How to Register with Austria’s NIS2 Competent Authority on nis.gv.at — and Which Sector Authority Regulates Your Industry
The NIS2 Directive required every EU member state to designate a competent authority by October 2024. Austria missed that deadline — the European Commission sent a reasoned opinion for non-transposition on 7 May 2025. [1] The NISG 2026 was promulgated on 23 December 2025, establishing the Bundesamt für Cybersicherheit as Austria’s first dedicated federal cybersecurity authority. The law enters into force on 1 October 2026, giving approximately 4,000 entities three months to register via nis.gv.at before the 31 December 2026 deadline. [8]
The Bundesamt für Cybersicherheit does not regulate all sectors directly. E-Control oversees energy operators, the FMA covers financial institutions, RTR handles telecommunications providers, and GovCERT serves public administration — each holding direct supervisory jurisdiction over NIS2 obligations in their domain. Which authority regulates your organisation determines where you report incidents, who can audit you, and who issues enforcement orders.
This guide maps the full authority structure, explains how nis.gv.at registration works, and clarifies which of Austria’s three incident reporting portals your organisation should use.
What NISG 2026 Created — Austria’s First Dedicated Cybersecurity Authority
Before NISG 2026, Austria’s NIS1 compliance framework distributed authority across two bodies. The Federal Chancellery held designation as national competent authority (NCA) for operators of essential services and digital service providers, while the Federal Ministry of the Interior (BMI) served as the Single Point of Contact (SPOC) — Austria’s liaison for EU cross-border coordination. The SPOC contact was, and remains, post@nis.gv.at.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
NISG 2026 replaces this split structure. The Bundesamt für Cybersicherheit (Federal Cybersecurity Office) is established as an independent authority, reporting directly to the Federal Minister of the Interior but sitting outside the Directorate General for Public Security. This arrangement keeps it at arm’s length from police and internal security functions while anchoring cybersecurity regulation firmly within the Interior Ministry’s portfolio.
Three coordination structures operate under the Bundesamt:
- Cyber Security Steering Group (CSS): The strategic tier — convenes sector ministries to align national cybersecurity policy and set priorities.
- Inner Circle of Operational Coordination: Tactical inter-agency alignment for active threat campaigns and cross-sector response.
- Operational Coordination Structure: Incident-level response, activated when a significant incident crosses sector boundaries or requires multi-authority involvement.
The Bundesamt’s director and deputy director must hold relevant academic qualifications and pass regular security clearances. A transparency provision in NISG 2026 requires that any ministerial directive issued to the Bundesamt must be “written, justified, and published semi-annually” — an accountability standard uncommon among EU member states. [6]
Under Article 8 of the NIS2 Directive, member states must ensure their NCAs have adequate resources and must notify the European Commission of any NCA changes. [2] The European Commission’s official records currently list the Federal Chancellery and BMI as Austria’s co-designated authorities, reflecting the NIS1 structure. These designations will be updated once the Bundesamt assumes its role on 1 October 2026. [1]
Sector-Specific Competent Authorities — Who Regulates Your Industry
The Bundesamt für Cybersicherheit coordinates Austria’s national NIS2 supervision, but does not cover every sector directly. NISG 2026 preserves the supervisory mandates of six sector regulators, each holding primary jurisdiction over NIS2 obligations for entities in their domain.
| Sector | Competent Authority | Incident Reporting Portal |
|---|---|---|
| Energy | E-Control | nis.energy-cert.at |
| Finance and capital markets | FMA (Austrian Financial Market Authority) | nis.cert.at |
| Telecommunications | RTR (Rundfunk und Telekom Regulierungs-GmbH) | nis.cert.at |
| Healthcare | BMG / BMK (Federal Ministry of Health / Climate Action) | nis.cert.at |
| Public administration | GovCERT Austria | nis.govcert.gv.at |
| All other Annex I and Annex II sectors | Bundesamt für Cybersicherheit | nis.cert.at |
The coordination model matters for organisations operating across sectors. An energy distribution operator that also provides managed IT services falls under both E-Control (energy sector supervision) and the Bundesamt (general NIS2 obligations). Article 8 of the Directive obliges member states to ensure cross-sectoral cooperation between competent authorities to prevent conflicting obligations. [2]
Financial entities subject to DORA (the Digital Operational Resilience Act, which entered into force on 17 January 2025) face an additional layer. The FMA supervises both NIS2 and DORA obligations for financial institutions, but the two regimes use different reporting channels and documentation requirements. DORA’s ICT risk management framework (Articles 5–15) covers significant ground similar to NIS2 Article 21, but the two are not identical. Entities in financial services should map which DORA obligations are additive before the NISG 2026 registration deadline rather than assuming full equivalence.
CERT.at, GovCERT, and Austria’s Three Incident Reporting Portals
Austria’s CSIRT structure is not a single organisation — it is three separate bodies, each with a dedicated incident reporting portal. Submitting a report to the wrong portal creates a procedural delay that risks missing the 24-hour early warning deadline under NISG 2026.
Under Article 10 of the NIS2 Directive, national CSIRTs must handle incidents through a well-defined process, maintain secure communication infrastructure, and participate in the EU-wide CSIRT network. [3] Austria designates three bodies to collectively meet this requirement.
CERT.at is the default CSIRT for essential service operators and digital service providers across most Annex I and Annex II sectors. Unusually for an EU national CSIRT, CERT.at operates as a daughter company of nic.at GmbH — a privately-held internet registry. This makes it a private entity operating under a public mandate, an arrangement uncommon among EU member states. Incidents go to reports@cert.at or via the reporting portal at nis.cert.at, with emergency contact at +43 1 5056416 78. [10]
GovCERT Austria handles public administration entities. Its incident portal is nis.govcert.gv.at, with reports addressed to reports@govcert.gv.at. Under NISG 2026, GovCERT also temporarily assumes national CSIRT coordination tasks while the formal national CSIRT designation under the new law is finalised — making it both a sector CSIRT and a transitional coordination hub.
AEC (Austrian Energy CERT) is the sector CSIRT for the energy sector. Energy-sector entities under E-Control’s supervision route all NIS2 incident notifications through AEC at nis.energy-cert.at (reports@energy-cert.at), not through CERT.at. This is the single most common routing error in practice: energy operators defaulting to CERT.at when they should use AEC.
The notification timeline is identical across all three portals: early warning within 24 hours, full incident notification within 72 hours, and a final report within one month. The nis.gv.at portal links to all three platforms and provides sector-specific guidance. [9] For full details on notification obligations, see the NIS2 incident reporting guide.
How to Register on nis.gv.at — Requirements, Data, and Deadline
The nis.gv.at portal is Austria’s NIS Anlaufstelle (contact point), operated by the BMI as SPOC. All essential and important entities must complete initial registration via this portal by 31 December 2026. There is no registration fee. [8]
What registration requires:
- Entity identification: Legal name, registered address, and legal form.
- Sector classification: Which Annex I or Annex II sector under NISG 2026 applies. Entities operating across multiple sectors register each applicable one.
- Designated point of contact: Name, role, and direct contact details for the person responsible for NIS2 compliance at your organisation.
- IP address ranges: The IP address blocks used by the entity in covered network and information systems.
- Cross-border services indicator: Whether the entity provides services to other EU member states — required for SPOC coordination under Article 8 of the Directive. [2]
Scope check before you register:
NISG 2026 applies to entities that meet both criteria: (a) operate in one of the 18 sectors listed in Annexes I/II, and (b) meet the size threshold — ≥50 employees, OR annual turnover and balance sheet total both exceeding €10 million. DNS operators, top-level domain name registries, and trust service providers are captured regardless of size. [12] To verify whether your organisation falls within scope, use the NIS2 scope guide.
Failure to register by 31 December 2026 carries an administrative fine of up to €50,000 — and up to €100,000 for repeated violations. [7][12] Registration is the entry point to the supervisory regime, but does not substitute for the self-declaration requirement. Within 12 months of the registration obligation arising — by 30 September 2027 — entities must also file a self-declaration confirming implementation of risk-management measures under Article 21 of the Directive.
NISG 2026 Compliance Timeline
| Date | Obligation |
|---|---|
| 23 December 2025 | NISG 2026 published in the Austrian Federal Law Gazette |
| 1 October 2026 | NISG 2026 enters into force; compliance obligations and supervisory regime begin |
| 31 December 2026 | Entity registration deadline via nis.gv.at |
| 30 September 2027 | Self-declaration of implemented Article 21 risk-management measures due |
| Ongoing | Annual review of risk measures; incident reporting per 24-hour / 72-hour / one-month timeline |
Two deadlines catch organisations unprepared: the registration deadline (31 December 2026) and the self-declaration (30 September 2027). The self-declaration is a distinct step — a formal attestation confirming that Article 21 risk-management measures have been implemented, not just that the organisation has registered as an in-scope entity. For a step-by-step checklist covering both steps, see the NIS2 compliance checklist. [6]
Supervisory Model — What Happens After Registration
NISG 2026 adopts the NIS2 Directive’s two-tier supervisory model, with materially different implications depending on entity classification.
Essential entities (Annex I, larger organisations in high-criticality sectors — energy, transport, water, digital infrastructure, and others) face proactive, ex ante supervision. The Bundesamt für Cybersicherheit and relevant sector authorities can initiate audits, request security scans, and require evidence of compliance at any time, without waiting for an incident. The BMI holds extensive audit rights, including on-site inspections. [7] Essential entities can be required to produce organisational and operational proof of compliance within two months of an authority request.
Important entities (Annex II sectors, or sub-threshold entities in Annex I sectors) receive reactive, ex post supervision. Oversight is triggered by incidents, complaints, or indications of non-compliance — the authority does not routinely schedule audits.
Management accountability applies to both tiers. Under Article 20 of the NIS2 Directive, management body members must formally approve the organisation’s cybersecurity risk-management measures and receive mandatory training. [4] NISG 2026 adds personal exposure: gross negligence in NIS2 oversight can lead to individual director fines and temporary bans from managerial functions, not only entity-level penalties. Maintaining auditable records of management approvals and training completion is the practical response to this risk — registration alone does not demonstrate compliance.
Penalties for Non-Compliance
| Violation | Essential Entity maximum | Important Entity maximum |
|---|---|---|
| Failure to implement Article 21 security measures or Article 23 incident reporting obligations | €10 million or 2% of global annual turnover, whichever is higher | €7 million or 1.4% of global annual turnover, whichever is higher |
| Non-registration or failure to register by the deadline | Up to €50,000 | Up to €50,000 |
| Repeat administrative violations | Up to €100,000 | Up to €100,000 |
These thresholds reflect the mandatory minimum values in Article 34(4) and Article 34(5) of the NIS2 Directive — Austria has not raised them above the Directive’s floor. [5] Public authorities face a different enforcement track: binding compliance orders and public disclosure rather than monetary fines.
For a comparison with enforcement structures in other member states, see the NIS2 penalties overview. Austria’s penalty structure aligns closely with Germany’s, where the BSI holds ex ante supervisory powers over essential entities and applies the same maximum fine ceilings.
Frequently Asked Questions
Is CERT.at the same as the Bundesamt für Cybersicherheit?
No. CERT.at is Austria’s CSIRT — it handles incident response and operates the nis.cert.at reporting portal. The Bundesamt für Cybersicherheit is the supervisory NCA responsible for entity oversight, audits, and enforcement under NISG 2026. They are separate organisations with different legal mandates.
Can I register on nis.gv.at before 1 October 2026?
No. NISG 2026 enters into force on 1 October 2026, at which point the registration window opens. The deadline to complete registration is 31 December 2026.
Do I register directly with my sector authority or via nis.gv.at?
All entities register via nis.gv.at. The portal routes registration data to the appropriate sector authority — E-Control, FMA, RTR, or the Bundesamt. Your sector authority then handles supervisory and enforcement matters within their domain.
What is the difference between the NCA and the SPOC?
The NCA (Bundesamt für Cybersicherheit) supervises entities and enforces compliance. The SPOC (Federal Ministry of the Interior, post@nis.gv.at) facilitates coordination between Austria and other EU member states under Article 8 of the Directive. In Austria’s model, both share infrastructure via nis.gv.at, but their functions differ: the NCA looks inward at domestic entities, the SPOC looks outward at EU-level coordination.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- European Commission, “NIS2 Directive Implementation in Austria” — digital-strategy.ec.europa.eu
- NIS2 Directive (EU) 2022/2555, Article 8 — nis-2-directive.com
- NIS2 Directive (EU) 2022/2555, Article 10 — nis-2-directive.com
- NIS2 Directive (EU) 2022/2555, Article 20 — nis-2-directive.com
- NIS2 Directive (EU) 2022/2555, Article 34 — nis-2-directive.com
- Schoenherr, “Österreich: NISG 2026 — Alles, was Sie wissen müssen” — schoenherr.eu
- Wolf Theiss, “NIS-2 Implementation Act: New Cyber Obligations” — wolftheiss.com
- Eversheds Sutherland, “Austria — EU NIS2 Directive” — eversheds-sutherland.com
- NIS Anlaufstelle — nis.gv.at
- CERT.at — cert.at/en
- Global Law Experts, “NIS2 Compliance Austria 2026” — globallawexperts.com
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
