2026-09-23 · view entry permalink →
Austria's NISG 2026 creates the Bundesamt für Cybersicherheit, 24h/72h incident-reporting clock live 1 October 2026
Austria's Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) (the country's NIS2 transposition, two years late) enters into force on 1 October 2026: "with the entry into force of the [NISG 2026], the new Federal Office for Cybersecurity (BCS) officially begins its work on 1 October 2026" (translated from German; Austrian Federal Ministry of the Interior, via OTS, 2026-09-22). The new Bundesamt für Cybersicherheit (BCS), under the Interior Ministry and led by former Austrian Power Grid CIO Markus Kasinger, becomes the central registration and supervision authority for "essential" and "important" entities across energy, transport, health, water, digital infrastructure, industry and food supply (municipalities excluded), takes over operation of the civilian-administration GovCERT, and gains oversight of sectoral CERTs (including the Austrian HealthCERT) and the general-economy CERT.at (heise online, 2026-09-22). Covered entities face a graduated reporting clock: "an initial early warning is required without delay, in any case within 24 hours of becoming aware of the incident. A more detailed notification must be made without delay, at the latest within 72 hours" (translated from German; Austrian BMI, via OTS, 2026-09-22), followed by further reports and a final report as the incident develops. The law also mandates security-awareness training for management and gives the BCS new powers to run active vulnerability scans against internet-facing systems of essential entities: "blocking or defending against such state scans is a criminal offence from 1 October, and affected essential entities must also actively cooperate on request" (translated from German; heise online, 2026-09-22). Enforcement and fines run through the competent district administrative authority rather than the BCS itself (heise online, 2026-09-22).
This continues the pattern already tracked for Finland's NCSC-FI CRA reporting checklist and Canton Bern's ICSG (also a 24h/72h reporting clock, entering force 1 November 2026) giving Swiss cantonal and federal authorities a further live comparator for reporting-obligation design as additional cantons stand up their own ICSG-equivalents.
With the entry into force of the Network and Information System Security Act 2026 (NISG 2026), the new Federal Office for Cybersecurity (BCS) officially begins its work on 1 October 2026.
An initial early warning is required without delay, in any case within 24 hours of becoming aware of the incident. A more detailed notification must be made without delay, at the latest within 72 hours.
Blocking or defending against such state scans is a criminal offence from 1 October, and affected essential entities must also actively cooperate on request.