Skip to content
World Watch/Austria/Cybersecurity

Cybersecurity · Austria

Cybersecurity law in Austria: NIS2 compliance (2026)

Comprehensive lawCountry index 90 · A+

Austria shaded by its cybersecurity status

Cybersecurity in Austria: comprehensive law.

FrameworkNetz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026, BGBl. I Nr. 94/2025) transposing EU NIS2 Directive (2022/2555); currently NISG 2018 (NIS1) remains in force until 1 October 2026; supervised by the newly established Bundesamt für Cybersicherheit (BACS), with CERT.at as national CSIRT

Austria has a comprehensive cybersecurity regime built on EU law. The NISG 2018 (transposing NIS1) is currently in force covering ~1,000 designated operators of essential services, and will be replaced on 1 October 2026 by the NISG 2026, which transposes the NIS2 Directive after Austria's earlier NISG 2024 bill was rejected by the National Council in July 2024 and the country was subject to EU infringement proceedings. Sector-specific rules also apply, most notably the directly applicable EU DORA Regulation for the financial sector (supervised by the FMA since 17 January 2025).

NIS2 & cybersecurity law in Austria

In Austria, baseline cybersecurity obligations come from the EU NIS2 Directive, transposed into national law, which sets risk-management and incident-reporting duties for essential and important entities.

Framework
the NIS2 Directive (EU) 2022/2555, transposed into national law
Approach
cybersecurity risk-management measures plus mandatory incident reporting for in-scope entities
Applies to
medium and large entities in critical sectors: energy, transport, banking, health, water, digital infrastructure, ICT and public administration
Incident reporting
an early warning within 24 hours and a full notification within 72 hours to the national CSIRT
Maximum fine
up to €10 million or 2% of global annual turnover for essential entities
Oversight
the national competent authority and CSIRT designated under NIS2

NIS2 is a directive, so Austria implements it through national law; exact scope and deadlines can vary slightly by transposition.

NIS2 in Austria: FAQ

Does NIS2 apply in Austria?

Yes. As an EU member, Austria has transposed the NIS2 Directive (EU) 2022/2555 into national law, covering essential and important entities in critical sectors.

Who must comply with NIS2 in Austria?

Medium and large organisations in sectors such as energy, transport, banking, health, water, digital infrastructure and public administration.

What are the NIS2 incident-reporting deadlines in Austria?

An early warning within 24 hours of becoming aware and a fuller incident notification within 72 hours to the national CSIRT.

What are the penalties under NIS2 in Austria?

Up to €10 million or 2% of global annual turnover for essential entities, with lower ceilings for important entities.

Key points

NIS2 transposition — NISG 2026

The Netz- und Informationssystemsicherheitsgesetz 2026 was promulgated in the Federal Law Gazette (BGBl. I Nr. 94/2025) on 23 December 2025 and enters into force on 1 October 2026, expanding scope from ~1,000 to an estimated ~4,000 medium and large entities across sectors including energy, transport, health, digital infrastructure, manufacturing, telecoms and gambling.

Delayed transposition and infringement

Austria's original NISG 2024 bill was rejected by the National Council on 3 July 2024, causing Austria to miss the EU NIS2 transposition deadline of 17 October 2024 and prompting European Commission infringement proceedings before the replacement NISG 2026 was adopted in late 2025.

Competent authority and CSIRT

NISG 2026 establishes a new Bundesamt für Cybersicherheit (BACS) as the supervisory authority for entity registration, audits and enforcement, while CERT.at continues to act as the national CSIRT receiving 24h/72h incident reports via the nis.gv.at portal.

Incident reporting duties

Significant incidents must be reported to the NIS Anlaufstelle within 24 hours (early warning), followed by a detailed notification within 72 hours and a final report within one month setting out root cause, mitigation and cross-border impact — mirroring NIS2 Article 23.

Registration and penalties

In-scope entities must self-register with BACS by 31 December 2026. Maximum administrative fines follow NIS2 Article 34: up to EUR 10 million or 2% of global annual turnover for essential entities, and up to EUR 7 million or 1.4% for important entities, with personal liability and temporary management-function bans possible for board members.

Sectoral cybersecurity — DORA for finance

The EU Digital Operational Resilience Act (Regulation 2022/2554) has applied directly since 17 January 2025 to virtually all Austrian financial undertakings, with the Finanzmarktaufsicht (FMA) as competent authority for ICT risk management, incident reporting and oversight of critical ICT third-party providers.

Timeline - major decisions & events

Dec 23, 2025lawofficial
NISG 2026 enacted, transposing the EU NIS2 Directive

Austria's parliament adopted and published the Network and Information System Security Act 2026 (NISG 2026), transposing NIS2 and expanding cybersecurity duties (risk management, incident reporting, registration) to roughly 4,000 essential and important entities across 18 sectors; it enters into force on 1 October 2026 with a new Federal Office for Cybersecurity under the Interior Ministry.

Parlament Österreich
Sep 24, 2025lawofficial
Resilienz kritischer Einrichtungen-Gesetz (RKEG) passed

The National Council adopted the Critical Entities Resilience Act with a two-thirds majority, transposing the EU CER Directive to protect critical infrastructure across eleven sectors against physical threats and mandating a national resilience strategy and risk analysis; published as BGBl. I No. 60/2025.

RIS – Bundesgesetzblatt
May 7, 2025enforcementofficial
European Commission sends Austria a reasoned opinion over NIS2 delay

The Commission issued reasoned opinions to Austria and 18 other Member States for failing to fully transpose the NIS2 Directive by the 17 October 2024 deadline, escalating infringement pressure that pushed Austria toward the NISG 2026.

European Commission
Jul 1, 2024lawofficial
Austrian National Council rejects first NIS2 draft (NISG 2024)

The initial NIS2 implementation bill failed to secure the required parliamentary majority, causing Austria to miss the EU transposition deadline and leaving the older NISG 2018 in force for over a year longer.

European Commission – Shaping Europe's digital future
May 24, 2022incident
BlackCat/ALPHV ransomware cripples the State of Carinthia

A ransomware attack encrypted around 3,000 government computers in Carinthia, disrupting passport issuance, COVID-19 testing and contact tracing; attackers demanded $5 million and leaked stolen personal data after the state refused to pay, a landmark incident for Austrian public-sector cyber resilience.

BleepingComputer
Dec 22, 2021guidanceofficial
Austrian Cybersecurity Strategy 2021 (ÖSCS 2021) adopted

The federal government adopted an updated national cybersecurity strategy, refreshing the 2013 framework and setting the strategic direction for governance, critical-infrastructure protection, incident response and public-private cooperation.

Federal Chancellery of Austria
Dec 28, 2018lawofficial
Network and Information System Security Act (NISG 2018) enters into force

Austria's first dedicated cybersecurity law transposed the EU NIS Directive (2016/1148), imposing security and incident-reporting obligations on operators of essential services, digital service providers and public administration, the foundation of the current framework, covering about 100 entities.

Anlaufstelle NISG (nis.gv.at)
May 25, 2018lawofficial
Austrian Data Protection Act (DSG) takes effect alongside the GDPR

The amended Datenschutzgesetz entered into force with the GDPR, establishing the Datenschutzbehörde and national rules that underpin data-security and breach-notification obligations relevant to cybersecurity.

Austrian Data Protection Authority
Mar 1, 2013guidanceofficial
First Austrian Cybersecurity Strategy (ÖSCS 2013)

Austria adopted its inaugural national cybersecurity strategy, a comprehensive concept led by the Federal Chancellery covering cybercrime, critical information infrastructure protection, incident response and public-private partnership, the strategic origin point of Austria's cyber framework.

Federal Chancellery of Austria

Austria - other topics

Cybersecurity in other countries

Last verified 7/28/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →