Austria's NIS2 transposition is enacted but not yet in force, after an earlier attempt lapsed. A ministerial draft, the Netz- und Informationssystemsicherheitsgesetz 2024 (326/ME, XXVII. GP), completed public consultation on 1 May 2024 and was submitted to the Bundeskanzleramt on 3 May 2024, but did not advance to a government bill before that legislative period ended, so Austria missed Directive (EU) 2022/2555's own 17 October 2024 transposition deadline.
A new government bill (308 d.B., XXVIII. GP) became the Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), BGBl. I Nr. 94/2025, promulgated 23 December 2025.
Under its own Section 51, the Act's substantive provisions (Sections 2 to 45, 46(1), and 47 to 50, together with Annexes 1 and 2) enter into force nine months after promulgation, on the next following first of a month, which is 1 October 2026; on that same date Sections 2 to 31 of the predecessor Netz- und Informationssystemsicherheitsgesetz (NISG), BGBl. I Nr. 111/2018 (Austria's transposition of the original NIS Directive, Directive (EU) 2016/1148), and its implementing ordinances (the NISV, BGBl. II Nr. 215/2019, and the QuaSteV, BGBl. II Nr. 226/2019) cease to apply.
So as of this review the predecessor NISG remains Austria's operative cybersecurity regime, and Austria's cybersecurity law today sits in a transitional shape: the predecessor NISG's currently in-force security and reporting duties are recorded alongside NISG 2026's enacted-but-not-yet-binding duties, the same footing this topic already records for the Cyber Resilience Act's own not-yet-binding requirements.
The predecessor NISG binds an operator of essential services in the energy, transport, banking, financial-market-infrastructure, health, drinking-water and digital-infrastructure sectors (Section 17, security measures; Section 19, reporting) and a digital service provider, defined narrowly as an online marketplace, online search engine or cloud-computing service with a micro- or small-enterprise exemption (Section 21, both duties combined), on a lighter, non-fixed-clock notification duty than NIS2's own.
NISG 2026 replaces the Bundesminister für Inneres's direct oversight with a new monocratic Bundesamt für Cybersicherheit (Section 3a), binds an essential entity or an important entity drawn from the sector lists of Annexes 1 and 2 at the medium (at least 50 employees, or turnover and balance-sheet total each over EUR 10 million) or large (at least 250 employees, or turnover over EUR 50 million and balance-sheet total over EUR 43 million) enterprise threshold, and its territoriality provision, Section 28(2)(2), names an online marketplace, an online search engine and a social-networking-platform provider expressly among the digital providers it reaches.
Its risk-management duty (Section 32) restates NIS2 Article 21's ten-category all-hazards list, and its reporting duty (Section 34) restates NIS2 Article 23's clock: a 24-hour early warning, a 72-hour notification, an interim report on request, and a final report within one month.
A covered entity must register with the Bundesamt für Cybersicherheit within three months of commencement (by 1 January 2027) and self-declare its risk-management measures within twelve months of registration; an essential entity additionally faces a shortened two-month proof window once the Bundesamt first requests it, which it may not do before two years after commencement.
Fines run to EUR 10,000,000 or 2 percent of worldwide turnover for an essential entity and EUR 7,000,000 or 1.4 percent for an important entity, both administrative offences rather than crimes, with no double sanction where the same conduct already drew a General Data Protection Regulation (GDPR) fine; a public-sector body faces no fine at all, only a published notice of non-compliance.
No Austrian instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.
Austria has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is GDPR Article 32's security-of-processing obligation, and personal-data breach notification under GDPR Articles 33 and 34 and the Datenschutzgesetz, both of which sit in the privacy topic rather than here.
Only the digital-provider slice of each regime's covered-entity class is flagged on this jurisdiction's rows; the wider sector classes both Acts also reach (energy, transport, banking, health, water, public administration and the rest) are recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.
Austria's computer-misuse offences under the Strafgesetzbuch (Sections 118a and 126a to 126c) bind the person who accesses a system without authorisation rather than the system's operator, and sit in the scraping topic rather than here.