Cybersecurity · Austria
Cybersecurity law in Austria: NIS2 compliance (2026)
Austria shaded by its cybersecurity status
Cybersecurity in Austria: comprehensive law.
FrameworkNetz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026, BGBl. I Nr. 94/2025) transposing EU NIS2 Directive (2022/2555); currently NISG 2018 (NIS1) remains in force until 1 October 2026; supervised by the newly established Bundesamt für Cybersicherheit (BACS), with CERT.at as national CSIRT
Austria has a comprehensive cybersecurity regime built on EU law. The NISG 2018 (transposing NIS1) is currently in force covering ~1,000 designated operators of essential services, and will be replaced on 1 October 2026 by the NISG 2026, which transposes the NIS2 Directive after Austria's earlier NISG 2024 bill was rejected by the National Council in July 2024 and the country was subject to EU infringement proceedings. Sector-specific rules also apply, most notably the directly applicable EU DORA Regulation for the financial sector (supervised by the FMA since 17 January 2025).
NIS2 & cybersecurity law in Austria
In Austria, baseline cybersecurity obligations come from the EU NIS2 Directive, transposed into national law, which sets risk-management and incident-reporting duties for essential and important entities.
- Framework
- the NIS2 Directive (EU) 2022/2555, transposed into national law
- Approach
- cybersecurity risk-management measures plus mandatory incident reporting for in-scope entities
- Applies to
- medium and large entities in critical sectors: energy, transport, banking, health, water, digital infrastructure, ICT and public administration
- Incident reporting
- an early warning within 24 hours and a full notification within 72 hours to the national CSIRT
- Maximum fine
- up to €10 million or 2% of global annual turnover for essential entities
- Oversight
- the national competent authority and CSIRT designated under NIS2
NIS2 is a directive, so Austria implements it through national law; exact scope and deadlines can vary slightly by transposition.
NIS2 in Austria: FAQ
Yes. As an EU member, Austria has transposed the NIS2 Directive (EU) 2022/2555 into national law, covering essential and important entities in critical sectors.
Medium and large organisations in sectors such as energy, transport, banking, health, water, digital infrastructure and public administration.
An early warning within 24 hours of becoming aware and a fuller incident notification within 72 hours to the national CSIRT.
Up to €10 million or 2% of global annual turnover for essential entities, with lower ceilings for important entities.
Key points
The Netz- und Informationssystemsicherheitsgesetz 2026 was promulgated in the Federal Law Gazette (BGBl. I Nr. 94/2025) on 23 December 2025 and enters into force on 1 October 2026, expanding scope from ~1,000 to an estimated ~4,000 medium and large entities across sectors including energy, transport, health, digital infrastructure, manufacturing, telecoms and gambling.
Austria's original NISG 2024 bill was rejected by the National Council on 3 July 2024, causing Austria to miss the EU NIS2 transposition deadline of 17 October 2024 and prompting European Commission infringement proceedings before the replacement NISG 2026 was adopted in late 2025.
NISG 2026 establishes a new Bundesamt für Cybersicherheit (BACS) as the supervisory authority for entity registration, audits and enforcement, while CERT.at continues to act as the national CSIRT receiving 24h/72h incident reports via the nis.gv.at portal.
Significant incidents must be reported to the NIS Anlaufstelle within 24 hours (early warning), followed by a detailed notification within 72 hours and a final report within one month setting out root cause, mitigation and cross-border impact — mirroring NIS2 Article 23.
In-scope entities must self-register with BACS by 31 December 2026. Maximum administrative fines follow NIS2 Article 34: up to EUR 10 million or 2% of global annual turnover for essential entities, and up to EUR 7 million or 1.4% for important entities, with personal liability and temporary management-function bans possible for board members.
The EU Digital Operational Resilience Act (Regulation 2022/2554) has applied directly since 17 January 2025 to virtually all Austrian financial undertakings, with the Finanzmarktaufsicht (FMA) as competent authority for ICT risk management, incident reporting and oversight of critical ICT third-party providers.
Timeline - major decisions & events
Austria's parliament adopted and published the Network and Information System Security Act 2026 (NISG 2026), transposing NIS2 and expanding cybersecurity duties (risk management, incident reporting, registration) to roughly 4,000 essential and important entities across 18 sectors; it enters into force on 1 October 2026 with a new Federal Office for Cybersecurity under the Interior Ministry.
Parlament Österreich ↗The National Council adopted the Critical Entities Resilience Act with a two-thirds majority, transposing the EU CER Directive to protect critical infrastructure across eleven sectors against physical threats and mandating a national resilience strategy and risk analysis; published as BGBl. I No. 60/2025.
RIS – Bundesgesetzblatt ↗The Commission issued reasoned opinions to Austria and 18 other Member States for failing to fully transpose the NIS2 Directive by the 17 October 2024 deadline, escalating infringement pressure that pushed Austria toward the NISG 2026.
European Commission ↗The initial NIS2 implementation bill failed to secure the required parliamentary majority, causing Austria to miss the EU transposition deadline and leaving the older NISG 2018 in force for over a year longer.
European Commission – Shaping Europe's digital future ↗A ransomware attack encrypted around 3,000 government computers in Carinthia, disrupting passport issuance, COVID-19 testing and contact tracing; attackers demanded $5 million and leaked stolen personal data after the state refused to pay, a landmark incident for Austrian public-sector cyber resilience.
BleepingComputer ↗The federal government adopted an updated national cybersecurity strategy, refreshing the 2013 framework and setting the strategic direction for governance, critical-infrastructure protection, incident response and public-private cooperation.
Federal Chancellery of Austria ↗Austria's first dedicated cybersecurity law transposed the EU NIS Directive (2016/1148), imposing security and incident-reporting obligations on operators of essential services, digital service providers and public administration, the foundation of the current framework, covering about 100 entities.
Anlaufstelle NISG (nis.gv.at) ↗The amended Datenschutzgesetz entered into force with the GDPR, establishing the Datenschutzbehörde and national rules that underpin data-security and breach-notification obligations relevant to cybersecurity.
Austrian Data Protection Authority ↗Austria adopted its inaugural national cybersecurity strategy, a comprehensive concept led by the Federal Chancellery covering cybercrime, critical information infrastructure protection, incident response and public-private partnership, the strategic origin point of Austria's cyber framework.
Federal Chancellery of Austria ↗Austria - other topics
Cybersecurity in other countries
Last verified 7/28/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →