NIS2 · National implementation
NIS2 in Austria
Austria adopted the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026); it enters into force on 1 October 2026 — the last confirmed commencement in the EU, after a first attempt (NISG 2024) failed in parliament.
- National law
- Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026)
- Network and Information System Security Act 2026
- Status
- Adopted, not yet in force
- In force
- 1 October 2026
- Authority
- Bundesministerium für Inneres (BMI)
Supervision
The Bundesministerium für Inneres (BMI) is the cybersecurity authority, with the national CERT structures (CERT.at, GovCERT) as CSIRTs. Registration duties run from commencement.
What is specific to Austria
The two-year delay means Austrian entities have had the longest runway in the EU — and the least excuse. The NISG 2026 tracks the directive closely; the practical Austrian work is scope confirmation and registration readiness before 1 October, plus watching BMI's implementing regulations for the evidence and audit cycle.
Official sources
Primary references: the national statute book at www.ris.bka.gv.at and the national cybersecurity authority at www.bmi.gv.at.
NIS2 in Austria: frequently asked questions
Last reviewed:
Related reading
Definitions
