NIS 2 — Austria
NIS 2 IN AUSTRIA
Netz- und Informationssystemsicherheitsgesetz 2024 (NISG 2024) — the national act transposing Directive (EU) 2022/2555 in Austria. Supervised by Bundesministerium für Inneres (BMI).
DRAFT PUBLISHED
Key facts
In force
Not yet in force
Primary supervisor
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities register through the BMI's NIS 2 portal; deadlines follow the law's entry into force as set by the implementing regulation.
Scope and national nuance
Austria's NISG 2024 builds on the original NISG framework. The Bundesministerium für Inneres (BMI) is the policy and supervisory lead, with GovCERT Austria operating as the public-sector CSIRT and CERT.at as the national CSIRT for the wider economy.
Sector supervisors
| Sector | Authority | Acronym |
|---|---|---|
| National CSIRT and computer emergency response | GovCERT Austria | GovCERT |
| General CERT for the Austrian economy | Austrian Computer Emergency Response Team | CERT.at |
| Energy and electronic communications | Rundfunk- und Telekom-Regulierungs-GmbH | RTR |
What is specific to Austria
- Austria operates a two-CSIRT model — GovCERT Austria handles government and critical infrastructure of the state, CERT.at handles the broader economy — covered entities should know which one is their reporting partner.
- The BMI is the central national competent authority, which is unusual at EU level — most member states locate this function in a digital ministry or independent agency rather than the interior ministry.
- Austria's earlier NIS law already brought a substantial set of operators of essential services into scope — the NIS 2 transposition broadens rather than replaces this framework.
- Federal coordination with the Bundesländer is required for entities operating across regional boundaries; the BMI manages this through the existing crisis-coordination architecture.
DSI Advisory — NIS 2 Programme
Move from reading the law to evidencing compliance
Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to BMI’s supervisory expectations.