Law / Austria

Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management Measures

NISG 2026, BGBl. I Nr. 94/2025, §§ 24, 25, 28 und 32

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force in 15 days, effective 1 October 2026.

A sector security regimes rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This duty does not yet bind: Section 32, together with the rest of this Act's Sections 2 to 45, applies from 1 October 2026, nine months after the Act's 23 December 2025 promulgation.
  • Once it applies, it binds a wesentliche Einrichtung (essential entity) or wichtige Einrichtung (important entity) under Section 24, which reaches an online marketplace, an online search engine and a social-networking-services platform provider expressly (Section 28(2)(2)) at the medium-enterprise threshold of Section 25 (at least 50 employees, or turnover and balance-sheet total each over EUR 10 million) or above; the wider sector classes Section 24 also reaches (energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT-service management, public administration, space, postal and courier services, waste management, chemicals, food, and manufacturing) are a designation and sector class no activity in this vocabulary expresses, and are not separately flagged here.
  • Implement technical, operational and organisational risk-management measures, appropriate and proportionate to the risk, to reduce risks to the network and information systems you use for your operations or to provide your services, and to prevent or minimise the impact of a cybersecurity incident on your users and on other services.
  • Cover at least: risk analysis and information-system security concepts; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; effectiveness-assessment policies; basic cyber-hygiene practices and training; cryptography and, where appropriate, encryption policy; personnel security, access control and asset management; and multi-factor or continuous authentication.
  • Have your management body implement and oversee these measures and attend cybersecurity training designed for it, and offer your staff regular training.
  • Register with the Bundesamt für Cybersicherheit within three months of this duty applying (by 1 January 2027), and self-declare the risk-management measures you have implemented within twelve months of registration; expect the Bundesamt to be able to demand proof of operative and organisational implementation no earlier than two years after this duty applies.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Section 45's penalty regime for a Section 32 infringement is a Verwaltungsübertretung (administrative offence) carrying a fine only; no provision reviewed here makes it a criminal offence.

Penalty structure

Section 45(2) sets the fine for a wesentliche Einrichtung's (essential entity's) infringement, including a failure to implement the risk-management measures of Section 32, at up to EUR 10,000,000 or up to 2 percent of the undertaking's total worldwide turnover in the preceding financial year, whichever is higher. Section 45(3) sets the wichtige Einrichtung (important entity) tier at up to EUR 7,000,000 or up to 1.4 percent, whichever is higher, mirroring NIS2 Article 34(4) and (5). Section 46(2) instead requires a public-sector body's non-compliance to be established by decision and, if not remedied, published, with no fine.

Rule
Higher of
As of
14 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Bundesamt für Cybersicherheit (Cybersicherheitsbehörde), a monocratic authority established within, and directly subordinate to, the Bundesminister für Inneres; an administrative fine is imposed by the competent Bezirksverwaltungsbehörde (district administrative authority) on the Bundesamt's notification.

Settledness

The Bundesamt für Cybersicherheit does not commence operation until this duty's own effective date, so no dedicated guidance page from it was located as of this review; the Act's own text and the RIS consolidated register are the primary sources relied on.

As of
14 September 2026
Open questions
Will an implementing ordinance the Cybersicherheitsbehörde is authorised to issue under Section 32(5), or a still-pending European Commission implementing act under NIS2 Article 21(5), narrow the ten baseline risk-management measure categories as they apply specifically to an online marketplace, online search engine or social-networking-platform provider?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 32 requires a wesentliche Einrichtung (essential entity) or wichtige Einrichtung (important entity), as Section 24 defines them against the Annex 1 and Annex 2 sector lists and the medium- or large-enterprise thresholds Section 25 sets, to implement appropriate and proportionate technical, operational and organisational risk-management measures to reduce the risks to the security of the network and information systems it uses for its operations or to provide its services, and to prevent or minimise the impact of cybersecurity incidents on the users of its services and on other services.

The measures must follow an all-hazards approach and cover at least ten categories: risk analysis and information-system security concepts; cybersecurity-incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the security practices of direct suppliers and service providers; security in the acquisition, development and maintenance of network and information systems, including vulnerability management and disclosure; policies and procedures to assess the effectiveness of risk-management measures; basic cyber-hygiene practices and cybersecurity training; policies on the use of cryptography and, where appropriate, encryption; personnel security, access-control concepts and asset management; and multi-factor or continuous authentication, secure voice, video and text communication and, where appropriate, secure emergency communication systems, transposing NIS2 Article 21.

Section 28, the territoriality provision, names an online marketplace, an online search engine and a platform for social-networking services expressly among the digital providers it reaches, alongside cloud-computing, data-centre, content-delivery-network, managed-service and managed-security-service providers.

Section 31 places implementation and oversight of these measures on the entity's management body (Leitungsorgan), which must attend cybersecurity training designed for it and ensure staff receive regular training.

When LexLint raises it

  • operates_social_platform

Read the law

Bundesgesetzblatt, authentic PDF text, BGBl. I Nr. 94/2025

Back to the example  ·  Lint your app