Law and standards
RKEG
What is the Austrian critical entities resilience act?
The Resilienz kritischer Einrichtungen-Gesetz (RKEG), Federal Law Gazette I No. 60/2025, transposes Directive (EU) 2022/2557 in Austria. It concerns the resilience of critical entities as a whole, including against natural events, sabotage and outages.
The line to the NISG 2026 is easy to remember. The NISG 2026 concerns the security of network and information systems. The RKEG concerns the resilience of the entity as a whole, whatever the cause.
An entity does not become a critical entity by assessing itself. It is identified under section 11 RKEG by a formal decision of the Federal Minister of the Interior. Without such a decision you are not a critical entity under this act.
The link to NIS2 matters for those affected. Anyone identified as a critical entity under Directive (EU) 2022/2557 counts as an essential entity under section 24(1)(1)(f) NISG 2026, regardless of company size. The size thresholds then no longer apply. This is our interpretation and not legal advice.
All terms in the knowledge base
Note: This entry reflects the state of knowledge to the best of our understanding and serves as general orientation. It is not legal advice. What counts is always the version currently in force at the responsible body, for example dsb.gv.at, nis.gv.at or enisa.europa.eu.
From the term to practice
Where does your business actually stand?
The IT Check reviews your IT across 8 audit areas with more than 100 individual checks and delivers documented findings with a prioritised action plan. From 1,299 € excl. VAT. The first call takes 20 minutes and carries no charge.