← News

NIS2 in Austria: Deadlines and Duties Under the NISG 2026

Promotional image “Ihre Daten. Ihr Restore. Rund um die Uhr.” – a cloud with a shield above the outline of Austria, with the three private cloud products below

NIS2 in Austria: three questions about the NISG 2026

Am I in scope, what has to be done by when, and where do I start? Managing directors and IT managers have been asking these three questions since Austria published its NIS2 law, the NISG 2026. This guide answers them with section numbers and dates.

What the NISG 2026 is

The Network and Information System Security Act 2026 (Netz- und Informationssystemsicherheitsgesetz 2026) was published on 23 December 2025 as Federal Law Gazette BGBl. I No. 94/2025 (full text, in German, at ris.bka.gv.at) and transposes Directive (EU) 2022/2555, the NIS2 Directive. Under § 51(1) and (2) it enters into force nine months after publication, on the first day of the following month: 1 October 2026. Since the day after publication, the federal government has been required to take “all preparatory measures” the Cybersecurity Authority needs in order to do its work (§ 51(4)) – a duty on the state, not on your company. The act is administered by the Federal Minister of the Interior (§ 50 item 5); the Cybersecurity Authority (Cybersicherheitsbehörde) publishes its guidance at nis.gv.at. This article is not legal advice.

Who is in scope – and does NIS2 apply to SMEs?

The act distinguishes two groups (§ 24): essential entities are those in Annex 1 that operate a large enterprise; important entities are those in Annexes 1 and 2 that operate a large or medium-sized enterprise. Regardless of size, DNS providers, top-level domain registries and the federal administration count as essential, telecommunications providers and the Länder administrations as important.

Size is defined in § 25. A large enterprise has at least 250 employees, or an annual turnover above €50 million and an annual balance sheet total above €43 million (§ 25(2)). A medium-sized enterprise has at least 50 employees, or an annual turnover above €10 million and an annual balance sheet total above €10 million (§ 25(3)). Figures follow Recommendation 2003/361/EC; partner and linked enterprises count towards the thresholds in principle – but not where your company is organisationally, technically and operationally independent of them in respect of the network and information systems it uses to deliver its services (§ 25(4)). For SMEs the wording means: a company with fewer than 50 employees is not exempt if turnover and balance sheet total both exceed €10 million and its sector is listed.

The 18 sectors are split across two annexes:

  • Annex 1, sectors of high criticality (eleven): energy; transport; banking; financial market infrastructure; health; drinking water; waste water; digital infrastructure; ICT service management (managed service providers and managed security service providers); public administration; space.
  • Annex 2, other critical sectors (seven): postal and courier services; waste management; manufacture, production and distribution of chemicals; production, processing and distribution of food; manufacturing (including medical devices, electronics, machinery, vehicles); digital providers (online marketplaces, search engines, social networks); research.

NIS2 deadlines in Austria

The act sets four dates:

  • 1 October 2026 – entry into force. From this day, §§ 2 to 45 and the annexes apply (§ 51(1) and (2)).
  • 31 December 2026 – registration. Registration with the Cybersecurity Authority is due within three months of entry into force (§ 29(3)). It covers, among other things, sector, address, IP address ranges, thresholds and classification (§ 29(2)). A company that comes into scope later has three months from then.
  • 30 September 2027 – self-declaration. Within twelve months of the registration duty arising, you submit structured information to the authority on the § 32 measures you have implemented (§ 33(1)).
  • Proof by an independent body – on request. If the authority requests it, you demonstrate implementation within two years through an independent body; for the operational and organisational part, relevant valid certificates are accepted as proof. Essential entities have only two months from the request for that same part. The first request may be issued no earlier than two years after entry into force, so from October 2028 (§ 33(2)).

NIS2 checklist: the ten measure areas of § 32

§ 32(4) lists the minimum content of the risk management measures – here in plain language, each with the question to ask inside your company:

  1. Risk analysis and information system security policies: Do we know which systems the business depends on, and is it written down how we protect them?
  2. Incident handling: Who does what in an attack – and is the plan available when the network is down?
  3. Business continuity: The act explicitly names backup management, disaster recovery and crisis management. When did we last run a recovery, and where is the record?
  4. Supply chain security: Do we know the security measures of our direct suppliers and service providers, and are they in the contract?
  5. Acquisition, development and maintenance: How do we learn about vulnerabilities in our software, and how quickly do we close them?
  6. Assessing effectiveness: Do we regularly check whether the measures work – or only whether they were approved?
  7. Cyber hygiene and training: Does everyone in the company know the basic rules, and when was the last training session?
  8. Cryptography and encryption: Is it defined which data is encrypted – at rest, in transit, in the backup?
  9. Personnel security, access control and asset management: Who has access to what, who revokes it when someone leaves, and is there an inventory of devices?
  10. Multi-factor authentication and secured communication: Is a password alone still enough for us, and how do we reach each other when e-mail and the phone system are down?

The measures must take the state of the art and the cost of implementation into account (§ 32(2)) and be proportionate to risk exposure, size, likelihood and severity (§ 32(3)). Your effort follows your risk, but you must be able to answer all ten points. The authority may specify details by regulation (§ 32(5)).

Reporting duty: 24 hours, 72 hours, one month

Every significant cybersecurity incident (§ 35) must be reported under § 34 to the competent sector-specific CSIRT, otherwise to the national CSIRT, in three stages: an early warning within 24 hours of becoming aware of it, a notification with an initial assessment within 72 hours, and a final report no later than one month after that notification. If the incident is still ongoing, a progress report takes its place and the final report follows one month after the incident has been dealt with. Affected recipients of your services must be informed without undue delay (§ 34(3)).

These deadlines are a matter of organisation: who decides at three in the morning that an incident is significant, who writes the report, where do the facts come from while your own systems are down? Assign these roles in advance, deputies included.

Supply chain: what suppliers should expect

§ 32(4)(d) obliges entities in scope to address the security of their relationships with their direct suppliers and service providers, including the security of those providers’ development processes. The duty is placed on the customer, not on the supplier. The consequence – an inference, not a provision of the act – is that a company below every threshold will still get the questions as soon as one of its customers is in scope: how do you back up our data, where is it stored, who has access, how quickly would you report an incident? A supplier with those answers in writing negotiates from a better position.

What is at stake in case of breaches

§ 45 provides for fines of up to €10 million or up to 2 % of total worldwide annual turnover for essential entities, and up to €7 million or up to 1.4 % for important entities, whichever amount is higher.

Where to start: backup and recovery need lead time

One of the ten points cannot be caught up in a few weeks: business continuity. Policies can be written, training scheduled, multi-factor authentication rolled out. A recovery test, however, needs an existing backup, an environment to start it in, and a record that proves it took place. In the self-declaration what counts is what has been implemented: a documented test, not a planned one.

For a backup to serve as evidence, it has to do four things:

  • Encrypted: the data is encrypted before it leaves your premises, and the key stays with you (which also covers the cryptography point).
  • Verified: every backup is checked for integrity after it is written, on a schedule.
  • Restore-tested: a machine is actually started from the backup at fixed intervals, not just once a year.
  • Documented: backup, verification and restore logs exist and can be presented.

Add a copy off site, otherwise a fire or a ransomware attack takes the backup down with everything else.

Our offer for this part: with the Managed Proxmox Backup Server you back up your on-premises Proxmox VE environment to a backup server we operate in Austria, from €25 per TB per month. The data is encrypted on your side with your own key, verify jobs check every backup automatically, and in an emergency any VM backup starts as a cloud VM with us at a click – emergency operation until your own hardware is running again. All data stays exclusively in Austria. Proxmox Backup Server is software by Proxmox Server Solutions GmbH, Vienna; we run it for you and are not a sales or certification partner of the vendor. We provide the backup and recovery building block and support you in implementing it; classifying your company and the other nine points remain your task. More on our NIS2 page; to set up a recovery test with one of your machines, get in touch.

← See all news