Austria’s NIS 2 Act: Understanding the Requirements and Ensuring Compliance
With the Austrian NIS 2 Act, cybersecurity becomes a new legal obligation for thousands of companies and institutions. The Austrian Network and Information Systems Security Act 2026 (NISG 2026) transposes EU Directive 2022/2555 into national law and significantly expands the scope of affected organizations.
While the previous NISG 2018 covered only a few companies, the new NIS-2 Act will affect approximately 4,000 organizations in Austria across 18 defined sectors. The goal is to sustainably strengthen the resilience of critical and important facilities against cyberattacks and IT security incidents.
Companies now face key questions: Am I affected? What obligations apply? What deadlines must be met? And how can requirements such as risk management, reporting obligations, and access control be implemented efficiently?
Key Deadlines Under the Network and Information System Security Act of 2026
October 1, 2026
NISG 2026 takes effect; risk management and reporting requirements apply
December 31, 2026
Registration of affected facilities must be completed
October 1, 2027
Submission of the self-declaration regarding implemented measures
starting in 2028
Inspections by the Cybersecurity Agency Are Possible
Since many organizational and technical measures require significant lead time, it is advisable to conduct a gap analysis and project planning early on.
Which companies are affected by the NIS 2 Act in Austria?
Whether an organization falls under the NIS 2 Act generally depends on two factors:
- Belonging to a defined NIS sector
- Meeting the statutory size thresholds
As a rule, companies that employ at least 50 employees or have both annual revenue and total assets exceeding 10 million euros are affected.
Critical Infrastructure
Critical infrastructure includes, in particular, large companies in sectors of high criticality.
These include, among others:
- Energy
- Transport
- Banking
- Financial market infrastructures
- Healthcare
- Drinking water supply
- Wastewater management
- ICT service management
- Digital infrastructure
- Public administration
- Space sector
An enterprise is considered large if it has at least 250 employees or an annual revenue exceeding €50 million and total assets exceeding €43 million.
Critical Infrastructure
Critical infrastructure includes medium-sized companies in sectors of high criticality, as well as medium- and large-sized companies in other critical sectors.
These other sectors are:
- Postal and courier services
- Waste management
- Chemical industry
- Food production
- Food processing
- Food distribution
- Manufacturing industries
- Digital services
- Research institutions
Suppliers and service providers may be indirectly affected
Even companies that are not themselves directly subject to the NIS-2 Act in Austria may be required to comply with certain requirements. This is due to supply chain security requirements. In the future, affected organizations will require service providers and suppliers to provide appropriate evidence of compliance.
What obligations does the NIS-2 Act impose in Austria?
The Network and Information System Security Act of 2026 requires affected companies to implement organizational and technical measures and to maintain documentation. Three areas are of particular focus:
1. Risk Management Measures: The Core of NIS 2 Compliance
The most important requirement of the NIS 2 Act in Austria is the implementation of systematic risk management. Companies must implement appropriate technical, organizational, and physical security measures to reduce cyber risks and maintain operational resilience.
These include, among other things:
- Security policies and governance structures
- Incident management processes
- Business continuity and crisis management
- Supply chain security
- Authentication and access policies
- Training and awareness programs
- Access controls – both digital and physical
2. Registration Requirement Under Austria’s NIS-2 Act
Affected essential and critical infrastructure operators must register with the competent cybersecurity authority. Registration must be completed by December 31, 2026 at the latest. Details regarding the registration process will be specified in future regulations. Companies should determine early on whether they fall within the scope of the law, as the responsibility for registration lies with the organizations themselves.
3. Reporting Requirements for Security Incidents
A key component of the NIS Act is the stricter reporting requirements. In the future, significant security incidents must be reported to the relevant authorities or CSIRTs within specified timeframes.
The reporting process consists of several stages:
- Early warning within 24 hours
- Detailed incident report within 72 hours
- Final report upon completion of the investigation (no later than one month)
What penalties apply for violations?
The NIS-2 Act provides for severe sanctions in the event of violations. In addition to regulatory requirements and audit measures, substantial fines may be imposed.
Depending on the nature and severity of the violation, penalties of up to 10 million euros or up to 2 percent of global annual revenue are possible—whichever is higher. In particularly serious cases, the license to provide the services may be revoked. Furthermore, there is an increased risk of reputational damage, business interruptions, and liability issues for management bodies.
Differences in NIS 2 Implementation in Austria and Germany
Germany and Austria are both implementing the European NIS 2 Directive; as a result, the fundamental requirements for risk management, reporting obligations, and corporate responsibility are largely identical.
However, differences exist in national implementation. Among other things, there are varying deadlines, regulatory authorities’ jurisdictions, and documentation requirements. While Austria is introducing the Network and Information System Security Act 2026 with a transition period ending on October 1, 2026, Germany already has stricter requirements for documenting and providing evidence of implemented security measures. The registration deadline has also already passed there.
Companies with locations or business operations in both countries should review the respective national requirements separately and align their compliance processes accordingly.
NIS-2 and Switzerland: Indirectly Affected by European Supply Chains
Although the NIS-2 Directive does not apply directly to companies in Switzerland, many companies within the EU now require their suppliers and service providers to demonstrate that they have adequate cybersecurity measures in place.
Swiss companies that are part of a European supply chain or provide services to NIS-2-regulated organizations must therefore often meet requirements related to information security, documentation, and compliance. Adhering to NIS-2 guidelines can thus become an important factor in competitiveness and trust even outside the EU.

Physical Security as Part of Your NIS 2 Strategy
The requirements of Austria’s NIS 2 Act go beyond traditional IT security measures. Controlling physical access is also a key component of effective risk management.
With VISIT, you can digitize visitor and supplier processes, manage access in a traceable manner, and create audit-proof documentation for audits and compliance. This allows you to seamlessly integrate visitor management, access control, and yard management into your NIS 2 strategy and establish a robust foundation for greater security and transparency.
Would you like to implement NIS2 requirements in a structured and sustainable way?
Talk to us about customized solutions for secure, scalable, and future-proof infrastructure.




