NISG 2026

NIS2: are you affected?

The Austrian NISG 2026 enters into force on 1 October 2026. Registration by 31 December 2026 18 sectors

NIS2 reaches companies on two paths. As an essential or important entity under the NISG 2026. Or through the contract of a customer who is affected. The check below shows which case applies, in two minutes.

Scoping check

Three questions. Your answers stay in your browser, nothing is transmitted.

This tool gives a non binding first indication. It can suggest that you are covered. It cannot rule out that you are covered. Every entity has to make the assessment itself.

A secondary activity in one of these sectors can bring the entire legal person into scope.

2. Do you provide any of these services?

These services are covered regardless of company size.

3. Size of the legal person

What counts is the legal person, not the division. Figures of linked undertakings are added in full, those of partner undertakings pro rata (section 25(1)). If an operation is run as an own enterprise of a municipality, the municipality is the entity.

4. Do you supply companies in these sectors?

Supplying affected companies does not in itself create coverage. It does not change the result.

Without warranty. This first indication reflects our interpretation of the NISG 2026 and is not legal advice. The NISG 2026 (BGBl. I No. 94/2025) enters into force on 1 October 2026. Covered entities have to register by 31 December 2026.

What the law asks for

Section 32(4) NISG 2026 lists ten requirements. Our testing basis are the controls of ISO/IEC 27002:2022. We have mapped every requirement to its related controls, 35 in total, and we test each of them individually.

Requirement, section 32(4) What we look at Related controls, ISO/IEC 27002:2022
a) Risk analysis and information system security Which systems exist, what data sits on them, what is reachable from the internet 4controls
b) Incident handling Whether an incident plan exists, who does what, where alerts go 4controls
c) Business continuity, backup management, recovery and crisis management Whether backups are complete and whether restoring them has been tested 4controls
d) Supply chain security, for direct suppliers Which providers have access, through what, and what the contract says 4controls
e) Security in acquisition, development and maintenance, vulnerability handling Whether updates arrive reliably and how known vulnerabilities are handled 4controls
f) Assessing the effectiveness of the measures Whether anyone checks that the measures actually hold in daily work 3controls
g) Cyber hygiene and training Whether staff are trained and whether management attends, as section 31 requires 4controls
h) Cryptography and encryption Whether devices, storage and transmission paths are encrypted 2controls
i) Personnel security, access control, asset management Who may access what, how accounts are granted and revoked 4controls
j) Multi factor authentication and secured communication Whether a second factor is in place, especially for remote access and email 4controls

On the mapping: it follows ENISA's mapping table for Implementing Regulation (EU) 2024/2690. Two controls each cover two requirements, so the column adds up to 37 entries across 35 distinct controls. ENISA notes that such a mapping is not to be read as equivalency between standards. A control that is met therefore likely does not evidence that the legal requirement is met. Two points also sit outside ISO/IEC 27002: the risk assessment itself (a) and the assessment of effectiveness (f) are governed by the management system clauses of ISO/IEC 27001, not by a control.

The statute says these contents are required "at least". The list is a floor, not a ceiling. The cybersecurity authority may specify the requirements further by regulation (section 32(5)).

Two paths, two roles

You are directly affected

The law applies directly. It requires registration, the risk management measures under section 32, the reporting duties under section 34 and training of the management bodies under section 31. The security of direct suppliers has to be taken into account and is passed on through contracts in practice.

Section 29 registration, 31 management, 32 risk management, 34 reporting

You are a supplier

The NISG 2026 obliges essential and important entities. A supplier that is not one is under no direct statutory duty in that respect. The requirements arrive through the customer's contract, so evidence becomes a condition of the contract. IT providers are frequently covered in their own right, for example as MSP, MSSP, cloud or data centre providers.

Section 32(4)(d) NISG 2026, recital 85 of the NIS2 directive

What suppliers get asked for

Implementing Regulation (EU) 2024/2690 sets out what customers should put into their contracts, where appropriate. It usually reaches you in the questionnaire:

  • Security requirements on you as a provider
  • Awareness, qualification and training of your staff
  • Background checks on staff
  • Duty to report security relevant incidents without delay
  • Right to audit or to receive audit reports
  • Duty to remediate security relevant vulnerabilities
  • Rules for subcontractors
  • Obligations when the contract ends, such as retrieval and disposal of the information
Implementing Regulation (EU) 2024/2690, Annex point 5.1.4. It applies directly only to certain digital providers. For everyone else it is a good benchmark for what arrives in contracts, not a direct duty.

What we offer

Two packages, depending on which path NIS2 reaches you by.

You are directly affected

NIS2 gap analysis

For essential and important entities. Our testing basis are the controls of ISO/IEC 27002:2022. We have mapped them to the ten requirements of section 32(4) and test each mapped control individually.

The security of your direct suppliers has to be taken into account under section 32(4)(d). The simplest way is to send your suppliers straight to the supplier package.

Book a first call

You are a supplier

IT Check, supplier edition

For companies that have received a questionnaire or security requirements from a customer. A technical IT Check and an organisational check along exactly the points the questionnaire asks about.

We do not confirm conformity and we do not answer the questionnaire on your behalf. We record what is actually in place and name the gaps.

Received a questionnaire?

Implementation

We build this infrastructure

Monitoring and logging, a SIEM for central analysis, hardened servers, network segmentation, EDR and backups that can actually be restored. We plan, build and operate it, together with your IT team.

To the IT solutions
1. Oktober 2026 The NISG 2026 enters into force (section 51)
31. Dezember 2026 Registration with the federal cybersecurity authority, three months after entry into force (section 29)
24 hours Early warning to the responsible CSIRT after becoming aware of a significant incident (section 34)
72 hours Incident report, final report at the latest one month later (section 34)
up to 10m euro or 2 percent of the worldwide annual turnover of the undertaking the entity belongs to, whichever is higher. For essential entities (section 45(2))
up to 7m euro or 1.4 percent of the worldwide annual turnover of the undertaking the entity belongs to, whichever is higher. For important entities (section 45(3))

The high penalty range applies to serious failures, for example missing risk measures or unreported incidents. For a missed registration the law provides a separate, lower range of up to 50,000 euro, and up to 100,000 euro on repetition (section 45(4)).

Evidence

There is no NIS2 certification

The NISG 2026 provides for self declaration (section 33(1)) and, upon request of the authority, proof of the technical, operational and organisational implementation by an independent body (section 33(2)). For the operational and organisational implementation the act also accepts relevant valid certificates, for example ISO 27001. Such a certificate does not cover the technical implementation.

We deliver the scoping check and the gap analysis: current state against section 32, documented gaps, a prioritised order. We implement the measures with you. We do not issue a confirmation of conformity.

The testing basis is 35 annotated controls of ISO/IEC 27002:2022, each tested individually. On request, all 93 controls of the standard. The result doubles as groundwork for an ISO 27001 certification.

Section 33 NISG 2026 (self declaration and proof), WKO NIS FAQ. This is not legal advice. We assess technical and organisational measures only.

How secure is your IT really?

The IT Check reviews your IT across 8 areas with more than 100 checks. Findings within two weeks, from 1,299 € excl. VAT.