Home / Services

NIS2 compliance (Austrian NISG 2026)

The Austrian NIS2 act, NISG 2026, has been in force since 1 October 2026. We bring your systems and processes up to the required level: inventory, technical measures, incident reporting process, documentation. Technically grounded, without consultant jargon.

Item 06·Unit Lump sum · stage·Acceptance List of measures, incident reporting process

Typical starting point

  • Your company falls under NISG 2026 (from 50 employees or 10 million euros in turnover in one of the 18 sectors), and registration with the NIS authority is due by 31 December 2026.
  • A consultant delivered an 80-page gap analysis, but nobody is implementing the technical items: logging, backups, access control, patch management.
  • A major customer requires evidence of your security measures as part of its supply chain, and there is no documentation for it.

What we deliver

  • Inventory: systems, data flows, access, suppliers, mapped against the risk-management measures required by NISG 2026
  • Action plan with priorities, effort and owners, understandable to management
  • Implementation of the technical measures: multi-factor authentication, permissions model, central logging, tested backups, patch process, network segmentation, encryption
  • Incident reporting process for the 24-hour, 72-hour and one-month deadlines, including templates and responsibilities
  • Documentation for registration, self-declaration and supplier questionnaires
  • Training material for management and staff

How it runs

  1. Applicability check and inventory, two to five days
  2. Action plan, approved by management
  3. Implementation in stages, critical measures first
  4. Documentation, reporting process, handover, then annual review