What you'll learn
- Whether your business is covered: sector, size, linked businesses, essential or important
- How and by when to register in the USP, and what to keep current afterwards
- What the management itself owes, and who is liable for what
- What § 32 with the NISV 2026 and the EU catalogue actually requires, and what "proportionate" means with 60 staff
- When an incident is significant, and how the early warning, notification and final report work
- The self-declaration, audits, supervision, fines and every deadline at a glance
How is your business getting on with the NISG 2026?
Do you know yet whether it covers you? Who is looking after it, what will it cost, and what is least clear? Eight short questions, about ten minutes. We're not selling anything. If you like, we'll send you the results, summarised and anonymised.
Course content
Section 1: Am I covered?
Section 2: Registration
Section 3: The management
Section 4: Risk management under § 32
Section 5: Reporting incidents
Section 6: Proof and supervision
Requirements
- No prior knowledge of law or IT.
- Meant for managing directors, people responsible for IT, compliance or quality, and anyone asked to work out what the NISG 2026 means for their business.
Description
Since 1 October 2026 Austria's Network and Information System Security Act 2026 has applied, the country's implementation of the EU's NIS2 Directive. It covers businesses of medium size and up in 18 sectors, from energy through mechanical engineering and the food industry to IT service providers. A business that is covered must register by the end of 2026, put risk management measures in place, report significant incidents within 24 hours and file a self-declaration by 30 September 2027.
This course explains the duties in short lessons, with the paragraph for every statement and the guidance of the Federal Office for Cyber Security. Every lesson has narrated slides, a checklist to tick off and a quiz question. It starts with whether you are covered and ends with every deadline at a glance.
Who this course is for
- Managing directors and boards of medium-sized businesses who need to know whether they are covered
- Heads of IT, information security, compliance and quality management
- IT service providers and managed service providers, who may be covered themselves
- Suppliers whose customers are now asking for proof
About this course
Written in Vienna as a free learning resource. The course follows the wording of the NISG 2026 and the NISV 2026 in RIS, of Implementing Regulation (EU) 2024/2690 and of the Federal Office for Cyber Security's pages linked in every lesson, but hasn't been reviewed by an expert yet. Pointers to mistakes are very welcome: info@globalapps.top.
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.