Skip to main content
NIS2 · AUSTRIA

NIS2 in Austria — the NISG 2026, a new federal cyber office, and a clock that starts 1 October.

Austria's transposition arrived in two steps: the Nationalrat passed the NISG 2026 on 12 December 2025, published in the Federal Law Gazette as BGBl I 94/2025 on 23 December 2025, and it enters into force on 1 October 2026. It brings a new institution with it — a Bundesamt für Cybersicherheit (Federal Office for Cybersecurity) under the Interior Ministry, whose stated posture is “Beraten statt Strafen”: advise rather than punish. Around 4,000 entities are expected in scope.

The distinctive part is the calendar, not the content. With the law adopted but not yet in force, Austrian entities hold something most member states' entities no longer have — a genuine runway. Registration is due within three months of entry into force, landing on 31 December 2026, and the first security-measures self-declaration follows within twelve months.

Who it applies to

Essential and important entities across the NIS2 sectors, with Austria's federal structure raising real questions for provincial (Länder) public-administration bodies — whether a Land-level hospital, transport authority or digital-service provider meets thresholds is assessed case by case, not assumed from the federal baseline. Private-sector entities face the standard regime. Once the law is in force on 1 October 2026: registration by 31 December 2026, first security-measures self-declaration within twelve months.

The clock

Competent authority: Bundesamt für Cybersicherheit under the Interior Ministry (from 1 October 2026). Transposition: NISG 2026 (BGBl I 94/2025).

NIS2 in Austria · timeline
WhenWhat happens
12 Dec 2025Nationalrat passes the NISG 2026 · published 23 Dec as BGBl I 94/2025
1 Oct 2026NISG 2026 enters into force · Bundesamt für Cybersicherheit takes up its role
31 Dec 2026Registration deadline — three months after entry into force
Within 12 monthsFirst self-declaration of security measures

A new authority, an advisory posture

Austria pairs its late transposition with a brand-new institution: the Bundesamt für Cybersicherheit under the Interior Ministry. Its stated enforcement philosophy — “Beraten statt Strafen”, advise rather than punish — signals supervision built around guidance-first engagement, in a country where the federal structure already layers the applicability question (federal vs Land level). The practical read for entities: the obligations are the NIS2 baseline, but the supervisory relationship starts fresh, with an authority that has no KRITIS-style predecessor regime to inherit expectations from. TruSecure holds the federal/Land classification and the NISG 2026 clocks as dated records on the entity, so the 1 October start and the December registration deadline are tracked facts, not things to remember.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Austria transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Austria requirements · how TruSecure answers them
What the law asksWhere it is answered
Determine applicability at federal vs Land levelApplicability engine · provincial-level classification checked, not just federal baseline
Register with the new Bundesamt by 31 December 2026Entity profile · registration facts held as records, clock computed from entry into force
File the security-measures self-declaration within twelve monthsRisk register · assessment generated from live control state
Report incidents: early warning 24 h, report 72 h, final one monthIncident workflow · clocked from awareness, each stage pre-built from the last
Document controls and management-body oversightControl library mapped to the NISG 2026 · continuous evidence collection

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Austria NIS2 readiness file · excerptSample data
Applicability
confirmed · Land-level healthcare provider, essential classification
Registration
scheduled · window opens 1 Oct 2026, due 31 Dec 2026
Self-declaration
drafted from live controls · ready for the 12-month clock
Controls evidenced
89/103 · 14 open, each with an owner and a date
Export
sealed · sha256:3d8f...2b1c

Where teams usually start

With a demo walked through by TruSecure — your federal/Land applicability assessed under the NISG 2026, the controls you already operate mapped against what the new Bundesamt will ask for, and the 1 October clocks computed from the actual in-force date. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Austria by Bundesamt für Cybersicherheit under the Interior Ministry (from 1 October 2026). TruSecure determines applicability against Austria's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Does NIS2 apply to Austrian provincial government bodies?
Austria's federal structure means the NISG's public-administration scope interacts directly with the Länder — TruSecure's applicability engine checks provincial-level classification specifically, not just the federal baseline.