Majority of domestic companies not NIS-2 ready

With the Network and Information Security Act 2026 (NISG 2026), Austria is implementing the EU’s NIS 2 Directive. The new obligations will come into full effect on 1 October 2026 – failure to comply could result in fines running into millions. The domestic NIS 2 certification body, CIS Certification, is now warning that many companies are not yet sufficiently prepared and is issuing clear recommendations for action.

When the transition period for the new Cybersecurity Act (NISG 2026) ends on 1 October 2026, failure to comply could result in fines running into millions. Although many companies are currently in the preparatory phase, we warn that implementation is progressing too slowly. Studies show that a significant proportion of domestic companies misjudge the extent to which they are affected or underestimate the effort required for implementation. SMEs, in particular, often do not feel affected, yet the NISG 2026 applies to organisations with as few as 50 employees or an annual turnover of ten million euros. Furthermore, smaller companies may be affected via the supply chain.

. “Compared with the previous NIS regulations, the new law covers significantly more companies. Furthermore, under the new regulations, the responsibility for self-assessment lies with the companies themselves. This means that every legal entity must check for itself whether it falls under NIS-2 and actively register with the competent authority,”

explains Thomas Mann, Managing Director of CIS – Certification & Information Security Services GmbH. The expert estimates that in Austria, 3,500 to 5,000 companies are directly affected and a further 50,000 are indirectly affected via supply chains or service relationships. “Companies that have already implemented information security management systems such as ISO 27001 have a clear advantage. This is because they already cover the entire organisational part of the 2026 NISG audit,” says Mann.

With the following list, CIS Certification answers the most important questions about the new NIS 2 Act:

 

1.) Which organisations are affected by NIS 2?

In addition to traditional critical infrastructure (energy, transport, healthcare, etc.), other economically significant sectors (retail, manufacturing, food supply, IT service providers, etc.) now also fall under the NIS-2 Act. Furthermore, legal entities with an annual turnover of ten million euros or more, or at least 50 employees, are affected. For smaller companies, the NISG may become binding in 2026 if they fall within a specific scope of application as service providers or suppliers via the supply chain, or as trust service providers.

 

2.) Who within organisations is responsible for implementation?

Implementing the directive requires time, resources and staff. Ideally, a Chief Information Security Officer (CISO) within the organisation should be responsible for implementation and should involve all departments. This is because the new legislation affects not only IT departments but, as a complex cross-functional matter, the entire organisation. To meet the legislative requirements, all areas of the organisation must be involved.

 

3.) What obligations must affected companies fulfil?

The core requirements can be divided into four areas: risk management, reporting obligations, registration and reporting, and supply chain security. Specifically, companies must implement a documented, continuously monitored risk management system by 1 October 2026. Cyber incidents that could have a significant impact must then be reported within 24 hours. “Affected companies must actively register with the Austrian Cybersecurity Authority. It should be noted that risk management must be ensured throughout the entire supply chain and that suppliers must demonstrably meet security requirements,” emphasises CIS Certification Managing Director Thomas Mann.

 

4.) What penalties apply in the event of non-compliance?

Supervision is the responsibility of the Federal Office for Cyber Security (BMI), which handles registrations, audits and the analysis of reports, and reports to EU agencies such as ENISA. Breaches of NIS-2 can be very costly: particularly critical enterprises face fines of up to ten million euros or two per cent of their global annual turnover. Furthermore, enterprises that have not established an information security management system risk security incidents, critical business interruptions and, consequently, the disruption of their own business operations.

 

5.) Which management systems or certifications does the NISG 2026 refer to?

Frameworks such as ISO 27001 can be used to create a solid foundation for compliance with cybersecurity measures. This is because organisations that have already implemented an information security management system (ISO 27001) automatically fulfil the organisational part of the NIS-2 assessment.

 

6.) When does the implementation deadline end?

The NISG 2026 will come into full effect on 1 October 2026. This means that organisations only have until 30 September to assess their compliance status and subsequently implement all necessary measures. CIS Certification assists organisations and corporate groups of all sizes in preparing an independent NIS 2 audit report and offers bespoke training for senior management. To give you an initial overview, we have put together a checklist for you.

Our NIS-2 training and further education courses – find out more now!

Whether you’re just starting out, are already well versed in the subject and wish to capitalise on the synergies offered by ISO 27001 certification, or whether you need top-level guidance on implementation – we have the right training programme for you:

Our services for businesses

We’re here to help!