Local presence · Austria

Cybersecurity services in Austria

Cybersecurity · NIS2 · NISG · Datenschutzbehörde · DORA

NISG ready, DORA-aligned — operated from our EU SOCs.

Austrian enterprises operate under a supervisory model where cybersecurity sits with the Federal Ministry of the Interior (BMI) rather than a standalone agency. The Netz- und Informationssystemsicherheitsgesetz (NISG) — Austria's NIS2 transposition — extends duties far beyond the operators covered by the original 2018 act, bringing thousands of essential and important entities across 18 sectors into scope, with the Cyber Security Center at the Directorate State Protection and Intelligence Service (DSN) running operational supervision and CERT.at and GovCERT Austria coordinating technical incident response. The Datenschutzbehörde enforces GDPR alongside the Datenschutzgesetz, the Finanzmarktaufsicht supervises DORA-scope financial entities, and health data carries additional duties under the Gesundheitstelematikgesetz. Austrian banking groups with Central and Eastern European subsidiaries, industrial suppliers, and Vienna's cluster of international organisations all raise the bar on supply-chain assurance. From our Stockholm and Zoetermeer SOCs we deliver 24×7 detection with telemetry kept inside the EEA and reporting available in German.

Regulatory landscape

The Austrian regulatory landscape we cover

NISG (NIS2 transposition)

Austria's Netz- und Informationssystemsicherheitsgesetz implementing NIS2 — risk-management duties, supply-chain controls, entity registration, and a 24-hour early warning followed by a 72-hour notification for essential and important entities.

BMI supervision & Cyber Security Center

The Federal Ministry of the Interior is the competent NIS authority; the Cyber Security Center at the DSN runs operational supervision, and qualified bodies carry out NIS conformity audits.

DORA

Digital Operational Resilience Act for Austrian banks, insurers, payment and crypto-asset service providers and their critical ICT third parties — supervised by the Finanzmarktaufsicht (FMA).

Datenschutzgesetz (DSG) & GDPR

Austrian Data Protection Act layered on GDPR and enforced by the Datenschutzbehörde — 72-hour breach notification and fines up to 4% of global revenue.

GTelG 2012 & ELGA

Health Telematics Act rules for electronic health data and ELGA participation — additional access-control, logging, and encryption duties for Austrian healthcare providers.

TKG 2021

Telecommunications Act security and integrity obligations for network and service operators, supervised by RTR alongside sector incident-reporting duties.

~3,000–4,000
NISG in-scope entities (estimated)
Source: BMI
24 hours
NIS2 early-warning window
Source: NIS2 Art. 23
4% global revenue
GDPR maximum fine
Source: Datenschutzbehörde
Banking, insurance & CEE groupsIndustrial manufacturing & automotive supply chainEnergy & utilitiesPublic sector & international organisations

FAQs · Austria

Is my Austrian company in scope of the NISG?
If you operate in energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space, postal and courier services, waste management, chemicals, food, manufacturing, digital providers, or research — and you exceed the medium-enterprise threshold of 50 staff or EUR 10M turnover — you are likely an essential or important entity. We run a free in-scope assessment.
How fast must we report an incident, and to whom?
The NIS2 timelines apply: an early warning within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report within one month — filed with the competent authority and coordinated technically with GovCERT Austria and CERT.at. Our SOC drafts and submits each notification when the triggers are met.
Where does our data sit during SOC monitoring?
Telemetry and case data remain inside the EEA, processed across our Stockholm and Zoetermeer SOCs, with reporting available in German for Austrian stakeholders. No transfer to third countries without a documented Article 46 safeguard.

Speak with our Austria desk

For NISG readiness, incident-reporting workflow, DORA evidence, or GDPR alignment with the Datenschutzbehörde — we respond within one business day.

Austria
consult@gsecurelabs.com