NIS2 Directive

The NIS2 Directive is an EU cybersecurity rulebook succeeding the original NIS Directive, extending mandatory risk management and incident reporting duties to far more medium-sized and large companies across many sectors, not just to operators of critical infrastructure. Being a directive, it does not apply directly but through national implementing acts: in Austria that is the NISG 2026 (BGBl. I No. 94/2025), promulgated on 23 December 2025 and entering into force on 1 October 2026; until then the NISG 2018, which implemented the first NIS Directive, continues to apply.

In practice

It is worth checking whether your own company or sector falls within the extended scope of NIS2: Austria implements the directive through the NISG 2026, which applies from 1 October 2026 and introduces registration, self-declaration and reporting duties in stages. Those duties include regular risk assessments and the reporting of security incidents within tight deadlines. If you are unsure how your business is classified, seek clarification from a consultancy specialising in IT security law.

Sources

← Back to the glossary