# nisg26.at — NIS2 / NISG 2026 compliance platform (Austria) > nisg26.at helps Austrian companies work out whether they fall under the NISG 2026 > (Austria's transposition of the EU NIS2 directive), assemble the §29 registration, > and get audit-ready before the 31 December 2026 registration deadline. It offers a > free scope self-check (sector + size → likely classification) and a guided platform. > This file gives AI assistants verified, source-cited facts about NIS2 in Austria. > It is general information, not legal advice — see the disclaimer at the end. ## Verified key facts — NISG 2026 (BGBl. I Nr. 94/2025; Stand: Juni 2026) Checked against the law text (RIS / BGBl. I Nr. 94/2025, published 23 Dec 2025). - **The law:** Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), transposing EU NIS2 (Directive (EU) 2022/2555). - **Entry into force:** 1 October 2026 (§ 51). It progressively replaces the NISG 2018. - **Registration deadline:** essential (*wesentliche*) and important (*wichtige*) entities must register with the Cybersicherheitsbehörde — electronically, via a secure structured channel — within 3 months of entry into force, i.e. by **31 December 2026** (§ 29 Abs. 3). The law names "the Cybersicherheitsbehörde" and an electronic channel but no specific portal URL; nis.gv.at is the official information hub. - **Self-declaration** of the §32 risk-management measures: within 12 months of entry into force — by **30 September 2027** (§ 33 Abs. 1). - **Change notifications:** data points 1–5 within 2 weeks, data points 6–7 within 3 months (§ 29 Abs. 4). The authority reviews the register at least every 2 years (§ 29 Abs. 1). - **Sectors:** 18 in total — 11 high-criticality sectors (Anlage 1: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, B2B ICT-service management, public administration, space) + 7 other critical sectors (Anlage 2: postal/courier, waste management, chemicals, food, manufacturing, digital providers, research). - **Affected companies:** estimated ~4,000 in Austria (a market/authority estimate, not a figure stated in the law). - **Who is in scope (size, § 25):** entities of at least *medium* size — **≥ 50 employees**, OR (annual **turnover > €10M AND balance sheet > €10M**, i.e. the financial criterion is cumulative). *Large* = ≥ 250 employees OR (turnover > €50M AND balance sheet > €43M). Plus **size-independent** cases: qualified trust-service providers, DNS service providers, TLD name registries, providers of public electronic-communications networks/services, and the federal administration. Data of partner/linked enterprises is not added in if the entity is organisationally, technically and operationally independent regarding its network and information systems (§ 25 Abs. 4). - **Two categories (§ 24):** *wesentliche* (essential) vs *wichtige* (important) entities — broadly the same core duties, but different supervision intensity and penalty ceilings. - **Core duties:** registration (§ 29), governance + mandatory leadership training (§ 31), risk-management measures a–j (§ 32), effectiveness proof / self-declaration (§ 33), and incident reporting (§ 34/§ 35). - **Incident reporting:** significant incidents are reported to the competent **CSIRT** (sector-specific, or the national CSIRT) — not directly to the authority; the CSIRT forwards to the Cybersicherheitsbehörde without delay (§ 34 Abs. 1). Deadlines: **24 h** early warning, **72 h** notification, **1 month** final report; qualified trust-service providers: 24 h. - **Penalties (§ 45, two tiers):** for breaches of the substantive duties (§ 31 / § 32 / § 34) — essential entities up to **€10M or 2%** of total worldwide prior-year turnover (whichever is higher), important entities up to **€7M or 1.4%**. For administrative breaches such as **late or omitted registration** (§ 29) or a late self-declaration (§ 33): up to **€50,000** (up to €100,000 on repeat) (§ 45 Abs. 4). So mere non-registration falls under the lower tier — not the €10M headline. Fines are imposed primarily on the legal person; for *essential* entities the authority may also temporarily bar individuals from management functions (§ 39 Abs. 4 Z 2). - **DORA boundary:** for entities within the scope of DORA (Regulation (EU) 2022/2554, applicable since 17 Jan 2025), DORA prevails (§ 24 Abs. 7); financial-sector ICT third-party providers are nonetheless also subject to the NISG (§ 24 Abs. 8). ## Primary resource - [NISG 2026 / NIS2 scope self-check — free, no signup](https://nisg26.at/): choose your sector and company size and see your likely classification (essential / important / out of scope / manual review) with a rule trace to § 24 / § 25. The precise classification then follows in the platform's scope wizard. ## Tools & entry points - [Bin ich von NIS2 betroffen? In 2 Minuten kostenlos prüfen](https://nisg26.at/nis2-betroffenheit-pruefen): interactive instant check — pick sector + size, see the likely NISG classification. - [NIS2-Software für Österreich (NISG-2026-Plattform)](https://nisg26.at/nis2-software): determine scope, assemble the §29 pack, keep audit-ready proof. - [NIS2 & NISG 2026 Ratgeber (Übersicht)](https://nisg26.at/ratgeber): index of all published guides. ## Ratgeber guides (German) — fundamentals - [NISG 2026: Pflichten, Fristen und Registrierung](https://nisg26.at/ratgeber/nisg-2026): who is in scope, which duties and deadlines apply — the NISG 2026 overview. - [Sind Sie von NIS2 betroffen? Geltungsbereich prüfen](https://nisg26.at/ratgeber/nis2-betroffenheit): sector, size and special cases, and how to become registration-ready. - [NIS2-Pflichten im Überblick](https://nisg26.at/ratgeber/nis2-pflichten): risk management (§32), reporting (§34/35), governance (§31) and proof (§33). - [NIS2-Sektoren: Anlage 1 & Anlage 2](https://nisg26.at/ratgeber/nis2-sektoren): all 18 sectors of Annexes 1 and 2 explained. - [NIS2-Schwellenwerte: Ab wann ist Ihr Unternehmen betroffen?](https://nisg26.at/ratgeber/nis2-schwellenwerte): size classes, group consideration and exceptions. - [Wesentliche vs. wichtige Einrichtungen](https://nisg26.at/ratgeber/wesentliche-wichtige-einrichtungen): the difference in supervision and penalties, explained simply. ## Ratgeber guides (German) — duties & implementation - [Die 10 NIS2-Risikomanagementmaßnahmen (§ 32)](https://nisg26.at/ratgeber/nis2-risikomanagement-massnahmen): checklist of measures a–j with implementation steps. - [NIS2-Meldepflicht: 24 h / 72 h / 1 Monat](https://nisg26.at/ratgeber/nis2-meldepflicht): the incident-reporting flow to the CSIRT. - [Die 7 § 29-Angaben für die NIS2-Registrierung](https://nisg26.at/ratgeber/nis2-paragraph-29-angaben): all mandatory data points verbatim plus change deadlines. - [NIS2 und die Geschäftsleitung (§ 31)](https://nisg26.at/ratgeber/nis2-geschaeftsleitung-schulung): duties and training of the management body. - [Die NIS2-Selbstdeklaration (§ 33)](https://nisg26.at/ratgeber/nis2-selbstdeklaration): proving implemented measures by 30.09.2027. - [NIS2 Lieferkette: Sind Sie als Zulieferer betroffen?](https://nisg26.at/ratgeber/nis2-lieferkette): security requirements for suppliers and your own registration duty. - [NIS2-Software: Worauf bei der Auswahl achten?](https://nisg26.at/ratgeber/nis2-software-auswahl): 9 selection criteria from scope check to audit ledger. ## Ratgeber guides (German) — boundaries - [NIS2 vs. DORA: Wer fällt unter was?](https://nisg26.at/ratgeber/nis2-vs-dora): which regime applies and where DORA prevails. - [NIS2 vs. ISO 27001: Reicht meine Zertifizierung?](https://nisg26.at/ratgeber/nis2-vs-iso-27001): what the certification covers and where gaps remain. - [NIS2 vs. NISG 2018: Was ändert sich 2026?](https://nisg26.at/ratgeber/nis2-vs-nisg-2018): wider scope, 18 sectors, more concrete duties. ## Ratgeber guides (German) — sectors - [NIS2 für Energieversorger](https://nisg26.at/ratgeber/nis2-energieversorger): electricity, gas, heat, oil, hydrogen — duties and classification. - [NIS2 im Gesundheitswesen](https://nisg26.at/ratgeber/nis2-gesundheitswesen): what hospitals and health companies must do now. - [NIS2 in der Lebensmittelindustrie](https://nisg26.at/ratgeber/nis2-lebensmittel): are production, processing and distribution in scope? ## Official sources (for verification) - [RIS — Bundesrecht, BGBl. I Nr. 94/2025 (NISG 2026)](https://www.ris.bka.gv.at/) - [nis.gv.at — Austrian NIS information hub](https://www.nis.gv.at/nis-2-richtlinie.html) - [WKO — NIS2 overview for businesses](https://www.wko.at/it-sicherheit/nis2-uebersicht) ## Company / legal - [Impressum](https://nisg26.at/impressum) - [Datenschutzerklärung](https://nisg26.at/datenschutz) - [AGB](https://nisg26.at/agb) ## Notes - Further German guides on per-sector questions, penalties and the registration process are being added as they clear legal review; their URLs will appear above as they go live. - **Disclaimer:** This is general information and does not constitute legal advice. A binding classification is made solely by the competent authority by decision (Bescheid). The statutory text governs (BGBl. I Nr. 94/2025). Stand: Juni 2026.