Austria’s NISG 2026 imposes cybersecurity rules on 4,000 organisations
- Beginning October 1, 2026, roughly 4,000 medium-sized and larger organizations across 18 regulated sectors in Austria face mandatory cybersecurity requirements and incident reporting obligations under the Netz- und...
- The legislative text was published in the Bundesgesetzblatt on December 23, 2025, setting a nine-month transition window before taking effect on October 1, 2026.
- Regulated entities must implement comprehensive risk management measures, including strict controls over supply chain security.
Beginning October 1, 2026, roughly 4,000 medium-sized and larger organizations across 18 regulated sectors in Austria face mandatory cybersecurity requirements and incident reporting obligations under the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), according to data published by the Wirtschaftskammer Österreich (wko.at). The legislation implements the European Union’s NIS-2 Directive, replacing the older NISG 2018 framework and expanding oversight from roughly 100 critical infrastructure operators to a broad swath of the domestic economy.
Scope and Timeline of the NISG 2026 Rollout
The legislative text was published in the Bundesgesetzblatt on December 23, 2025, setting a nine-month transition window before taking effect on October 1, 2026. Unlike the 2018 rules that targeted only essential services, the new statutory framework applies to entire organizations operating within designated sectors. Essential and important entities must complete their formal registration by December 31, 2026. Further compliance benchmarks follow a structured statutory timeline: organizations must finish self-declarations by October 1, 2027, while the national cybersecurity authority gains the power to request compliance audits starting October 1, 2028.
Mandatory Risk Management and Supply Chain Security
Regulated entities must implement comprehensive risk management measures, including strict controls over supply chain security. Under the rules outlined by wko.at, affected organizations are required to bind their service providers and suppliers to specific risk management obligations through contracts. Companies must report significant cybersecurity incidents to authorities once the law becomes active. Organizations designated as essential face the earliest possible deadline of November 30, 2028, to demonstrate the operational and organizational execution of their risk measures upon official request, while independent audits for essential and important entities are scheduled to phase in by September 30, 2030.

