NIS2 in Austria
NIS2 registration in Austria: by 1 January 2027
The NISG 2026 has applied since 1 October 2026. An essential or important entity registers with the Bundesamt für Cybersicherheit.
- Who
Wesentliche und wichtige Einrichtungen sowie Einrichtungen, die Domänennamen-Registrierungsdienste erbringen, müssen sich initial binnen drei Monaten nach Inkrafttreten des NISG 2026 registrieren und ihre jeweiligen Angaben aktuell halten.
Essential and important entities, and entities providing domain name registration services, register within three months of the NISG 2026 entering into force and keep their details current.- By when
Grundsätzlich bis 1. Jänner 2027, aufgrund § 33 Abs. 2 AVG bis spätestens 4. Jänner 2027 (drei Monate nach Inkrafttreten).
As a rule by 1 January 2027; under § 33 Abs. 2 AVG by 4 January 2027 at the latest (three months after entry into force).- Later
Spätestens drei Monate nach Erfüllung der Kriterien als wesentliche oder wichtige Einrichtung.
At the latest three months after meeting the criteria of an essential or important entity.
Bundesamt für Cybersicherheit, read on 4 October 2026
Why register early
The later date in the authority's sentence is not an extension. It only moves the last day past a public holiday and a weekend, when nobody at the office answers. Whoever has not registered by 1 January 2027 has no margin left.
The size question is yours to answer, not ours
When you register, you state yourself whether you are an essential or an important entity. We cannot see your headcount or your turnover, so we do not tell you whether you are in scope.
Informationen zu den in § 25 angeführten Schwellenwerten und darüber, ob es sich um eine wesentliche oder wichtige Einrichtung handelt.The registration includes the § 25 thresholds and whether the entity is essential or important.
After registering
Je nach Art der Angabe innerhalb von zwei Wochen oder drei Monaten.Depending on the detail, within two weeks or three months.
Security incidents
Wesentliche und wichtige Einrichtungen müssen erhebliche Cybersicherheitsvorfälle an das für sie zuständige Computer-Notfallteam melden. Dieses leitet die Meldungen anschließend an die Cybersicherheitsbehörde weiter.Essential and important entities report significant incidents to their competent CSIRT, which then forwards them to the cybersecurity authority.
- GovCERT
- HealthCERT
- CSIRT
das GovCERT für Einrichtungen der öffentlichen Verwaltung, das HealthCERT für den Gesundheitssektor sowie das nationale CSIRT mit allgemeiner Zuständigkeit.
GovCERT for public administration, HealthCERT for the health sector, and the national CSIRT with general competence. Reports under §§ 34 and 37 of the NISG 2026. A manufacturer reports to the national CSIRT.
Public administration
Public administration bodies cannot register yet. On the connection through the Portalverbund the authority writes: diese soll zeitnah nach dem 1. Oktober 2026 zur Verfügung gestellt werden.
(It is to be made available shortly after 1 October 2026.)
The NIS2 Registration Pack
A worksheet for the size question, the authority, portal and deadline for Austria, the CSIRT, an incident runbook, the ten Article 21(2) measures with the ISO/IEC 27001 records that show each, and the Article 20 management record.
Questions
- Does StandardOS register us?
- No. You file the registration yourself on the USP. The pack gives you the documents and the answers it asks for.
Read on 4 October 2026 with the Bundesamt für Cybersicherheit: Registration, Computer emergency response teams
StandardOS is a software tool. It is not a certification body, a law firm or a consultancy, and it cannot issue certificates. Certification comes from an accredited certification body you contract with separately.