Technology

Austria Implements NIS2 Directive and Establishes New Cybersecurity Agency

9/25/2026, 03:47 PM • Evgenia Sliv

(edited: 09/25/2026)

Austria Implements NIS2 Directive and Establishes New Cybersecurity Agency

Two years late, Austria is implementing the EU NIS2 directive. The Network and Information Systems Security Act of 2026 (NISG 2026) introduces new registration and reporting obligations for companies and government agencies (excluding municipalities) starting October 1, and establishes the Federal Cybersecurity Agency (BCS). It is subordinate to the Minister of the Interior.

The first director of BCS is Markus Kasinger, previously the IT director at Austrian Power Grid AG, which manages the Austrian electricity transmission network. "Cyberattacks do not respect industry boundaries. We need an agency that provides an overview, identifies risks, and brings stakeholders together," he stated. BCS is responsible for the national cybersecurity strategy, situation reports, coordination during major incidents, and collaboration with partners. The agency will oversee the NISG 2026 and manage GovCERT for the public sector, also overseeing HealthCERT and CERT at for the private sector (managed by nic at).

BCS does not have police powers but will actively scan the internet systems of "important institutions" to identify vulnerabilities. Blocking such scans from October 1 will be a criminal offense. Fines may be imposed for violations of registration, reporting, or non-participation of executives in mandatory training. These fines are imposed by the district administrative authority based on BCS recommendations, not by BCS itself. A separate directive DORA applies to the financial sector, which supersedes NISG 2026 in case of conflict.

Popular news