CTIPilot

Austria NISG 2026

policy · policy:austria-nisg-2026

Austria's NIS2-transposition law, in force 1 October 2026, creating the Bundesamt für Cybersicherheit (BCS) with 24h/72h incident-reporting obligations and active-scanning powers for essential/important entities (Austrian BMI press release, 2026-09-22).

Aliases: Netz- und Informationssystemsicherheitsgesetz 2026

Coverage timeline
1
first 2026-09-23 → last 2026-09-23
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
research
Co-occurring entities
3
see Co-occurring entities below
ATT&CK techniques
0
no mapped behavior yet

Hunting pivots

Tags

Story timeline

  1. 2026-09-23Austria's NISG 2026 creates the Bundesamt für Cybersicherheit, 24h/72h incident-reporting clock live 1 October 2026
    researchAustria stands up a new federal cybersecurity authority with 24h/72h reporting and active-scanning powers

Where this entity is cited

  • research1

Source distribution

  • heise.de1 (50%)
  • ots.at1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Austria NISG 2026 (1)

2026-09-23 · view entry permalink →

NOTABLENATOA1

Austria's NISG 2026 creates the Bundesamt für Cybersicherheit, 24h/72h incident-reporting clock live 1 October 2026

Austria's Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) (the country's NIS2 transposition, two years late) enters into force on 1 October 2026: "with the entry into force of the [NISG 2026], the new Federal Office for Cybersecurity (BCS) officially begins its work on 1 October 2026" (translated from German; Austrian Federal Ministry of the Interior, via OTS, 2026-09-22). The new Bundesamt für Cybersicherheit (BCS), under the Interior Ministry and led by former Austrian Power Grid CIO Markus Kasinger, becomes the central registration and supervision authority for "essential" and "important" entities across energy, transport, health, water, digital infrastructure, industry and food supply (municipalities excluded), takes over operation of the civilian-administration GovCERT, and gains oversight of sectoral CERTs (including the Austrian HealthCERT) and the general-economy CERT.at (heise online, 2026-09-22). Covered entities face a graduated reporting clock: "an initial early warning is required without delay, in any case within 24 hours of becoming aware of the incident. A more detailed notification must be made without delay, at the latest within 72 hours" (translated from German; Austrian BMI, via OTS, 2026-09-22), followed by further reports and a final report as the incident develops. The law also mandates security-awareness training for management and gives the BCS new powers to run active vulnerability scans against internet-facing systems of essential entities: "blocking or defending against such state scans is a criminal offence from 1 October, and affected essential entities must also actively cooperate on request" (translated from German; heise online, 2026-09-22). Enforcement and fines run through the competent district administrative authority rather than the BCS itself (heise online, 2026-09-22).

This continues the pattern already tracked for Finland's NCSC-FI CRA reporting checklist and Canton Bern's ICSG (also a 24h/72h reporting clock, entering force 1 November 2026) giving Swiss cantonal and federal authorities a further live comparator for reporting-obligation design as additional cantons stand up their own ICSG-equivalents.

With the entry into force of the Network and Information System Security Act 2026 (NISG 2026), the new Federal Office for Cybersecurity (BCS) officially begins its work on 1 October 2026.

An initial early warning is required without delay, in any case within 24 hours of becoming aware of the incident. A more detailed notification must be made without delay, at the latest within 72 hours.

Austrian Federal Ministry of the Interior (BMI), via OTS press release

Blocking or defending against such state scans is a criminal offence from 1 October, and affected essential entities must also actively cooperate on request.

heise online 2026-09-22
policy23 Sep 04:44Zmulti-sourceOpen finding ↗