What Is NISG 2026?
Since 1 October, a new cybersecurity law has applied in Austria. Many companies are unsure whether it affects them. This article aims to give a short overview.
Summary
NISG 2026 (Netz- und Informationssystemsicherheitsgesetz 2026, the Austrian Network and Information Systems Security Act) implements the EU NIS2 Directive in Austria. It was promulgated on 23 December 2025, has applied since 1 October 2026 and replaces the previous NIS Act, which only covered a small number of operators of essential services.
Scope
Two conditions must be met:
- Sector: The company operates in one of the 18 covered sectors, such as energy, transport, health, digital infrastructure, waste, chemicals or food.
- Size: At least 50 employees or more than €10 million in annual turnover and balance sheet total.
It is estimated that around 4,000 organizations in Austria are covered in total.
Source: Austrian Economic Chambers (WKO), NISG 2026 overview (in German, as of 2 October 2026)
Important for manufacturers: Manufacturing only includes certain industries such as electronics or mechanical engineering. Wood businesses, for example, are usually not covered, although running your own district heating network can change that. A closer look is worthwhile.
What covered companies
must implement
Overview:
- Registration: by 31 December 2026 with the competent authority
- Risk management: appropriate technical and organizational measures
- Incident reporting: significant security incidents must be reported on time
- Self-declaration: to be submitted by 30 September 2027
- Training: mandatory for management and should also take place regularly for employees
Possible penalties: Essential entities face fines of up to €10 million or 2% of worldwide annual turnover, important entities up to €7 million or 1.4%. Failing to register costs up to €50,000, or up to €100,000 for repeat offenses.
Indirect effects
on smaller companies
Companies that are not covered by NISG 2026 themselves can still be affected indirectly. Covered companies must address the security of their supply chain and often pass requirements on to suppliers and service providers. Anyone supplying an energy provider, a hospital or a machine builder will therefore often receive an IT security questionnaire.
Conclusion
NISG 2026 is a serious topic for many companies and should not be neglected. Still, an individual assessment is advisable, as not every company is covered. The basics behind it, however, usually make sense for every business:
- Updates: update operating systems, software and firewalls promptly
- Access: multi-factor authentication (guide in German), individual accounts for each person, administrator rights only where needed
- Backups: regular, separated from the network and with tested restores
- Emergency plan: document responsibilities, contacts and recovery steps in writing
- Employees: recognize phishing and fraud attempts, for example with a free phishing test (in German)
Many of these points are also part of the risk-management measures required by NISG 2026.
Back to all articlesThis article is a general introduction and does not replace legal advice.