Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
Back to the NIS2 overview
NIS2 · Austria

NIS2 in Austria — transposition status and what’s changed

Austria adopted the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) on 23 December 2025. The Act enters into force on 1 October 2026, at which point the NIS 2 regulatory framework becomes operational; the existing NISG 2018 regime continues to apply until then. The supervisory cooperation runs through the Federal Chancellery (BKA) and the Federal Ministry of Interior (BMI), which took over the NIS Office and GovCERT Austria from the BKA in April 2025. Approximately 4,000 Austrian entities are expected to fall within scope when NISG 2026 takes effect.

National competent authority
Austrian NIS Office

Authoritative source for Austria-specific NIS2 guidance, registration, and incident reporting.

1.0 / What Austrian entities face under NIS2

Austria enters NIS2 with the sharpest scope jump in the region relative to its starting point: NISG 2018 covered roughly 100 designated operators of essential services, and NISG 2026 brings around 4,000 entities into scope on 1 October 2026 — with obligations applying in full from day one. The delta is the Austrian mid-market: machinery and component manufacturers, food and chemical producers, logistics operators, regional utilities and healthcare providers, plus the Vienna-headquartered groups whose operations span central and eastern Europe. Most of the newly scoped population has never dealt with a cybersecurity supervisor.

Entities sort into essential and important, with genuinely different supervisory postures: essential entities face proactive, ex ante supervision, while important entities are supervised reactively, on occasion. The calendar is compressed either way — registration with the new Cybersecurity Authority within three months of entry into force, and a proactive self-declaration of implemented risk-management measures within twelve. Austria transposed late; the schedule it adopted makes up the time.

2.0 / NISG 2026 and what the new Cybersecurity Authority will ask for

The NISG 2026 was promulgated in the Federal Law Gazette (BGBl. I No. 94/2025) on 23 December 2025 — after a first transposition attempt, the NISG 2024, failed to reach the required two-thirds parliamentary majority in July 2024. It enters into force on 1 October 2026; until then the NISG 2018 continues to apply to its small population of designated operators. The act establishes a new supervisory authority, the Bundesamt für Cybersicherheit (Federal Office for Cybersecurity), under the Federal Ministry of the Interior; CERT.at and GovCERT Austria continue as the operational CSIRTs. Incident notification follows the directive ladder — early warning within 24 hours of becoming aware, full notification within 72 hours, a final report within a month, interim reports on request.

What distinguishes the Austrian regime is its explicit proof-of-compliance staircase: register within three months, self-declare implemented risk-management measures within twelve, and from October 2028 answer evidence requests on statutory clocks — essential entities have two months to evidence their operational and organisational measures, and a current ISO/IEC 27001 certification can carry part of that demonstration. Management accountability is personal: executive bodies bear responsibility for risk management, must complete cybersecurity training themselves, and in severe cases can be temporarily barred from exercising managerial functions.

3.0 / Supplier-risk patterns particular to Austria

Austria’s timing creates a two-way asymmetry. Slovakia’s transposition took effect in January 2025, Czechia’s in November 2025, Germany’s in December 2025 — so Austrian suppliers selling into those markets have been receiving NIS2-shaped evidence requests from regulated buyers well before their own law bites. Meanwhile, Austrian buyers starting structured supplier programmes in October 2026 will find much of the domestic supplier base untouched by supervision: when the regulated population jumps from about 100 entities to around 4,000, the supplier tier beneath is greener still.

Vienna’s role as a regional headquarters hub adds a structural pattern of its own: Austrian groups in banking, insurance, energy, and retail run subsidiaries across central and eastern Europe, so supplier inventories and intra-group service relationships cross borders in both directions. And the statutory weight NISG 2026 gives ISO/IEC 27001 will make certificates do more of the talking in Austrian evidence collection — useful, but a supplier’s certificate is evidence about the supplier; it is not your documented assessment of the relationship, and that assessment duty stays with the buyer.

4.0 / How Vittnor fits the Austrian market

Vittnor — Supply Chain Assurance for the mid-market — produces the proof shape the Austrian regime is built around: structured, dated, reviewer-attributed records with a decision trace, exportable when the Cybersecurity Authority asks. In a regime where implemented measures must be self-declared within twelve months and evidence requests run on statutory clocks — two months for essential entities’ operational and organisational measures — the working difference is between answering from records you already hold and attempting a reconstruction under deadline. Hosting is Microsoft Azure, EU regions only, with customer evidence never leaving the EU.

For the cross-border chains Austrian buyers actually run, the aim is one supplier file that supports the Austrian buyer’s questions and the supplier’s own German, Czech, or Slovak obligations — cross-buyer routing is planned for later versions. For mid-market entities without a dedicated CISO, the one-off NIS2 Supplier Exposure Assessment maps the supplier-risk landscape before the 1 October 2026 clock starts, and the platform then carries the ongoing programme the NISG 2026 expects — the pilot is open today, ahead of the in-force date.

5.0 / Next step

Where are you with NIS2 supplier work in Austria?

Two ways to find out fast — a five-minute readiness check, or a practitioner-walked exposure picture in two to three weeks.