International Edition
Latest News
Technology

Austria Implements NIS2 and Establishes Federal Cybersecurity Agency

Austria is establishing the Bundesamt für Cybersicherheit (BCS) to officially implement the European Union's updated Network and Information Security Directive, known as NIS2, with the newly enacted Netz- und Informationssystemsicherheitsgesetzes 2026 (NISG 2026) taking effect on October 1,…

Austria Implements NIS2 and Establishes Federal Cybersecurity Agency

Austria is establishing the Bundesamt für Cybersicherheit (BCS) to officially implement the European Union’s updated Network and Information Security Directive, known as NIS2, with the newly enacted Netz- und Informationssystemsicherheitsgesetzes 2026 (NISG 2026) taking effect on October 1, according to reports by heise online and OTS. Set to operate directly under the Federal Ministry of the Interior rather than the Directorate-General for Public Security, the newly formed federal agency aims to centralize digital defense, incident coordination, and risk monitoring across critical public and private sectors.

Leadership and Structure of the New Cybersecurity Agency

Markus Kasinger, formerly the Chief Information Officer of Austrian Power Grid AG, assumes the role of the inaugural director of the BCS, as detailed by OTS. Interior Minister Gerhard Karner emphasized that the agency’s primary mission under Kasinger’s leadership will focus on advising rather than penalizing, aiming to collaborate closely with the economy to bolster resilience.

Director Kasinger outlined three strategic priorities for the agency during its launch phase: strengthening overall resilience against threats driven by artificial intelligence, enhancing the cybersecurity posture of small and medium-sized enterprises as the backbone of the economy, and advancing the country’s national cybersecurity framework. The BCS will oversee the civil public sector’s Computer Emergency Response Team (GovCERT) while maintaining supervisory oversight over sector-specific CERTs, such as the Austrian HealthCERT, alongside the national private sector handler, CERT.at, which is operated by nic.at.

Expanded Regulatory Scope and Mandatory Compliance

Under the NISG 2026 framework, organizations operating within essential and important sectors face strict new compliance obligations. Important entities include medium and large organizations spanning these same sectors that do not meet the strict thresholds of essential classification.

Impacted entities must independently determine their registration requirements under the new law, as direct administrative notices will only be issued in specific scenarios, according to heise online. Furthermore, organizations operating within the financial sector are governed by the separate Digital Operational Resilience Act (DORA), an EU regulation that supersedes NISG 2026 standards in the event of regulatory conflicts.

Active Scanning and Enforcement Measures

While the BCS lacks police powers or direct law enforcement authority, the agency is authorized to conduct active security scans of internet-facing systems belonging to essential entities to identify vulnerabilities. Blocking or actively resisting these state scans constitutes an offense punishable by law starting October 1, and affected entities are legally required to cooperate upon request, as reported by heise online.

Austria Implements NIS2 and Establishes Federal Cybersecurity Agency
Photo: sec4you.com

Penalties apply for violations of registration mandates, failure to report significant security incidents, or skipping mandatory IT security training for management personnel. While the BCS identifies shortcomings and initiates proceedings, fines are officially levied by the competent district administrative authority upon recommendation from the agency, ensuring a structured division between technical oversight and administrative punishment.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”