NIS2 · National implementation

NIS2 in Austria

Austria adopted the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026); it enters into force on 1 October 2026 — the last confirmed commencement in the EU, after a first attempt (NISG 2024) failed in parliament.

National law
Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026)
Network and Information System Security Act 2026
Status
Adopted, not yet in force
In force
1 October 2026
Authority
Bundesministerium für Inneres (BMI)

Supervision

The Bundesministerium für Inneres (BMI) is the cybersecurity authority, with the national CERT structures (CERT.at, GovCERT) as CSIRTs. Registration duties run from commencement.

What is specific to Austria

The two-year delay means Austrian entities have had the longest runway in the EU — and the least excuse. The NISG 2026 tracks the directive closely; the practical Austrian work is scope confirmation and registration readiness before 1 October, plus watching BMI's implementing regulations for the evidence and audit cycle.

Official sources

Primary references: the national statute book at www.ris.bka.gv.at and the national cybersecurity authority at www.bmi.gv.at.

NIS2 in Austria: frequently asked questions

Last reviewed:

Related reading

Definitions

All 27 EU member states