From January 2026, the Network and Information Systems Security Act 2026 (NISG 2026) came into force in Austria. This represents a massive expansion of the requirements for cyber security and risk management. Reporting obligations have also become stricter under the NIS 2 Act. The NIS 2 audit comprises an organisational and a technical component to ensure compliance with the law by 1 October 2026. Organisations must assess for themselves whether they are affected.
However, there is one significant relief: companies that already hold certification to ISO 27001 (Information Security Management System) are automatically covered by the organisational part of the NIS-2 assessment and are spared the most time-consuming step!
Why obtain ISO 27001 certification now?
The deadlines for businesses are tight:
- Oct 2026
Obligations come into force
- December 2026
Registration completed
- September 2027
Self-declaration required
NISG 2026 requires an established risk management system. To establish this, organisations must first understand where their risks actually lie. This bespoke process takes time and depends heavily on the state of the art. A key difference between the new legislation and NIS-1 is that, under NIS-2, the ISMS scope covers the entire organisation concerned, not just individual departments – so more audits and a greater workload are to be expected!
Organisations that have already implemented ISO 27001 certification, or are in the process of doing so, have an advantage – as the organisational aspects align with the NIS-2 requirements.
Make sure that your certification partner is accredited – as only then is ISO 27001 recognised as evidence of the organisational assessment required under the NIS-2 Act. The technical audit (e.g. penetration tests) is separate from this and can be carried out independently.
Get started now, stay secure in the long term
So start implementing the measures now: if organisations fail to meet these deadlines, they face substantial fines. Furthermore, according to current standards, they will not meet the requirements for operating their day-to-day processes securely. This is because, in the event of cyber-attacks and operational failures, there is a risk of serious consequences if companies are not adequately prepared without an Information Security Management System (ISMS).
Take advantage of the opportunities offered by the new NIS-2 legislation: bring your information security up to date, remain competitive and meet regulatory requirements.
CIS Certification is the leading certification body for ISO 27001 (information security), ISO 22301 (business continuity) and the largest NIS auditor in Austria. As a qualified body, CIS Certification will automatically become an independent NIS auditor under NISG 2026 (independent body) from 1 October 2026.
Tip
Organisations that are still subject to NIS-1 must continue to carry out regular audits in 2026.
There is no automatic transition period! The CIS Certification team will be happy to assist you with any questions you may have regarding NIS-2.