Austria's New Cyber Law Will Pull 4,000 Firms Into Its Regulatory Orbit — With Personal Liability for Bosses
Published on 09/23/2026 at 01:10 | Editorial boerse-global.de
Austria has finished legislating a sweeping overhaul of its cybersecurity rules, and the clock is now running for thousands of companies that have never before faced this kind of oversight. The core provisions of the Network and Information System Security Act — known locally as NISG 2026 — take effect on 1 October 2026, transposing the EU's NIS2 Directive into national law. The bill was published in the official gazette on 23 December 2025 and replaces the earlier NIS1 framework, which covered only about 100 companies.
Who is caught
Roughly 4,000 Austrian companies and organisations are expected to fall under the new regime, according to estimates from the Austrian Federal Economic Chamber and current sector analysis. The scope spans 18 sectors, and the size threshold applies cumulatively: at least 50 employees, or annual turnover or a balance sheet total exceeding €10 million in each case.
Annex 1 of the statute lists the sectors designated as highly critical. Energy and banking are on it, along with transport, financial market infrastructures, healthcare, and drinking water as well as wastewater disposal. Digital infrastructure, public administration, ICT service management and the space economy are covered too. One carve-out matters for finance: where the Digital Operational Resilience Act (DORA) and NISG 2026 collide, DORA prevails.
Three deadlines, three years
Compliance unfolds in stages. Registration with the competent cybersecurity authority is due by 31 December 2026. A required self-declaration must follow by 1 October 2027. From 1 October 2028, officials may demand formal proof of security measures in the form of an audit report from an independent body. Should the authority order an extraordinary audit, essential entities have two months from the request to produce that evidence.
No passing the buck
Perhaps the most consequential element for boardrooms is that responsibility cannot be delegated. Management bodies are legally obliged to ensure and oversee compliance with risk management measures, and their members must attend dedicated cybersecurity training. Personal liability attaches to the leadership itself.
Enforcement sits with a brand-new agency, the Federal Office for Cybersecurity (BCS), which reports directly to the Interior Minister and is headed by Director Markus Kasinger.
Reporting an incident: 24 hours, 72 hours, one month
Significant security incidents trigger a three-stage notification chain. An early warning must reach the relevant CSIRT immediately and no later than 24 hours after the organisation becomes aware of the incident. A notification with an initial assessment follows within 72 hours, and a final report is due within one month at the latest.
Supply chain security is folded into risk management as well, covering relationships with direct service providers. That can mean contractually binding requirements on suppliers and measures to vet personnel reliability — identity checks, cross-referencing criminal records and sanctions lists, and verifying employment history.
Fines, and a criminal twist
Failures to register, to report incidents, or to complete IT security training can all draw penalties of up to €10 million or 2% of worldwide turnover. There is another provision worth flagging: from 1 October, actively scanning third-party systems and carrying out blocking measures may carry criminal liability.
