NIS2 in Austria — the NISG 2026, a new federal cyber office, and a clock that starts 1 October.
Austria's transposition arrived in two steps: the Nationalrat passed the NISG 2026 on 12 December 2025, published in the Federal Law Gazette as BGBl I 94/2025 on 23 December 2025, and it enters into force on 1 October 2026. It brings a new institution with it — a Bundesamt für Cybersicherheit (Federal Office for Cybersecurity) under the Interior Ministry, whose stated posture is “Beraten statt Strafen”: advise rather than punish. Around 4,000 entities are expected in scope.
The distinctive part is the calendar, not the content. With the law adopted but not yet in force, Austrian entities hold something most member states' entities no longer have — a genuine runway. Registration is due within three months of entry into force, landing on 31 December 2026, and the first security-measures self-declaration follows within twelve months.
Who it applies to
Essential and important entities across the NIS2 sectors, with Austria's federal structure raising real questions for provincial (Länder) public-administration bodies — whether a Land-level hospital, transport authority or digital-service provider meets thresholds is assessed case by case, not assumed from the federal baseline. Private-sector entities face the standard regime. Once the law is in force on 1 October 2026: registration by 31 December 2026, first security-measures self-declaration within twelve months.
The clock
Competent authority: Bundesamt für Cybersicherheit under the Interior Ministry (from 1 October 2026). Transposition: NISG 2026 (BGBl I 94/2025).
| When | What happens |
|---|---|
| 12 Dec 2025 | Nationalrat passes the NISG 2026 · published 23 Dec as BGBl I 94/2025 |
| 1 Oct 2026 | NISG 2026 enters into force · Bundesamt für Cybersicherheit takes up its role |
| 31 Dec 2026 | Registration deadline — three months after entry into force |
| Within 12 months | First self-declaration of security measures |
A new authority, an advisory posture
Austria pairs its late transposition with a brand-new institution: the Bundesamt für Cybersicherheit under the Interior Ministry. Its stated enforcement philosophy — “Beraten statt Strafen”, advise rather than punish — signals supervision built around guidance-first engagement, in a country where the federal structure already layers the applicability question (federal vs Land level). The practical read for entities: the obligations are the NIS2 baseline, but the supervisory relationship starts fresh, with an authority that has no KRITIS-style predecessor regime to inherit expectations from. TruSecure holds the federal/Land classification and the NISG 2026 clocks as dated records on the entity, so the 1 October start and the December registration deadline are tracked facts, not things to remember.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Austria transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Determine applicability at federal vs Land level | Applicability engine · provincial-level classification checked, not just federal baseline |
| Register with the new Bundesamt by 31 December 2026 | Entity profile · registration facts held as records, clock computed from entry into force |
| File the security-measures self-declaration within twelve months | Risk register · assessment generated from live control state |
| Report incidents: early warning 24 h, report 72 h, final one month | Incident workflow · clocked from awareness, each stage pre-built from the last |
| Document controls and management-body oversight | Control library mapped to the NISG 2026 · continuous evidence collection |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Applicability
- confirmed · Land-level healthcare provider, essential classification
- Registration
- scheduled · window opens 1 Oct 2026, due 31 Dec 2026
- Self-declaration
- drafted from live controls · ready for the 12-month clock
- Controls evidenced
- 89/103 · 14 open, each with an owner and a date
- Export
- sealed · sha256:3d8f...2b1c
Where teams usually start
With a demo walked through by TruSecure — your federal/Land applicability assessed under the NISG 2026, the controls you already operate mapped against what the new Bundesamt will ask for, and the 1 October clocks computed from the actual in-force date. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Austria by Bundesamt für Cybersicherheit under the Interior Ministry (from 1 October 2026). TruSecure determines applicability against Austria's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.