NIS2 — Austrian NISG 2026
Austria’s NIS2 law is in force since 1 October 2026: thousands of medium and large companies must register by 31 December 2026 — and pass security requirements on to their suppliers.
- Reference
- Directive (EU) 2022/2555 · Austria: NISG 2026 (BGBl. I Nr. 94/2025)
- Status
- Applies
- Sources last checked
What it is
The NIS2 Directive raises cybersecurity duties for essential and important entities in 18 sectors. Austria implemented it with the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), published on 23 December 2025 and in force since 1 October 2026. Management bodies are responsible for approving and overseeing the risk-management measures, including supply-chain security.
Who is affected
Medium and large organisations (from 50 employees or more than €10 million turnover and balance sheet) in the sectors listed — including energy, transport, health, water, digital infrastructure and manufacturing of electronics, electrical equipment and machinery. Certain entities (e.g. DNS, trust service and public electronic communications providers) are covered regardless of size. Smaller suppliers are affected indirectly through contracts.
What you have to do
- Check whether your organisation is an essential or important entity (size + sector); register by 31 December 2026 at the latest.
- Implement risk-management measures: incident handling, business continuity, access control, encryption, supply-chain security.
- Report significant incidents in stages (early warning within 24 h, notification within 72 h, final report).
- Management bodies must approve the measures, oversee their implementation and take part in training.
- Suppliers: expect security questionnaires, update commitments and evidence (SBOM, support periods) in contracts.
Fact check
Partly correct “We have fewer than 50 employees, so NIS2 doesn’t concern us.”
You may not be directly regulated, but your NIS2 customers must secure their supply chain — they will pass requirements on to you contractually.
Not correct “Manufacturing companies are not in scope — NIS2 is for critical infrastructure.”
Manufacturing of computers, electronic and optical products, electrical equipment, machinery and vehicles is a listed sector (important entities).
Sources
- NISG 2026 — BGBl. I Nr. 94/2025 (opens external website) ↗
- Directive (EU) 2022/2555 (NIS2) — Official Journal text (opens external website) ↗
- NISG 2026 — overview for companies (opens external website) ↗
General information, not legal advice. Authentic are only the texts published in the Official Journal of the EU and the Austrian Federal Law Gazette.
Not sure where your product stands?
Send us the product and its documents. We check the technical file against the rules on this radar and tell you what is missing — and source an EU-ready alternative if needed.