Austria's Network and Information Systems Security Act 2026 (NISG 2026, BGBl. I Nr. 94/2025), the national transposition of Directive (EU) 2022/2555 (NIS2), becomes substantively applicable on October 1, 2026, when the NISG 2018 regime, the NISV and the QuaSteV are repealed and the Bundesamt fuer Cybersicherheit becomes the competent authority under section 3a.
Cloud-computing and data-centre providers, managed-service and managed-security providers, DNS service providers, TLD registries, domain-name registration service providers, online marketplaces meeting the Annex size rules, and qualified trust service providers serving Austria must determine their in-scope status under sections 24 to 26, put section 32 risk-management measures in place, and register with the Bundesamt fuer Cybersicherheit under section 29 by October 1, 2026, or fall outside the only operative Austrian NIS regime.
- Deadline : October 1, 2026 (substantive NISG 2026 regime applies; NISG 2018, NISV and QuaSteV repealed)
- Who : Essential and important entities and domain-name registration service providers in Annex 1 and 2 sectors operating in Austria
- What : Classify in-scope status (sections 24 to 26), implement section 32 risk-management measures, register under section 29, prepare for supervision
- Otherwise : Outside the only operative Austrian NIS regime; supervisory orders up to withdrawal of authorisation for essential entities; penalties up to EUR 50,000 (EUR 100,000 on repeat) per the WKO
- Official source : NISG 2026, BGBl. I Nr. 94/2025 (RIS)
What is due on October 1, 2026
Four obligations fall due when the substantive regime starts on October 1, 2026. In-scope entities must determine whether they are a wesentliche Einrichtung (essential entity), a wichtige Einrichtung (important entity) or a domain-name registration service provider under sections 24 to 26, applying the Annex 1 and 2 sectors and the section 25 size-cap rules. They must implement proportionate technical, operational and organisational risk-management measures under section 32, and register with the Bundesamt fuer Cybersicherheit under section 29.
Transitional provisions under section 51 have applied since December 24, 2025, while the NISG 2018 regime remained operative. The section 29 registration form is still to be set by ordinance: according to the Austrian chamber (WKO), registration must be completed by December 31, 2026, although the duty arises from October 1, 2026.
| Step | Date |
|---|---|
| Government bill filed | November 20, 2025 |
| Nationalrat adoption | December 12, 2025 |
| Bundesrat approval | December 18, 2025 |
| Promulgation (BGBl. I Nr. 94/2025) | December 23, 2025 |
| Transitional provisions apply | December 24, 2025 |
| Substantive regime applies | October 1, 2026 |
Who is covered
Entities are classified as essential (wesentliche Einrichtungen), important (wichtige Einrichtungen) or domain-name registration service providers. Section 25 sets the size-cap rules that move an entity between the essential and important tiers; qualified trust service providers, TLD registries, DNS service providers, the federal public administration, CER critical entities and section 26 designations are size-independent and always in scope.
What to do before October 1, 2026
- Classify the entity as essential, important or domain-name registration service provider under sections 24 to 26, applying the Annex sectors, the section 25 size-cap rules and the size-independent categories.
- Implement proportionate technical, operational and organisational risk-management measures under section 32, taking into account state of the art, relevant standards, cost, risk exposure and size.
- Prepare the section 29 registration data (name, address, sector, subsector and entity type per Annex 1 or 2, and EU Member States served) and submit it once the form is published; the WKO states registration must be completed by December 31, 2026.
- Prepare for supervisory interaction with the Bundesamt fuer Cybersicherheit from the October 1, 2026 go-live, and review obligations under the NISG 2018 regime that end on that date.
What happens otherwise
On October 1, 2026 the NISG 2018, the NISV (BGBl. II Nr. 215/2019) and the QuaSteV are repealed, so an entity that has not classified itself or put section 32 measures in place sits outside the only operative Austrian NIS regime. The Bundesamt fuer Cybersicherheit can then supervise in-scope entities and issue supervisory measures; per the WKO, organisational-duty penalties reach EUR 50,000 (EUR 100,000 on repeat), and for essential entities supervisory orders can extend to withdrawal of the authorisation to provide the service. Continuous per-jurisdiction monitoring surfaces such application dates as they are fixed in the law.
Follow this topic in real time with a free monitoring job


