Netz- und Informationssystemsicherheitsgesetz (NISG), Security Measures for Operators of Essential Services and Digital Service Providers
NISG, BGBl. I Nr. 111/2018, §§ 17 und 21
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 28 December 2018.
A sector security regimes rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds a digital service provider that is an online marketplace, online search engine or cloud-computing service with a main establishment, or a designated representative, in Austria, unless it is a micro or small enterprise under Commission Recommendation 2003/361/EC; the wider operator-of-essential-services class this Act also reaches (energy, transport, banking, financial-market infrastructure, health, drinking water, digital infrastructure) is a sector designation no activity in this vocabulary expresses, and is not flagged here on that account.
- Take technical and organisational security measures for the network and information systems you use to provide the service, appropriate to the state of the art and proportionate to the risk that can be identified with reasonable effort.
- As a digital service provider, cover at minimum the security of your systems and facilities, incident handling, business-continuity management, monitoring, review and testing, and compliance with relevant international standards.
- Prove compliance on request; expect this duty, together with the rest of this Act's Sections 2 to 31, to be repealed and replaced on 1 October 2026 by the Netz- und Informationssystemsicherheitsgesetz 2026's own risk-management duty, documented on this jurisdiction's companion row.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Section 26 makes a breach of this duty a Verwaltungsübertretung (administrative offence) carrying a fine only; no provision reviewed here makes it a criminal offence.
Penalty structure
Section 26(1) sets a fine of up to EUR 50,000 for, among other listed breaches, a failure to take the security measures required by Section 17 or 21, or to comply with the reporting duty of Section 19(1) or 21(2); a repeat offence raises the fine to up to EUR 100,000. The schema records the base cap; this note carries the repeat-offence figure, which the shape has no separate field for.
- Rule
- Fixed only
- As of
- 14 September 2026
- Currency
- EUR
- Fixed cap
- 50,000
Who enforces it
Enforcement body
Bundesminister für Inneres (Federal Minister of the Interior) administers this Act and receives proof of compliance; an administrative fine for a breach is imposed by the competent Bezirksverwaltungsbehörde (district administrative authority).
Settledness
No dedicated guidance page from the Bundesminister für Inneres or GovCERT.at addressing this specific duty was located as of this review; the Act's own text and the RIS consolidated register are the primary sources relied on.
- As of
- 14 September 2026
- Open questions
- Will the Bundesamt für Cybersicherheit, once operational, treat a security measures declaration or certification already accepted by the Bundesminister für Inneres under this Act's Section 17(3) as satisfying the Netz- und Informationssystemsicherheitsgesetz 2026's own Section 33 proof duty, or will it require a fresh submission after 1 October 2026?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 17 requires an operator of essential services, designated under Section 16 in the energy, transport, banking, financial-market-infrastructure, health, drinking-water or digital-infrastructure sector, to take technical and organisational security measures for the network and information systems it uses to provide the essential service, appropriate and proportionate to the state of the art and to the risk that can be identified with reasonable effort, and to prove compliance to the Bundesminister für Inneres at least every three years.
Section 21 places the equivalent duty on a digital service provider, defined by Section 3(12) and (13) as an online marketplace, online search engine or cloud-computing service with a main establishment or a designated representative in Austria and excluding a micro or small enterprise, covering at minimum the security of its systems and facilities, incident handling, business-continuity management, monitoring and testing, and compliance with international standards.
This is Austria's transposition of the original NIS Directive (Directive (EU) 2016/1148); the successor Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) repeals Sections 2 to 31 of this Act, this provision included, on 1 October 2026, documented on this jurisdiction's companion rows.
When LexLint raises it
operates_social_platform