NISG 2026 · in force 1 October 2026
Five thousand entities are obliged. Ten times as many get asked.
Austria transposed the NIS2 Directive through the NISG 2026. Supplying essential or important entities means receiving their security requirements – by contract, not by statute.
The NISG 2026 was published in late 2025 and enters into force on 1 October 2026. It carries the NIS2 requirements into Austrian law: risk management measures, reporting duties, registration and management accountability.
The interesting figure is not in the statute. Against an estimated 5,000 directly covered entities stands a multiple of companies affected as suppliers. For a Swiss SME with Austrian customers that means the questionnaire arrives regardless of whether you fall in scope yourself.
Who is affected
- Essential and important entities in the covered sectors in Austria.
- Their suppliers and service providers, including those in Switzerland and Liechtenstein.
- Group companies with Austrian sites.
- Digital service providers operating in Austria.
What is required
- Risk management
- State-of-the-art measures with evidence of effectiveness.
- Supply chain
- Assess and govern security in relationships with direct suppliers.
- Reporting
- Staged reporting of significant incidents, with short initial deadlines.
- Registration
- Registration with the competent authority within the statutory period.
- Management
- Approval, oversight and training duties at management level.
How SCRM covers it
Customer demands as tasks
Who needs what evidence by when – with an owner instead of an inbox.
Security profile per supplier
Your own chain assessed, because the requirement travels onward.
Evidence with expiry
Certificates and declarations renewed before the customer asks.
Incident history
Reports and actions documented, in both directions of the chain.
Frequently asked
We are a Swiss supplier. Does the NISG affect us?
Not directly. Your Austrian customer must assess the security of its direct suppliers, and that assessment consists of questions to you.
What changed from the old NISG?
The population of covered entities is considerably larger, requirements are more concrete, and management bodies are explicitly accountable.
How does a supplier prepare?
With the details every questionnaire asks for: security organisation, certificates, reporting routes, subcontractors. Captured once in structure, reused thereafter.
As of July 2026. Not legal advice.