Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations
NISG 2026, BGBl. I Nr. 94/2025, §§ 34 und 35
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force in 15 days, effective 1 October 2026.
A vulnerability and incident reporting rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This duty does not yet bind: Section 34, together with the rest of this Act's Sections 2 to 45, applies from 1 October 2026, nine months after the Act's 23 December 2025 promulgation.
- Once it applies, it binds a wesentliche Einrichtung or wichtige Einrichtung on the same scope as this jurisdiction's companion risk-management row, which names an online marketplace, an online search engine and a social-networking-services platform provider expressly; the wider sector classes are not separately flagged here for the reason given on that row.
- Notify your competent sector-specific CSIRT, or, absent one, the national CSIRT, of every significant cybersecurity incident: an early warning within 24 hours of becoming aware, stating whether it is suspected to result from unlawful and culpable acts or to have cross-border effects.
- Follow with a fuller notification within 72 hours of becoming aware, updating the early warning with an initial evaluation of the incident's severity and impact and any indicators of compromise.
- Submit an interim report on request, and a final report no later than one month after the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have resolved it.
- Treat an incident as significant where it has caused, or can cause, severe operational disruption or severe financial loss to your own operations, or has affected, or can affect, another person through considerable material or non-material damage.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Section 45's penalty regime for a Section 34 infringement is a Verwaltungsübertretung (administrative offence) carrying a fine only; no provision reviewed here makes it a criminal offence.
Penalty structure
The same Section 45(2) and (3) tiers that govern a Section 32 infringement govern a Section 34 infringement: up to EUR 10,000,000 or up to 2 percent of worldwide turnover for a wesentliche Einrichtung, whichever is higher, and up to EUR 7,000,000 or up to 1.4 percent for a wichtige Einrichtung, whichever is higher. Section 45(1)(4) names a failure to comply with the Section 34(1) and (2) reporting duty among the offences this penalty punishes.
- Rule
- Higher of
- As of
- 14 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Bundesamt für Cybersicherheit (Cybersicherheitsbehörde), a monocratic authority established within, and directly subordinate to, the Bundesminister für Inneres, working with the sector-specific and national CSIRTs that receive notifications; an administrative fine is imposed by the competent Bezirksverwaltungsbehörde (district administrative authority).
Settledness
The Bundesamt für Cybersicherheit does not commence operation until this duty's own effective date, so no dedicated guidance page from it was located as of this review; the Act's own text and the RIS consolidated register are the primary sources relied on.
- As of
- 14 September 2026
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 34 requires a wesentliche Einrichtung (essential entity) or wichtige Einrichtung (important entity) to notify its competent sector-specific CSIRT, or, absent one, the national CSIRT, of every significant cybersecurity incident (defined by Section 35) without delay: an early warning within 24 hours of becoming aware of the incident, stating whether it is suspected to result from unlawful and culpable acts or to have cross-border effects, followed by a fuller notification within 72 hours updating that assessment with an initial evaluation of the incident's severity and impact and any indicators of compromise.
It also requires an interim report on the CSIRT's or the Cybersicherheitsbehörde's request, and a final report no later than one month after the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once it is resolved, transposing NIS2 Article 23.
Section 35 treats a cybersecurity incident as significant where it has caused or can cause severe operational disruption or severe financial loss to the entity, or has affected or can affect another natural or legal person through considerable material or non-material damage, judged against criteria including the dependency of other Annex 1 or Annex 2 sectors on the affected service, the entity's market share, and the incident's possible geographic and cross-border reach.
When LexLint raises it
operates_social_platform