# RKEG

**What is the Austrian critical entities resilience act?**

The Resilienz kritischer Einrichtungen-Gesetz (RKEG), Federal Law Gazette I No. 60/2025, transposes Directive (EU) 2022/2557 in Austria. It concerns the resilience of critical entities as a whole, including against natural events, sabotage and outages.

The line to the NISG 2026 is easy to remember. The NISG 2026 concerns the security of network and information systems. The RKEG concerns the resilience of the entity as a whole, whatever the cause.

An entity does not become a critical entity by assessing itself. It is identified under section 11 RKEG by a formal decision of the Federal Minister of the Interior. Without such a decision you are not a critical entity under this act.

The link to NIS2 matters for those affected. Anyone identified as a critical entity under Directive (EU) 2022/2557 counts as an essential entity under section 24(1)(1)(f) NISG 2026, regardless of company size. The size thresholds then no longer apply. This is our interpretation and not legal advice.

## Related terms
- [NIS2](https://vetosec.at/en/it-security/nis2/)
- [IT emergency plan](https://vetosec.at/en/it-security/notfallplan/)
- [Risk analysis](https://vetosec.at/en/it-security/risikoanalyse/)
- [ISO/IEC 27001](https://vetosec.at/en/it-security/iso-27001/)

## Source
https://vetosec.at/en/it-security/rkeg/ (vetosec, recht)
