{"id":9297,"date":"2026-08-31T14:28:41","date_gmt":"2026-08-31T12:28:41","guid":{"rendered":"https:\/\/atb.law\/?post_type=blog-post&#038;p=9297"},"modified":"2026-09-01T10:33:21","modified_gmt":"2026-09-01T08:33:21","slug":"nis2-in-austria-is-your-company-prepared","status":"publish","type":"blog-post","link":"https:\/\/atb.law\/en\/blog-post\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\/","title":{"rendered":"NIS2 in Austria: Is your company prepared?"},"content":{"rendered":"<h2 id=\"page-was-ist-nis2-und-warum-gibt-es-das-nisg-2026\"><strong>What is NIS2 and why is there the NISG 2026?<\/strong><\/h2>\n<p>Cyberattacks are no longer exceptional events. Ransomware, phishing, compromised credentials, or attacks via service providers can paralyze essential business processes within a very short time. The European NIS2 Directive is therefore intended to significantly increase cyber resilience in the European Union and, in particular, improve the ability of companies and public institutions to prevent, manage, and respond to security incidents.<\/p>\n<p>Austria is implementing these requirements with the NISG 2026.<\/p>\n<p>While the previous NISG 2018 covers only a comparatively small circle of companies, the scope of application is now being significantly expanded. Around 4,000 companies and institutions in Austria are expected to be directly affected.<\/p>\n<p>Depending on the activity and company size, this includes companies from the energy, transport, health, drinking water and wastewater, digital infrastructure, ICT services, postal and courier services, waste management, chemicals, food production, manufacturing, digital services, and research sectors, among others.<\/p>\n<p>Even companies that do not fall directly under the NISG 2026 can be indirectly affected: supply chain security is an explicit part of mandatory risk management. NIS2-relevant companies will therefore increasingly involve their service providers and suppliers in their cybersecurity requirements.<\/p>\n<h2 id=\"page-1-oktober-2026-ab-dann-mussen-die-zentralen-pflichten-erfullt-sein\"><strong>October 1, 2026: The central obligations must be fulfilled by then<\/strong><\/h2>\n<p>A particularly important point is currently often overlooked: there is no general transition period after October 1, 2026, for the core obligations. As of this date, affected companies must, in particular, comply with the prescribed risk management measures and observe the statutory reporting obligations for significant cybersecurity incidents. The fact that later deadlines are provided for other obligations\u2014in particular for registration and self-declaration\u2014does not change this.<\/p>\n<p>Anyone who only begins implementation on October 1st is therefore starting too late.<\/p>\n<h2 id=\"page-geschaftsleitung-muss-ebenfalls-geschult-sein\"><strong>Management must also be trained\u00a0<\/strong><\/h2>\n<p>Particularly relevant for the remaining weeks: Section 31 Paragraph 2 of the NISG 2026 provides for a separate training obligation for management bodies. And a general cyber-awareness training for employees is not sufficient for this.<\/p>\n<p>Managing directors and board members must participate in cybersecurity training specifically designed for governing bodies. The specific aim is to provide them with the knowledge they need to assess cyber risks and fulfill their legal responsibility for risk management. Participation should be documented accordingly.<\/p>\n<p>In the case of multiple managing directors, it is also not sufficient to train only the managing director responsible for IT. The training obligation fundamentally applies to every member of the management body. For companies that have not yet trained their management accordingly, this item should therefore be at the top of the September agenda.<\/p>\n<h2 id=\"page-welche-nis2-pflichten-mussen-unternehmen-konkret-umsetzen\"><strong>What specific NIS2 obligations do companies have to implement?<\/strong><\/h2>\n<p>Key measures include, in particular:<\/p>\n<ul>\n<li><strong>Risk analysis and information security:<\/strong> Companies need concepts for analyzing their cyber risks and ensuring the security of their network and information systems\u2014including clear roles, responsibilities, and accountabilities.<\/li>\n<li><strong>Incident Response:<\/strong> Processes must be in place to detect, assess, contain, and manage cybersecurity incidents.<\/li>\n<li><strong>Business Continuity and Crisis Management:<\/strong> This includes, in particular, backup management, recovery processes, and emergency and crisis plans.<\/li>\n<li><strong>Supply chain security:<\/strong> Cyber risks at immediate suppliers and service providers must also be considered.<\/li>\n<li><strong>Security of IT systems:<\/strong> Security requirements must be taken into account during the acquisition, development, and maintenance of network and information systems. This also includes the handling of vulnerabilities.<\/li>\n<li><strong>Verification of effectiveness:<\/strong> Companies must establish procedures to verify whether their security measures actually work.<\/li>\n<li><strong>Cyber hygiene and training:<\/strong> Employees must be regularly sensitized and trained. For management bodies, separate training requirements apply\u2014as outlined.<\/li>\n<li><strong>Cryptography and encryption:<\/strong> Companies must provide appropriate concepts and procedures, insofar as this is necessary.<\/li>\n<li><strong>Access and authorization management:<\/strong> Personnel security, access controls, and IT asset management must be regulated in a structured manner.<\/li>\n<li><strong>Multi-Factor Authentication and Secure Communication:<\/strong> Where necessary, solutions for multi-factor or continuous authentication as well as secure communication systems must be used in particular.<\/li>\n<\/ul>\n<p>Which specific measures are appropriate depends on the respective company and its risk profile. In particular, the state of the art, exposure to risk, the size of the company, and the probability and potential impact of a security incident must be taken into account.<\/p>\n<h2 id=\"page-der-ernstfall-24-stunden-konnen-plotzlich-sehr-kurz-sein\"><strong>The emergency: 24 hours can suddenly be very short<\/strong><\/h2>\n<p>However, NIS2 is not only concerned with how cyberattacks should be prevented. Companies must also be organizationally prepared to, <strong>if an attack actually happens<\/strong>.<\/p>\n<p>In the event of a significant cybersecurity incident, NISG 2026 provides for a multi-stage reporting procedure. An initial early warning generally must <strong>immediately and within 24 hours<\/strong> take place. Within <strong>72 hours<\/strong> Another report containing an initial assessment of the incident and its impact will follow. As a rule, a final report is planned no later than one month after the early warning.<\/p>\n<p>These short deadlines in particular demonstrate why incident response cannot be organized only during a ransomware attack. Organizations should already know before an incident: Who decides? Who informs executive management? Who communicates with IT forensics experts, authorities, insurance companies, and external consultants? What reporting obligations exist under the NISG 2026 \u2013 and is there simultaneously a data breach that must be reported under the GDPR?<\/p>\n<h2 id=\"page-welche-fristen-sollten-unternehmen-jetzt-kennen\"><strong>Which deadlines should companies know about now?<\/strong><\/h2>\n<p>The <strong>October 1, 2026<\/strong> is the crucial operational deadline: From this point on, risk management measures and reporting obligations in particular will apply; the responsibilities and training obligations of the management bodies must also be observed.<\/p>\n<p>Further deadlines will follow. The registration of essential and important entities must take place within three months, and thus by the end of December 2026. The self-declaration regarding the implemented risk management measures must then be submitted within the period stipulated by law. However, these later verification and registration dates must not be confused with a transition period for the actual cybersecurity obligations.<\/p>\n<h2 id=\"page-was-sollten-unternehmen-im-september-noch-erledigen\"><strong>What else should companies take care of in September?<\/strong><\/h2>\n<p>The remaining month should be used for a targeted <strong>NIS2 Readiness Check<\/strong> be used.<\/p>\n<p>First, it must be clarified whether and in which category the company is covered by the NISG 2026. Subsequently, it should be checked which of the required technical, organizational, and legal measures have already been implemented and documented, and where gaps still exist.<\/p>\n<p>Special attention should be paid to governance: Are responsibilities defined? Are incident response and reporting processes established? Has the supply chain been considered? Are the necessary training programs in place?<\/p>\n<p>And above all: <strong>Have all members of the executive management already been trained to be NIS2-compliant?<\/strong><\/p>\n<p>Because starting October 1, 2026, cybersecurity will finally no longer be just an IT issue. It will become a management responsibility.<\/p>\n<h2 id=\"page-nis2-umsetzung-und-schulung-der-leitungsorgane\"><strong>NIS2 implementation and training of management bodies<\/strong><\/h2>\n<p>We support companies with the legal implementation of the NISG 2026 \u2013 from checking applicability and a NIS2 gap analysis to governance, internal guidelines, and incident response processes, as well as preparation for reporting obligations and cyber emergencies.<\/p>\n<p>A special focus is on <strong>practice-oriented NIS2 training courses for managing directors and board members<\/strong>. This is not about turning governing bodies into IT security experts. Rather, they need to understand, <strong>what responsibility they bear, what decisions they must make, how they can tell whether their company is actually prepared for a cyberattack, and what potential liabilities they may face if statutory requirements are not met.\u00a0<\/strong><\/p>\n<p>For individual advice, you are <a href=\"https:\/\/atb.law\/en\/anela-bloech\/\">Anela Bl\u00f6ch<\/a> and your team at the phone number <a href=\"tel:+4313912345\">01 3912345<\/a> or by email <a href=\"mailto:office@atb.law\">bloech@atb.law<\/a> happy to help.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><\/p>","protected":false},"template":"","categories":[32],"class_list":["post-9297","blog-post","type-blog-post","status-publish","has-post-thumbnail","hentry","category-compliance"],"acf":[],"post-kategorie":"32","_post-kategorie":"field_66d947537140a","post-kurzbeschreibung":"Der NIS2-Countdown l\u00e4uft: Ab 1. Oktober 2026 m\u00fcssen betroffene Unternehmen die zentralen Vorgaben des NISG 2026 erf\u00fcllen. Welche Pflichten jetzt umgesetzt sein m\u00fcssen, warum Cybersecurity zur Aufgabe der Gesch\u00e4ftsleitung wird und weshalb Gesch\u00e4ftsf\u00fchrer und Vorst\u00e4nde rechtzeitig geschult werden m\u00fcssen.","_post-kurzbeschreibung":"field_66d949fe1efe2","post-beitragsbild":"8649","_post-beitragsbild":"field_66d94a4a1efe3","post-author_post-author-name":"Anela Bl\u00f6ch","_post-author_post-author-name":"field_66d94a801efe5","post-author_post-author-foto":"7314","_post-author_post-author-foto":"field_66d94aa11efe6","post-author":"","_post-author":"field_66d94ee2827ca","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NISG 2026: Was Unternehmen jetzt noch umsetzen m\u00fcssen<\/title>\n<meta name=\"description\" content=\"Ab 1. Oktober 2026 gilt das NISG 2026. Welche NIS2-Pflichten Unternehmen jetzt umsetzen m\u00fcssen und warum Gesch\u00e4ftsf\u00fchrer und Vorst\u00e4nde geschult sein m\u00fcssen.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/atb.law\/en\/blog-post\/nis2-in-austria-is-your-company-prepared\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NISG 2026: Was Unternehmen jetzt noch umsetzen m\u00fcssen\" \/>\n<meta property=\"og:description\" content=\"Ab 1. Oktober 2026 gilt das NISG 2026. Welche NIS2-Pflichten Unternehmen jetzt umsetzen m\u00fcssen und warum Gesch\u00e4ftsf\u00fchrer und Vorst\u00e4nde geschult sein m\u00fcssen.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/atb.law\/en\/blog-post\/nis2-in-austria-is-your-company-prepared\/\" \/>\n<meta property=\"og:site_name\" content=\"ATB.LAW\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-01T08:33:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/atb.law\/wp-content\/uploads\/2026\/05\/088A5635-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1708\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\\\/\",\"url\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\\\/\",\"name\":\"NISG 2026: Was Unternehmen jetzt noch umsetzen m\u00fcssen\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/088A5635-scaled.jpg\",\"datePublished\":\"2026-08-31T12:28:41+00:00\",\"dateModified\":\"2026-09-01T08:33:21+00:00\",\"description\":\"Ab 1. Oktober 2026 gilt das NISG 2026. Welche NIS2-Pflichten Unternehmen jetzt umsetzen m\u00fcssen und warum Gesch\u00e4ftsf\u00fchrer und Vorst\u00e4nde geschult sein m\u00fcssen.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/atb.law\\\/blog-post\\\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\\\/#primaryimage\",\"url\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/088A5635-scaled.jpg\",\"contentUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/088A5635-scaled.jpg\",\"width\":2560,\"height\":1708,\"caption\":\"ATB Law TRCN Mad(e) for Krypto\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/atb.law\\\/blog-post\\\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/atb.law\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NIS2 in \u00d6sterreich: Ist Ihr Unternehmen vorbereitet?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/atb.law\\\/#website\",\"url\":\"https:\\\/\\\/atb.law\\\/\",\"name\":\"atb Rechtsanw\u00e4lte\",\"description\":\"Rechtsanwaltskanzlei in Wien\",\"publisher\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/atb.law\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/atb.law\\\/#organization\",\"name\":\"atb Rechtsanw\u00e4lte\",\"url\":\"https:\\\/\\\/atb.law\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/atb.law\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/ATB_Rechtsanwaelte_site-logo-beige.png\",\"contentUrl\":\"https:\\\/\\\/atb.law\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/ATB_Rechtsanwaelte_site-logo-beige.png\",\"width\":1572,\"height\":1110,\"caption\":\"atb Rechtsanw\u00e4lte\"},\"image\":{\"@id\":\"https:\\\/\\\/atb.law\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NISG 2026: What companies still need to implement","description":"Starting October 1, 2026, the NISG 2026 will apply. Which NIS2 obligations companies must implement now and why managing directors and board members must be trained.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/atb.law\/en\/blog-post\/nis2-in-austria-is-your-company-prepared\/","og_locale":"en_US","og_type":"article","og_title":"NISG 2026: Was Unternehmen jetzt noch umsetzen m\u00fcssen","og_description":"Ab 1. Oktober 2026 gilt das NISG 2026. Welche NIS2-Pflichten Unternehmen jetzt umsetzen m\u00fcssen und warum Gesch\u00e4ftsf\u00fchrer und Vorst\u00e4nde geschult sein m\u00fcssen.","og_url":"https:\/\/atb.law\/en\/blog-post\/nis2-in-austria-is-your-company-prepared\/","og_site_name":"ATB.LAW","article_modified_time":"2026-09-01T08:33:21+00:00","og_image":[{"width":2560,"height":1708,"url":"https:\/\/atb.law\/wp-content\/uploads\/2026\/05\/088A5635-scaled.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/atb.law\/blog-post\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\/","url":"https:\/\/atb.law\/blog-post\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\/","name":"NISG 2026: What companies still need to implement","isPartOf":{"@id":"https:\/\/atb.law\/#website"},"primaryImageOfPage":{"@id":"https:\/\/atb.law\/blog-post\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\/#primaryimage"},"image":{"@id":"https:\/\/atb.law\/blog-post\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\/#primaryimage"},"thumbnailUrl":"https:\/\/atb.law\/wp-content\/uploads\/2026\/05\/088A5635-scaled.jpg","datePublished":"2026-08-31T12:28:41+00:00","dateModified":"2026-09-01T08:33:21+00:00","description":"Starting October 1, 2026, the NISG 2026 will apply. Which NIS2 obligations companies must implement now and why managing directors and board members must be trained.","breadcrumb":{"@id":"https:\/\/atb.law\/blog-post\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/atb.law\/blog-post\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/atb.law\/blog-post\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\/#primaryimage","url":"https:\/\/atb.law\/wp-content\/uploads\/2026\/05\/088A5635-scaled.jpg","contentUrl":"https:\/\/atb.law\/wp-content\/uploads\/2026\/05\/088A5635-scaled.jpg","width":2560,"height":1708,"caption":"ATB Law TRCN Mad(e) for Krypto"},{"@type":"BreadcrumbList","@id":"https:\/\/atb.law\/blog-post\/nis2-in-oesterreich-ist-ihr-unternehmen-vorbereitet\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/atb.law\/"},{"@type":"ListItem","position":2,"name":"NIS2 in \u00d6sterreich: Ist Ihr Unternehmen vorbereitet?"}]},{"@type":"WebSite","@id":"https:\/\/atb.law\/#website","url":"https:\/\/atb.law\/","name":"atb Attorneys at Law","description":"Law firm in Vienna","publisher":{"@id":"https:\/\/atb.law\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/atb.law\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/atb.law\/#organization","name":"atb Attorneys at Law","url":"https:\/\/atb.law\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/atb.law\/#\/schema\/logo\/image\/","url":"https:\/\/atb.law\/wp-content\/uploads\/2024\/05\/ATB_Rechtsanwaelte_site-logo-beige.png","contentUrl":"https:\/\/atb.law\/wp-content\/uploads\/2024\/05\/ATB_Rechtsanwaelte_site-logo-beige.png","width":1572,"height":1110,"caption":"atb Rechtsanw\u00e4lte"},"image":{"@id":"https:\/\/atb.law\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/blog-post\/9297","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/blog-post"}],"about":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/types\/blog-post"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/media\/8649"}],"wp:attachment":[{"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/media?parent=9297"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/atb.law\/en\/wp-json\/wp\/v2\/categories?post=9297"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}