NIS2
NIS2 in Austria — the NISG 2026, guided.
The same obligations as in Germany, under Austrian law: classification, registration with the Bundesamt für Cybersicherheit, self-declaration.
Price
Price on request
Depends on which country or countries you implement NIS2 for — we calculate it together with you.
Request a quote →All prices plus VAT, flat per company, hosted in Germany, cancel monthly.
See bundles →Questions? Request a demo →What NIS2 requires of you.
Find out whether you're in scope, and at which tier — before anything else gets registered or reported.
Register with the competent national authority inside the statutory deadline.
Put all ten statutory minimum measures in place — from risk analysis to multi-factor authentication — each backed by dated evidence, not a checkbox.
Report incidents through the correct channel, at every stage the law requires: early warning, formal report, and follow-up.
In numbers, from our requirement catalogue
9
Requirements in the catalogue
10
Provisions checked against the statute text and backed by at least one measure in the catalogue
Every requirement carries a source, every one has at least one measure — checked by an automated catalogue test on every change. That's the foundation of our promise: audit-ready.
Austria's Network and Information System Security Act 2026 (NISG 2026 — Federal Law Gazette I No. 94/2025)
Competent authority
Bundesamt für Cybersicherheit (BFC) — Austria's Federal Office for Cyber Security
Classification: Section 24 NISG 2026, together with Section 25 (size classes) and Section 26 (classification by official notice) · Registration: Section 29 NISG 2026 — registration with the Bundesamt für Cybersicherheit
Reporting incidents: Section 34(2) NISG 2026 — reported to the Federal Office for Cyber Security (BfC)
Next deadlines
- NISG 2026 takes effect (Austria) — 01/10/2026 (derived)(§ 51 NISG 2026)
- NISG 2026: Austria registration deadline (BfC) — 31/12/2026 (derived)(§ 29 Abs. 3 NISG 2026)
- Austria: self-declaration on the measures implemented — 30/09/2027 (derived)(§ 33 Abs. 1 NISG 2026)
The ten minimum measures — same duty, your source citation
Risk analysis and information security policies
Section 32(4)(a) NISG 2026
Incident handling
Section 32(4)(b) NISG 2026
Business continuity — backup, disaster recovery, crisis management
Section 32(4)(c) NISG 2026
Supply chain security
Section 32(4)(d) NISG 2026
Security in acquisition, development and maintenance
Section 32(4)(e) NISG 2026
Effectiveness assessment
Section 32(4)(f) NISG 2026
Basic training and awareness measures
Section 32(4)(g) NISG 2026
Cryptographic procedures
Section 32(4)(h) NISG 2026
Personnel security, access control and management of ICT systems
Section 32(4)(i) NISG 2026
Multi-factor authentication and secure communications
Section 32(4)(j) NISG 2026
Named openly and honestly: The NISG 2026 doesn't name a CSIRT anywhere in the statutory text. Section 8 provides for the role to be assigned by administrative decision, and Section 51 lets the body currently handling it continue on a transitional basis until that happens. Confirm your actual reporting contact with the Bundesamt für Cybersicherheit before you need it — not in the middle of an incident.
One honest note: There is no official NIS2 certificate. Unlike ISO 27001, NIS2 is a regulatory obligation, not a certification scheme — no accredited body issues a "NIS2-certified" seal, and no vendor can honestly sell you one. What we deliver instead is audit-ready evidence: every requirement met, documented, and dated, so you can show a regulator or a large customer exactly how you meet the law.
NIS2 in Austria: frequently asked questions
What does the NIS2 in Austria module cost at Compliverse?
We don't publish a list price for this module — we calculate it with you, because scope, the number of companies and, for NIS2, the number of countries differ too much. You get a written quote with a fixed amount before anything starts. You can ask for one through the contact form; a sales call is not a precondition.
NIS2 in Austria: legal obligation or voluntary?
An obligation — though not for every company. Sector and size decide whether you are in scope (Section 24 NISG 2026, together with Section 25 (size classes) and Section 26 (classification by official notice)). No official notice arrives: you assess the classification yourself and register if it applies (Section 29 NISG 2026). Judging your individual case is a lawyer's job; we supply structure and evidence, not legal advice.
What does NIS2 in Austria actually require of us?
Find out whether you're in scope, and at which tier — before anything else gets registered or reported. Register with the competent national authority inside the statutory deadline. Put all ten statutory minimum measures in place — from risk analysis to multi-factor authentication — each backed by dated evidence, not a checkbox. Report incidents through the correct channel, at every stage the law requires: early warning, formal report, and follow-up.
How completely does Compliverse cover NIS2 in Austria?
Our catalogue holds 9 requirements for this framework. Each carries a legal source and each has at least one measure behind it — checked by an automated test on every change, not by good intentions. That is what "audit-ready" means for us: we do not guarantee that you end up compliant, because nobody can do that honestly. We guarantee that it is provable.
Which authority is responsible in Austria — and where do we report an incident?
Registration and supervision: Bundesamt für Cybersicherheit (BFC) — Austria's Federal Office for Cyber Security. Registering: Section 29 NISG 2026 — registration with the Bundesamt für Cybersicherheit. Reporting an incident: to the Federal Office for Cyber Security (BfC), under Section 34(2) NISG 2026. The incident assistant takes you there with the clock running.
Our promise
We don't say “compliant”. We say audit-ready — and we can prove it.
Nobody can guarantee that a company did everything right in an audit — not even a provider who promises it more confidently. What can be guaranteed is this. Four points, each independently verifiable.
01
Complete against the statute text
Every provision we cover has at least one requirement, every requirement at least one measure — and every one carries its source citation. That's not a promise: an automated test checks the catalogue on every change. If it finds a gap, the module doesn't ship.
→ Verifiable in each framework's requirement catalogue
02
Current, with a date
We re-read the legal texts in the original wording every month and update the product, training and website to match. Every check lands publicly in the change log — even when nothing changed.
→ Public change log on the Legal Landscape page
03
Evidenced, not asserted
Every requirement we mark as met has a document, certificate or log behind it — with a source citation and a legal-status date. What you can't hand an auditor doesn't count as done with us.
→ Evidence package as PDF, exportable at any time
04
Honest about the boundary
We provide structure, documents and evidence — not legal advice for your specific case. Where a question belongs with a lawyer, we say so instead of selling you something.
→ No legal advice — printed on every document
Last checked on 01/09/2026. That's how you get evidence that survives scrutiny — instead of a binder that falls apart at the first follow-up question.
What becomes important next
Legal Landscape
Deadline radar and change log — every update with a checked date.
To Legal Landscape →More modules
Legal status checked on 01/09/2026 · Every statement with a source · No legal advice