NISG 2026: Austria registration deadline (BfC)
What applies
Austria's NIS2 transposition requires affected entities to register electronically with the cybersecurity authority — the Federal Office for Cyber Security (Section 3a(1) NISG 2026). What has to be included is set out in Section 29(2), items 1 to 7: name, address, and contact details; sector and entity type under Annex 1 or 2; affected member states; IP address ranges.
The date deserves an honesty rarely offered elsewhere: the statute names no date. Section 29(3) says "within three months of this federal act entering into force," and entry into force follows from Section 51 as "nine months after publication, rolled forward to the first day of the following month." Counting from publication on 23 December 2025 lands on 31 December 2026. We present this date as our own calculation, not as a quotation from the statute.
Anyone who only falls under the act later also gets three months, counted from the point the conditions are met. Changes to reported details must be updated within two weeks or three months, depending on which detail changed (Section 29(4)).
Who it affects
Essential and important entities under Section 24 NISG 2026, plus domain name registration services. Size thresholds are in Section 25: large from 250 employees or over €50 million turnover and over €43 million balance sheet total; medium from 50 employees or over €10 million in both figures.
Example (fictional): The German parent, the Austrian subsidiary
A German machine builder has a sales and service subsidiary in Linz with 70 employees. In Germany, applicability has been assessed and documented under the BSIG. For Austria, nobody has done that — “the parent company already took care of it.”
But the Austrian entity has to be assessed on its own and registers itself. Anyone who only notices this in December has to pull together classification, details, and reporting channel in a few weeks. The same work, done three months earlier, would have been a calendar appointment instead.
The risks, plainly stated
Fine for late registration
A registration that's late or incorrect is punishable by a fine of up to €50,000 — up to €100,000 on repeat (Section 45(4)(1) NISG 2026). It's imposed by the district administrative authority, not the cybersecurity authority (Section 44).
Registration is only the start
Within twelve months of the registration duty arising, a structured self-declaration on implemented measures follows (Section 33(1)). Anyone who only starts at the deadline won't have the measures in place yet.
Management bodies are personally on the hook
Management bodies must ensure and oversee the measures, and must themselves attend cybersecurity training (Section 31 NISG 2026).
Your next steps
- 01Assess applicability separately for each Austrian entity (Sections 24, 25) and document it
- 02Compile the Section 29(2) details and designate a permanently reachable contact point
- 03Start on the Section 32 measures right after — the Section 33 self-declaration follows twelve months later
In Compliverse
The compass turns exactly these steps into measures in your plan automatically — with deadlines, owners, and evidence.
Plain-language product content, not legal advice · Case studies are fictional · Fine amounts as stated in the legal act (“up to”)