Since the start of the year, the Network and Information SystemsSecurity Act 2026 (NISG 2026) has come into force in Austria. The requirements regarding cyber security, risk management and reporting obligations have been significantly expanded and present new challenges for information security officers, IT managers and decision-makers.
Larger organisations, longer implementation period
To successfully implement the NISG 2026, companies generally need around nine months; in the quickest case, six months. The larger the company, the longer implementation takes. All necessary technical, organisational and documentary measures must be in place by 1 October 2026. This means that audit dates must also be scheduled well in advance – we recommend consulting your certification partner as soon as possible!
Multiple sites? Implement NISG 2026 swiftly regardless
With multi-site certification – that is, certification covering multiple sites and companies – you not only save time and money, but also secure a number of benefits. By using a sampling procedure, multiple sites and/or companies can be audited.
The ISO 27001 for information security management covers the organisational part of the NISG 2026 audit for organisations of all sizes. For large organisations, this can be obtained as a multi-site certification in accordance with the IAF (International Accreditation Forum).
Your benefits:
- Centralised management for an organisation with multiple sites or subsidiaries
- Cost and effort savings without compromising on regulatory compliance
- Reduced audit workload through sampling and clustering of similar units
- The scope can be easily extended to include new sites or companies
- Random audits instead of full audits of all sites
The NISG 2026 brings not only obligations but also benefits: Large companies in particular know, thanks to the audit, exactly where action is currently needed and where investments must be made to ensure future viability.
Start implementing the requirements now: Those who fail to meet the deadlines not only risk heavy fines but, under current standards, are also unable to operate securely – which could have disastrous consequences for domestic companies. A key difference between the new law and its predecessor, NIS-1, is that the scope of the NISG 2026 (NIS-2) covers the entire organisation concerned and no longer just individual departments – accordingly, more audits and a greater workload are to be expected.
CIS Certification GmbH was selected as early as 2018 by the Ministry of Economic Affairs to carry out NISG audits, making it Austria’s most experienced NIS audit body. CIS’s extensive experience, expertise and pragmatic approach ensure that your NISG 2026 audit is carried out efficiently and correctly. We look forward to receiving your enquiry!
Tip: Organisations still subject to NIS-1 must continue to carry out regular audits in 2026. There is no automatic transition period! The CIS Certification team will be happy to assist you with any questions regarding NISG 2026.