and reporting processes
- Backups and recovery
- Access controls and multi-factor authentication
- Supply chain security
- Training for staff and management
In the event of significant security incidents, an initial report must generally be submitted within 24 hours, followed by a further report within 72 hours. Affected organisations must also register by 31 December 2026. A self-declaration regarding the risk management measures implemented must be submitted by 30 September 2027.
Das NISG 2026 tritt am 1. Oktober 2026 vollständig in Kraft. Ab diesem Zeitpunkt müssen betroffene Unternehmen die gesetzlichen Anforderungen erfüllen.
Nein. Die geforderten Maßnahmen müssen ab Inkrafttreten umgesetzt sein. Dazu gehören unter anderem Risikomanagementmaßnahmen sowie entsprechende Schulungen für Leitungsorgane und Mitarbeitende.
Ja. Unternehmen müssen ihre Betroffenheit selbst beurteilen und gegebenenfalls die erforderliche Registrierung als wesentliche oder wichtige Einrichtung vornehmen. Eine automatische Einstufung durch die Cybersicherheitsbehörde ist nicht vorgesehen.
Erfasst werden wesentliche und wichtige Einrichtungen aus den gesetzlich definierten Sektoren. Dazu kommen besondere Regelungen für bestimmte digitale Dienste, Kommunikationsanbieter und weitere Einrichtungen mit entsprechendem Bezug zu Österreich.
Der erste Schritt ist eine strukturierte Prüfung der eigenen Betroffenheit. Danach sollten bestehende Sicherheitsmaßnahmen, Verantwortlichkeiten, Prozesse und Schulungen mit den Anforderungen des NISG 2026 abgeglichen und notwendige Maßnahmen rechtzeitig umgesetzt werden.
Für eine erste Einschätzung bietet die WKO einen Online-Ratgeber zu NIS2 an. Dieser unterstützt unter anderem bei der Einordnung des Sektors und der Unternehmensgröße.











