Lesson 1.4 · 6 min
Essential or important, and the cases with no size threshold
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- Annex 1 and large: essential. For most businesses: an entity of Annex 1 that is a large business is essential. Annex 1 and medium-sized, or Annex 2 from medium size, is important.
- Never essential just by size. A machinery maker or food manufacturer with a thousand staff is an important entity, not an essential one.
- Some always are. DNS providers, TLD registries and qualified trust services are always essential; trust services and public communication services are always at least important.
- The same duties. Both register, put the same measures in place, report incidents the same way and file the same self-declaration.
- Supervision, fines, audit deadlines. Essential entities are supervised on an ongoing basis, important ones only when there are indications. Maximum fines and audit deadlines differ.
In detail
Essential entities
These count as essential § 24(1) NISG 2026:
- regardless of size: qualified trust service providers, TLD name registries, DNS service providers, public administration entities at federal level, entities the authority has classified as essential, and critical entities under Directive (EU) 2022/2557;
- providers of public communication networks or publicly available communication services from medium size;
- entities of Annex 1 that are a large business.
Important entities
These count as important, unless already essential § 24(2) NISG 2026:
- entities of Annexes 1 and 2 that are a large or medium-sized business;
- public administration entities at state level;
- regardless of size: providers of public communication networks and services, trust service providers and entities the authority has classified as important.
| medium-sized | large | |
|---|---|---|
| Annex 1 | important | essential |
| Annex 2 | important | important |
| no annex | not covered | not covered |
The table shows the rule for most businesses; the special cases without a size threshold are listed above.
Classification by the authority
The authority classifies a small business of Annex 1 or 2 as essential or important by formal decision if, for instance, it is the only provider in Austria of a service that is indispensable, a disruption could significantly affect public safety or health, or it is of particular regional importance; it can likewise make an important entity essential § 26 NISG 2026.
What makes the difference
| essential | important | |
|---|---|---|
| Registration, measures, reporting, self-declaration | the same §§ 29, 31–34 | the same |
| Supervision | ongoing, ad hoc audits too § 38(1) | when there are indications of breaches § 38(2) |
| Audit of organisational implementation | within two months of a request § 33(2) | within two years |
| Maximum fine | €10m or 2% of worldwide turnover § 45(2) | €7m or 1.4% § 45(3) |
| Ban on management duties | possible § 39(4) | not provided for |
What else counts
- The whole legal person is covered, not just the line of business that brings it into scope (Federal Office, FAQ).
- Location: as a rule the act applies to entities established in Austria; communication providers and certain digital services have their own rules § 28 NISG 2026.
- Sector law: where EU sector law requires equivalent measures and reporting, §§ 32 and 34 don't apply to that extent § 27 NISG 2026; for financial entities DORA takes precedence § 24(7) NISG 2026. According to the Federal Office they must still register (FAQ).
Checklist
- We know whether our type of entity is in Annex 1 or Annex 2.
- We have checked whether one of the cases without a size threshold applies to us.
- We know whether we are essential, important or not covered.
- We have checked whether EU sector law such as DORA takes precedence for us.
- The classification and its reasons are in writing, and the management knows them.
Quiz
A machinery maker (Annex 2) with 400 staff is …
- only covered if the Federal Office classifies it
- not covered, because machinery isn't critical
- an essential entity
- an important entity
Show the answer
The answer is D: an important entity. Entities of Annex 2 are important from medium size (§ 24(2) no. 1 NISG 2026); only an entity in Annex 1 that is large becomes essential by size alone.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 24, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 26, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 27, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 28, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 33, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 38, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 39, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 45, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Federal Office for Cyber Security, FAQ: measures, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.