Lesson 1.1 · 6 min
What the NISG 2026 does, and since when
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- Austria's implementation of NIS2. The NISG 2026 implements the EU Directive 2022/2555, the NIS2 Directive. It was published on 23 December 2025.
- 1 October 2026. The duties have applied since 1 October 2026. At the same time the old NISG of 2018 and its regulation ceased to apply.
- Essential and important entities. It covers businesses in 18 sectors, as a rule from medium size upwards. Each business checks for itself whether that applies.
- Five duties. Register, train the management and hold it responsible, put risk management in place, report significant incidents and prove what has been done.
- The Federal Office for Cyber Security. The new Federal Office for Cyber Security, under the Interior Ministry, is in charge. Incidents go to a computer emergency team, a CSIRT.
In detail
The act
The Network and Information System Security Act 2026 (Netz- und Informationssystemsicherheitsgesetz 2026, NISG 2026) implements Directive (EU) 2022/2555, the NIS2 Directive § 48 no. 1 NISG 2026. It sets out measures to achieve a high level of cyber security, in particular among essential and important entities § 2 NISG 2026. It was published on 23 December 2025 in Federal Law Gazette I No. 94/2025.
Since when it applies
Its provisions entered into force on the first day of the month after nine months from publication, that is on 1 October 2026. At the same time §§ 2 to 31 of the 2018 NISG, the 2019 NIS Regulation and the regulation on qualified bodies ceased to apply § 51(2) NISG 2026.
What is being protected
A "network and information system" is not just the server. It means § 3 no. 1 NISG 2026:
- communication networks;
- any device or group of connected devices that process digital data automatically on the basis of a program, so laptops, tills, machine controls and building systems too;
- the digital data stored, processed, retrieved or transmitted in them, in the cloud as well.
A cyber security incident is an event that compromises the availability, authenticity, integrity or confidentiality of such data or services § 3 no. 30 NISG 2026.
The duties at a glance
| Duty | In short | Lesson |
|---|---|---|
| Register | within three months of 1 October 2026, in the USP § 29 | 2.1, 2.2 |
| Management | ensure and oversee the measures, training § 31 | 3.1, 3.2 |
| Risk management | appropriate and proportionate measures, at least ten elements § 32 | 4.1–4.6 |
| Report | significant incidents within 24 hours, 72 hours and one month §§ 34, 35 | 5.1–5.3 |
| Prove | self-declaration, an audit on request § 33 | 6.1, 6.2 |
Who is in charge
The competent authority is the Federal Office for Cyber Security (Bundesamt für Cybersicherheit), an authority directly under the Minister of the Interior with nationwide competence § 3a NISG 2026. Incidents are reported to a computer emergency team (CSIRT). Since 1 October 2026 there have been the GovCERT for the public administration, the HealthCERT for healthcare and the national CSIRT for everyone else (Federal Office, CSIRTs).
Who checks whether you're covered
You do. The Federal Office states that checking whether an entity is covered, including whether it must register, is up to the entity itself; the authority does not classify businesses (Federal Office, FAQ). Only in special cases does it classify an entity by formal decision § 26 NISG 2026. Lessons 1.2 to 1.4 go through this check step by step.
Checklist
- Someone in the business has been asked to check whether the NISG 2026 covers us.
- We know it also concerns machine controls, tills and data in the cloud.
- We know the five duties and the lessons that explain them.
- We know which CSIRT would be ours.
- We put the result of the check in writing, even if it is "not covered".
Quiz
Who decides whether a business falls under the NISG 2026?
- The competent CSIRT
- The Federal Office for Cyber Security, with a letter to every business
- The business itself
- The Chamber of Commerce
Show the answer
The answer is C: The business itself. The entity checks for itself whether it is covered (Federal Office, FAQ). A formal decision exists only in the special cases of § 26 NISG 2026.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 2, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 3, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 3a, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 48, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 51, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Federal Office for Cyber Security: computer emergency response teams (CSIRTs), in German (read on 6 October 2026)
- Federal Office for Cyber Security, FAQ: scope, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.