Check in 60 seconds whether NIS2 applies to you

NIS2 compliance in Austria — clarity in three minutes

NIS2 documents for 23 countries — based on each country's own law

Start the test — enter your details

The result with reasoning is shown immediately after answering. We use your details only for providing the NIS2 service.

23countries
21languages
5documents
3 900 EURpackage

Straight from the law

§ 2. Mit diesem Bundesgesetz werden Maßnahmen festgelegt, mit denen ein hohes Cybersicherheitsniveau, insbesondere von wesentlichen und wichtigen Einrichtungen in den Sektoren 1. Energie, 2. Verkehr, 3. Bankwesen, 4. Finanzmarktinfrastrukturen, 5. Gesundheitswesen, 6. Trinkwasser, 7. Abwasser, 8. Digitale Infrastruktur, 9. Verwaltung von IKT-Diensten (Business-to-Business), 10. Öffentliche Verwaltung, 11. Weltraum, 12. Post- und Kurierdienste, 13. Abfallbewirtschaftung, 14. Produktion, Herstellung und Handel mit chemischen Stoffen, 15. Produktion, Verarbeitung und Vertrieb von Lebensmitteln, 16. Verarbeitendes Gewerbe und Herstellung von Waren, 17. Anbieter digitaler Dienste sowie 18. Forschung, und den zugehörigen Teilsektoren nach den Anlagen 1 und 2 erreicht werden soll. Begriffsbestimmungen

— — —
[INKRAFTTRETEN — NISG 2026 § 51: Verpflichtungen treten (verbatim) „nach Ablauf von neun Monaten nach der Kundmachung dieses Bundesgesetzes mit dem nächstfolgenden Monatsersten“ in Kraft. Kundmachung 23.12.2025 -> arvutatud 1.10.2026 (MITTE verbatim seaduses). NISG 2018 (BGBl. I Nr. 111/2018) kehtib senikaua. Märkus lisatud programmaatiliselt (mitte seaduse osa).]

NISG 2026 § 2

The text is from the country's official, enacted law — verbatim, not paraphrased.

Competent authority

Zuständige Behörde und Meldepflicht (Cybersicherheitsbehörde, sektorspezifische CSIRTs — NISG § 4, § 34)

NISG 2026 § 34

The authority's details are from the country's official, enacted law: https://www.ris.bka.gv.at/Dokumente/BgblAuth/BGBLA_2025_I_94/BGBLA_2025_I_94.html

Data on an EU serverAll processing happens on a server located in the European Union — nothing leaves it.
GDPR by designConsent, the right to erasure and data minimisation are built in from the start.

What is NIS2 and who does it affect in Austria?

NIS2 is the European Union cybersecurity directive (EU) 2022/2555, transposed in Austria by the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) (NISG 2026). It significantly widens the scope of obligations: energy, transport, healthcare, digital infrastructure, manufacturing, food industry and many other sectors must implement risk management measures and report incidents to the Cybersicherheitsbehörde (Bundesamt für Cybersicherheit, NISG 2026 § 3a, § 4); Zentrale Anlaufstelle (§ 5); sektorspezifische CSIRTs und nationales CSIRT (§ 34); Nationales Koordinierungszentrum für Cybersicherheit (§ 6). Verpflichtungen treten neun Monate nach der Kundmachung in Kraft (§ 51; Kundmachung 23.12.2025, BGBl. I Nr. 94/2025) (Cybersicherheitsbehörde).

The deadlines are strict: a significant incident requires an early warning within 24 hours, a full notification within 72 hours and a final report within one month. Non-compliance can cost an essential entity up to 10 million euros or 2% of worldwide turnover, and an important entity up to 7 million euros or 1.4%.

Our portal turns NIS2 requirements into practice: the free scoping test shows whether NIS2 applies to your company, and the document package is generated automatically, grounded in the officially applicable law text for your country. Start with the test — it takes three minutes.

NIS2 transposition status by EU country

NIS2 incident reporting deadlines by EU country

NIS2 risk-management measures vs ISO 27001, DORA and GDPR

NIS2 administrative fines by country

NIS2 management body training obligation by country

The results are an indicative assessment, not legal advice. Your company remains responsible for the final content of any document.