Austria

← All Member States
Transposed, entry pending
NIS2 status
Transposed, entry pending
National law
Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), BGBl. I Nr. 94/2025
Competent authority
Bundesministerium für Inneres (BMI)
CSIRT
CERT.at / GovCERT Austria
Last verified
2026-07-16

Austria

🟡 NIS2 transposed; entry into force still pending.

NIS2 transposition

  • National law: Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), BGBl. I Nr. 94/2025
  • Status / entry into force: Entry into force 2026-10-01 (nine-month vacatio legis); published 2025-12-23

Competent authority & CSIRT

  • Competent authority: Bundesministerium für Inneres (BMI)
  • CSIRT / incident response: CERT.at / GovCERT Austria
  • Registration: Per NISG 2026 (post entry into force)

Incident reporting

Follows the NIS2 cascade: early warning within 24h, notification within 72h, final report within one month, submitted to the national CSIRT / competent authority. Assume national-language submission unless the authority states otherwise.

Penalties & board liability

  • Essential entities: up to €10M or 2% of worldwide turnover (directive minimum, adopted here).
  • Important entities: up to €7M or 1.4% of worldwide turnover.
  • Management-body accountability applies per NIS2 Art. 20; national enforcement mechanisms vary.

CER Directive

Critical-entities resilience is transposed in parallel (often via the same or a connected authority). Member States had to identify critical entities by 2026-07-17. ⚠️ VERIFY national CER instrument.

Notes

An earlier ‘NISG 2024’ bill was rejected by the National Council on 2024-07-03; a new coalition introduced the second-attempt bill, hence the delay.

Sources